{"cves":[{"id":"CVE-2012-0087","published":"2012-01-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.0.x and 5.1.x allows remote authenticated users to affect availability\nvia unknown vectors, a different vulnerability than CVE-2012-0101 and\nCVE-2012-0102.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per server team\nper Oracle, 5.5 not affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html","https://ubuntu.com/security/notices/USN-1397-1","https://www.cve.org/CVERecord?id=CVE-2012-0087"],"bugs":[""],"patches":{"mysql-dfsg-5.0":[],"mysql-dfsg-5.1":[],"mysql-5.1":[],"mysql-cluster-7.0":[],"mysql":[],"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql","source":"https://ubuntu.com/security/cve?package=mysql","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql","debian":"https://tracker.debian.org/pkg/mysql","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.1","source":"https://ubuntu.com/security/cve?package=mysql-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.1","debian":"https://tracker.debian.org/pkg/mysql-5.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.1.61-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.1.61-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"5.1.61-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.20","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"hardy","status":"released","description":"5.0.95-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.1.61-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1397-1"],"notices":[{"id":"USN-1397-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-03-12T14:37:53.714964","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10,\nUbuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to\nMySQL 5.0.95.\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\n\nhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-x.html\nhttp://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html\n","is_hidden":false,"release_packages":{"hardy":[{"name":"mysql-dfsg-5.0","version":"5.0.95-0ubuntu1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.0","version":"5.0.95-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.95-0ubuntu1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.61-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.61-0ubuntu0.10.04.1"}],"maverick":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.10.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.10.10.1"}],"natty":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.04.1"}],"oneiric":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2007-5925","CVE-2008-3963","CVE-2008-4098","CVE-2008-4456","CVE-2008-7247","CVE-2009-2446","CVE-2009-4019","CVE-2009-4030","CVE-2009-4484","CVE-2010-1621","CVE-2010-1626","CVE-2010-1848","CVE-2010-1849","CVE-2010-1850","CVE-2010-2008","CVE-2010-3677","CVE-2010-3678","CVE-2010-3679","CVE-2010-3680","CVE-2010-3681","CVE-2010-3682","CVE-2010-3683","CVE-2010-3833","CVE-2010-3834","CVE-2010-3835","CVE-2010-3836","CVE-2010-3837","CVE-2010-3838","CVE-2010-3839","CVE-2010-3840","CVE-2011-2262","CVE-2012-0075","CVE-2012-0087","CVE-2012-0101","CVE-2012-0102","CVE-2012-0112","CVE-2012-0113","CVE-2012-0114","CVE-2012-0115","CVE-2012-0116","CVE-2012-0117","CVE-2012-0118","CVE-2012-0119","CVE-2012-0120","CVE-2012-0484","CVE-2012-0485","CVE-2012-0486","CVE-2012-0487","CVE-2012-0488","CVE-2012-0489","CVE-2012-0490","CVE-2012-0491","CVE-2012-0492","CVE-2012-0493","CVE-2012-0494","CVE-2012-0495","CVE-2012-0496"]}]},{"id":"CVE-2012-0075","published":"2012-01-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect\nintegrity via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per server team"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html","https://ubuntu.com/security/notices/USN-1397-1","https://www.cve.org/CVERecord?id=CVE-2012-0075"],"bugs":[""],"patches":{"mysql-dfsg-5.0":[],"mysql-dfsg-5.1":[],"mysql-5.1":[],"mysql-cluster-7.0":[],"mysql":[],"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql","source":"https://ubuntu.com/security/cve?package=mysql","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql","debian":"https://tracker.debian.org/pkg/mysql","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.1","source":"https://ubuntu.com/security/cve?package=mysql-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.1","debian":"https://tracker.debian.org/pkg/mysql-5.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.1.61-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.1.61-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"5.1.61-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.20","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"hardy","status":"released","description":"5.0.95-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.1.61-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1397-1"],"notices":[{"id":"USN-1397-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-03-12T14:37:53.714964","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10,\nUbuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to\nMySQL 5.0.95.\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\n\nhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-x.html\nhttp://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html\n","is_hidden":false,"release_packages":{"hardy":[{"name":"mysql-dfsg-5.0","version":"5.0.95-0ubuntu1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.0","version":"5.0.95-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.95-0ubuntu1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.61-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.61-0ubuntu0.10.04.1"}],"maverick":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.10.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.10.10.1"}],"natty":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.04.1"}],"oneiric":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2007-5925","CVE-2008-3963","CVE-2008-4098","CVE-2008-4456","CVE-2008-7247","CVE-2009-2446","CVE-2009-4019","CVE-2009-4030","CVE-2009-4484","CVE-2010-1621","CVE-2010-1626","CVE-2010-1848","CVE-2010-1849","CVE-2010-1850","CVE-2010-2008","CVE-2010-3677","CVE-2010-3678","CVE-2010-3679","CVE-2010-3680","CVE-2010-3681","CVE-2010-3682","CVE-2010-3683","CVE-2010-3833","CVE-2010-3834","CVE-2010-3835","CVE-2010-3836","CVE-2010-3837","CVE-2010-3838","CVE-2010-3839","CVE-2010-3840","CVE-2011-2262","CVE-2012-0075","CVE-2012-0087","CVE-2012-0101","CVE-2012-0102","CVE-2012-0112","CVE-2012-0113","CVE-2012-0114","CVE-2012-0115","CVE-2012-0116","CVE-2012-0117","CVE-2012-0118","CVE-2012-0119","CVE-2012-0120","CVE-2012-0484","CVE-2012-0485","CVE-2012-0486","CVE-2012-0487","CVE-2012-0488","CVE-2012-0489","CVE-2012-0490","CVE-2012-0491","CVE-2012-0492","CVE-2012-0493","CVE-2012-0494","CVE-2012-0495","CVE-2012-0496"]}]},{"id":"CVE-2012-0055","published":"2012-01-18T00:00:00","updated_at":"2025-08-25T20:23:40.534375+00:00","description":"\nOverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4\nLTS and 11.10, is missing inode security checks which could allow attackers\nto bypass security restrictions and perform unauthorized actions.","ubuntu_description":"\nAndy Whitcroft discovered a that the Overlayfs filesystem was not doing the\nextended permission checks needed by cgroups and Linux Security Modules\n(LSMs). A local user could exploit this to by-pass security policy and\naccess files that should not be accessible.","notes":[{"author":"jjohansen","note":"removed https://launchpad.net/bugs/915941 link as it was causing\nscript to fail"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1363-1","https://ubuntu.com/security/notices/USN-1364-1","https://ubuntu.com/security/notices/USN-1384-1","https://www.cve.org/CVERecord?id=CVE-2012-0055"],"bugs":["https://launchpad.net/bugs/918212"],"patches":{"linux":["break-fix: 549ffd5a07c9098a6a1c7a82e7fd731a132fc1a0 local-2012-0055"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-16.27","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.0-16.28~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-1207.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1364-1","USN-1384-1","USN-1363-1"],"notices":[{"id":"USN-1364-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-02-13T19:47:13.419688","description":"\nA bug was discovered in the Linux kernel's calculation of OOM (Out of\nmemory) scores, that would result in the wrong process being killed. A user\ncould use this to kill the process with the highest OOM score, even if that\nprocess belongs to another user or the system. (CVE-2011-4097)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nAndy Whitcroft discovered a that the Overlayfs filesystem was not doing the\nextended permission checks needed by cgroups and Linux Security Modules\n(LSMs). A local user could exploit this to by-pass security policy and\naccess files that should not be accessible. (CVE-2012-0055)\n\nJüri Aedla discovered that the kernel incorrectly handled /proc//mem\npermissions. A local attacker could exploit this and gain root privileges.\n(CVE-2012-0056)\n\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service. (CVE-2012-0207)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux-ti-omap4","version":"3.0.0-1207.16","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.0.0-1207-omap4","version":"3.0.0-1207.16","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.0.0-1207.16"}]},"type":"USN","cves_ids":["CVE-2011-4097","CVE-2012-0038","CVE-2012-0055","CVE-2012-0056","CVE-2012-0207"]},{"id":"USN-1384-1","title":"Linux kernel (Oneiric backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-03-06T15:50:36.079301","description":"\nA bug was discovered in the Linux kernel's calculation of OOM (Out of\nmemory) scores, that would result in the wrong process being killed. A user\ncould use this to kill the process with the highest OOM score, even if that\nprocess belongs to another user or the system. (CVE-2011-4097)\n\nPaolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl\ncommand. A local user, or user in a VM could exploit this flaw to bypass\nrestrictions and gain read/write access to all data on the affected block\ndevice. (CVE-2011-4127)\n\nA flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual\ninterrupt control is not available a local user could use this to cause a\ndenial of service by starting a timer. (CVE-2011-4622)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nAndy Whitcroft discovered a that the Overlayfs filesystem was not doing the\nextended permission checks needed by cgroups and Linux Security Modules\n(LSMs). A local user could exploit this to by-pass security policy and\naccess files that should not be accessible. (CVE-2012-0055)\n\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service. (CVE-2012-0207)\n\nA flaw was found in the Linux kernel's ext4 file system when mounting a\ncorrupt filesystem. A user-assisted remote attacker could exploit this flaw\nto cause a denial of service. (CVE-2012-2100)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-oneiric","version":"3.0.0-16.29~lucid1","description":"Linux kernel backport from Oneiric","is_source":true},{"name":"linux-image-3.0.0-16-virtual","version":"3.0.0-16.29~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-16.29~lucid1"},{"name":"linux-image-3.0.0-16-generic","version":"3.0.0-16.29~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-16.29~lucid1"},{"name":"linux-image-3.0.0-16-server","version":"3.0.0-16.29~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-16.29~lucid1"},{"name":"linux-image-3.0.0-16-generic-pae","version":"3.0.0-16.29~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-16.29~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-4097","CVE-2011-4127","CVE-2011-4622","CVE-2012-0038","CVE-2012-0055","CVE-2012-0207","CVE-2012-2100"]},{"id":"USN-1363-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-02-13T19:21:48.098429","description":"\nA bug was discovered in the Linux kernel's calculation of OOM (Out of\nmemory) scores, that would result in the wrong process being killed. A user\ncould use this to kill the process with the highest OOM score, even if that\nprocess belongs to another user or the system. (CVE-2011-4097)\n\nA flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual\ninterrupt control is not available a local user could use this to cause a\ndenial of service by starting a timer. (CVE-2011-4622)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nAndy Whitcroft discovered a that the Overlayfs filesystem was not doing the\nextended permission checks needed by cgroups and Linux Security Modules\n(LSMs). A local user could exploit this to by-pass security policy and\naccess files that should not be accessible. (CVE-2012-0055)\n\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service. (CVE-2012-0207)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux","version":"3.0.0-16.28","description":"Linux kernel","is_source":true},{"name":"linux-image-3.0.0-16-server","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-powerpc-smp","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-virtual","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-powerpc64-smp","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-powerpc","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-generic-pae","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-omap","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-generic","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"}]},"type":"USN","cves_ids":["CVE-2012-0055","CVE-2012-0207","CVE-2011-4097","CVE-2011-4622","CVE-2012-0038"]}]},{"id":"CVE-2012-0031","published":"2012-01-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nscoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local\nusers to cause a denial of service (daemon crash during shutdown) or\npossibly have unspecified other impact by modifying a certain type field\nwithin a scoreboard shared memory segment, leading to an invalid call to\nthe free function.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.halfdog.net/Security/2011/ApacheScoreboardInvalidFreeOnShutdown/","https://ubuntu.com/security/notices/USN-1368-1","https://www.cve.org/CVERecord?id=CVE-2012-0031"],"bugs":[""],"patches":{"apache2":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1230065","upstream: http://svn.apache.org/viewvc?view=revision&revision=1231058"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"hardy","status":"released","description":"2.2.8-1ubuntu0.23","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.2.14-5ubuntu8.8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.2.16-1ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.2.17-1ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.2.20-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1368-1"],"notices":[{"id":"USN-1368-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in the Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-16T19:30:58.923745","description":"It was discovered that the Apache HTTP Server incorrectly handled the\nSetEnvIf .htaccess file directive. An attacker having write access to a\n.htaccess file may exploit this to possibly execute arbitrary code.\n(CVE-2011-3607)\n\nPrutha Parikh discovered that the mod_proxy module did not properly\ninteract with the RewriteRule and ProxyPassMatch pattern matches in the\nconfiguration of a reverse proxy. This could allow remote attackers to\ncontact internal webservers behind the proxy that were not intended for\nexternal exposure. (CVE-2011-4317)\n\nRainer Canavan discovered that the mod_log_config module incorrectly\nhandled a certain format string when used with a threaded MPM. A remote\nattacker could exploit this to cause a denial of service via a specially-\ncrafted cookie. This issue only affected Ubuntu 11.04 and 11.10.\n(CVE-2012-0021)\n\nIt was discovered that the Apache HTTP Server incorrectly handled certain\ntype fields within a scoreboard shared memory segment. A local attacker\ncould exploit this to to cause a denial of service. (CVE-2012-0031)\n\nNorman Hippert discovered that the Apache HTTP Server incorrecly handled\nheader information when returning a Bad Request (400) error page. A remote\nattacker could exploit this to obtain the values of certain HTTPOnly\ncookies. (CVE-2012-0053)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"apache2","version":"2.2.8-1ubuntu0.23","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.8-1ubuntu0.23","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.23"}],"lucid":[{"name":"apache2","version":"2.2.14-5ubuntu8.8","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.14-5ubuntu8.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.14-5ubuntu8.8"}],"maverick":[{"name":"apache2","version":"2.2.16-1ubuntu3.5","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.16-1ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.16-1ubuntu3.5"}],"natty":[{"name":"apache2","version":"2.2.17-1ubuntu1.5","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.17-1ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.17-1ubuntu1.5"}],"oneiric":[{"name":"apache2","version":"2.2.20-1ubuntu1.2","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.20-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.20-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2011-3607","CVE-2011-4317","CVE-2012-0021","CVE-2012-0031","CVE-2012-0053"]}]},{"id":"CVE-2012-0022","published":"2012-01-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23\nuses an inefficient approach for handling parameters, which allows remote\nattackers to cause a denial of service (CPU consumption) via a request that\ncontains many parameters and parameter values, a different vulnerability\nthan CVE-2011-4858.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream bug says last commit isn't in 6.0.35."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://tomcat.apache.org/security.html","http://tomcat.apache.org/security-7.html","http://tomcat.apache.org/security-6.html","http://tomcat.apache.org/security-5.html","https://ubuntu.com/security/notices/USN-1359-1","https://www.cve.org/CVERecord?id=CVE-2012-0022"],"bugs":["https://issues.apache.org/bugzilla/show_bug.cgi?id=52384","https://bugzilla.redhat.com/show_bug.cgi?id=783359"],"patches":{"tomcat5.5":[],"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1140904","upstream: http://svn.apache.org/viewvc?view=revision&revision=1199122","upstream: http://svn.apache.org/viewvc?view=revision&revision=1200601","upstream: http://svn.apache.org/viewvc?view=revision&revision=1206324","upstream: http://svn.apache.org/viewvc?view=revision&revision=1229027"],"tomcat7":[]},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.24-2ubuntu1.10","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6.0.28-2ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6.0.28-10ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6.0.32-5ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6.0.35-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6.0.35-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7.0.21-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"7.0.26-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"7.0.29-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.23","component":null,"pocket":"security"}]}],"notices_ids":["USN-1359-1"],"notices":[{"id":"USN-1359-1","title":"Tomcat vulnerabilities","summary":"Tomcat could be made to crash or expose sensitive information if it\nreceived specially crafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-13T13:53:01.725300","description":"It was discovered that Tomcat incorrectly performed certain caching and\nrecycling operations. A remote attacker could use this flaw to obtain read\naccess to IP address and HTTP header information in certain cases. This\nissue only applied to Ubuntu 11.10. (CVE-2011-3375)\n\nIt was discovered that Tomcat computed hash values for form parameters\nwithout restricting the ability to trigger hash collisions predictably.\nA remote attacker could cause a denial of service by sending many crafted\nparameters. (CVE-2011-4858)\n\nIt was discovered that Tomcat incorrectly handled parameters. A remote\nattacker could cause a denial of service by sending requests with a large\nnumber of parameters and values. (CVE-2012-0022)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"tomcat6","version":"6.0.24-2ubuntu1.10","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.24-2ubuntu1.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.24-2ubuntu1.10"}],"maverick":[{"name":"tomcat6","version":"6.0.28-2ubuntu1.6","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.28-2ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.28-2ubuntu1.6"}],"natty":[{"name":"tomcat6","version":"6.0.28-10ubuntu2.3","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.28-10ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.28-10ubuntu2.3"}],"oneiric":[{"name":"tomcat6","version":"6.0.32-5ubuntu1.2","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.32-5ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.32-5ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2011-3375","CVE-2011-4858","CVE-2012-0022"]}]},{"id":"CVE-2011-4153","published":"2012-01-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPHP 5.3.8 does not always check the return value of the zend_strndup\nfunction, which might allow remote attackers to cause a denial of service\n(NULL pointer dereference and application crash) via crafted input to an\napplication that performs strndup operations on untrusted string data, as\ndemonstrated by the define function in zend_builtin_functions.c, and\nunspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c,\next/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c,\nand main/php_open_temporary_file.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1358-1","https://www.cve.org/CVERecord?id=CVE-2011-4153"],"bugs":[""],"patches":{"php5":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.22","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.13","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.3.3-1ubuntu9.9","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.3.5-1ubuntu7.6","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"5.3.6-13ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1358-1"],"notices":[{"id":"USN-1358-1","title":"PHP vulnerabilities","summary":"Multiple vulnerabilities in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-10T04:55:00.946575","description":"It was discovered that PHP computed hash values for form parameters\nwithout restricting the ability to trigger hash collisions predictably.\nThis could allow a remote attacker to cause a denial of service by\nsending many crafted parameters. (CVE-2011-4885)\n\nATTENTION: this update changes previous PHP behavior by\nlimiting the number of external input variables to 1000.\nThis may be increased by adding a \"max_input_vars\"\ndirective to the php.ini configuration file. See\nhttp://www.php.net/manual/en/info.configuration.php#ini.max-input-vars\nfor more information.\n\nStefan Esser discovered that the fix to address the predictable hash\ncollision issue, CVE-2011-4885, did not properly handle the situation\nwhere the limit was reached. This could allow a remote attacker to\ncause a denial of service or execute arbitrary code via a request\ncontaining a large number of variables. (CVE-2012-0830)\n\nIt was discovered that PHP did not always check the return value of\nthe zend_strndup function. This could allow a remote attacker to\ncause a denial of service. (CVE-2011-4153)\n\nIt was discovered that PHP did not properly enforce libxslt security\nsettings. This could allow a remote attacker to create arbitrary\nfiles via a crafted XSLT stylesheet that uses the libxslt output\nextension. (CVE-2012-0057)\n\nIt was discovered that PHP did not properly enforce that PDORow\nobjects could not be serialized and not be saved in a session. A\nremote attacker could use this to cause a denial of service via an\napplication crash. (CVE-2012-0788)\n\nIt was discovered that PHP allowed the magic_quotes_gpc setting to\nbe disabled remotely. This could allow a remote attacker to bypass\nrestrictions that could prevent an SQL injection. (CVE-2012-0831)\n\nUSN 1126-1 addressed an issue where the /etc/cron.d/php5 cron job\nfor PHP allowed local users to delete arbitrary files via a symlink\nattack on a directory under /var/lib/php5/. Emese Revfy discovered\nthat the fix had not been applied to PHP for Ubuntu 10.04 LTS. This\nupdate corrects the issue. We apologize for the error. (CVE-2011-0441)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.22","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.22"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.22"},{"name":"php5-common","version":"5.2.4-2ubuntu5.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.22"},{"name":"php5-xsl","version":"5.2.4-2ubuntu5.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.22"},{"name":"php5","version":"5.2.4-2ubuntu5.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.22"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.22"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.13","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.13"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.13"},{"name":"php5-common","version":"5.3.2-1ubuntu4.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.13"},{"name":"php5-xsl","version":"5.3.2-1ubuntu4.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.13"},{"name":"php5","version":"5.3.2-1ubuntu4.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.13"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.13"}],"maverick":[{"name":"php5","version":"5.3.3-1ubuntu9.9","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.3-1ubuntu9.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.9"},{"name":"php5-cgi","version":"5.3.3-1ubuntu9.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.9"},{"name":"php5-common","version":"5.3.3-1ubuntu9.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.9"},{"name":"php5-xsl","version":"5.3.3-1ubuntu9.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.9"},{"name":"php5","version":"5.3.3-1ubuntu9.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.9"},{"name":"libapache2-mod-php5","version":"5.3.3-1ubuntu9.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.9"}],"natty":[{"name":"php5","version":"5.3.5-1ubuntu7.6","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.5-1ubuntu7.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.6"},{"name":"php5-cgi","version":"5.3.5-1ubuntu7.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.6"},{"name":"php5-common","version":"5.3.5-1ubuntu7.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.6"},{"name":"php5-xsl","version":"5.3.5-1ubuntu7.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.6"},{"name":"php5","version":"5.3.5-1ubuntu7.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.6"},{"name":"libapache2-mod-php5","version":"5.3.5-1ubuntu7.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.6"}],"oneiric":[{"name":"php5","version":"5.3.6-13ubuntu3.5","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.6-13ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.5"},{"name":"php5-cgi","version":"5.3.6-13ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.5"},{"name":"php5-common","version":"5.3.6-13ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.5"},{"name":"php5-xsl","version":"5.3.6-13ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.5"},{"name":"php5","version":"5.3.6-13ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.5"},{"name":"libapache2-mod-php5","version":"5.3.6-13ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.5"}]},"type":"USN","cves_ids":["CVE-2012-0831","CVE-2011-4153","CVE-2012-0830","CVE-2012-0057","CVE-2012-0788","CVE-2011-4885","CVE-2011-0441"]}]},{"id":"CVE-2011-3375","published":"2012-01-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly\nperform certain caching and recycling operations involving request objects,\nwhich allows remote attackers to obtain unintended read access to IP\naddress and HTTP header information in opportunistic circumstances by\nreading TCP data.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"advisory says Tomcat 6.0.30 to 6.0.33"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://tomcat.apache.org/security.html","http://tomcat.apache.org/security-7.html","http://tomcat.apache.org/security-6.html","http://seclists.org/fulldisclosure/2012/Jan/236","https://ubuntu.com/security/notices/USN-1359-1","https://www.cve.org/CVERecord?id=CVE-2011-3375"],"bugs":["https://issues.apache.org/bugzilla/show_bug.cgi?id=51872","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3375"],"patches":{"tomcat7":[],"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1185998"],"tomcat5.5":[]},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6.0.24-2ubuntu1.9","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6.0.28-2ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"6.0.28-10ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6.0.32-5ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"6.0.35-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"6.0.35-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.35","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7.0.21-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"7.0.26-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"7.0.29-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.22","component":null,"pocket":"security"}]}],"notices_ids":["USN-1359-1"],"notices":[{"id":"USN-1359-1","title":"Tomcat vulnerabilities","summary":"Tomcat could be made to crash or expose sensitive information if it\nreceived specially crafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-13T13:53:01.725300","description":"It was discovered that Tomcat incorrectly performed certain caching and\nrecycling operations. A remote attacker could use this flaw to obtain read\naccess to IP address and HTTP header information in certain cases. This\nissue only applied to Ubuntu 11.10. (CVE-2011-3375)\n\nIt was discovered that Tomcat computed hash values for form parameters\nwithout restricting the ability to trigger hash collisions predictably.\nA remote attacker could cause a denial of service by sending many crafted\nparameters. (CVE-2011-4858)\n\nIt was discovered that Tomcat incorrectly handled parameters. A remote\nattacker could cause a denial of service by sending requests with a large\nnumber of parameters and values. (CVE-2012-0022)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"tomcat6","version":"6.0.24-2ubuntu1.10","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.24-2ubuntu1.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.24-2ubuntu1.10"}],"maverick":[{"name":"tomcat6","version":"6.0.28-2ubuntu1.6","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.28-2ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.28-2ubuntu1.6"}],"natty":[{"name":"tomcat6","version":"6.0.28-10ubuntu2.3","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.28-10ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.28-10ubuntu2.3"}],"oneiric":[{"name":"tomcat6","version":"6.0.32-5ubuntu1.2","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.32-5ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.32-5ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2011-3375","CVE-2011-4858","CVE-2012-0022"]}]},{"id":"CVE-2011-2262","published":"2012-01-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.1.x and 5.5.x allows remote attackers to affect availability via unknown\nvectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per server team\n5.0 not affected per Oracle"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html","https://ubuntu.com/security/notices/USN-1397-1","https://www.cve.org/CVERecord?id=CVE-2011-2262"],"bugs":[""],"patches":{"mysql-dfsg-5.0":[],"mysql-dfsg-5.1":[],"mysql-5.1":[],"mysql-cluster-7.0":[],"mysql":[],"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql","source":"https://ubuntu.com/security/cve?package=mysql","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql","debian":"https://tracker.debian.org/pkg/mysql","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.1","source":"https://ubuntu.com/security/cve?package=mysql-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.1","debian":"https://tracker.debian.org/pkg/mysql-5.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.1.61-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.1.61-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"5.1.61-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.20","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.1.61-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1397-1"],"notices":[{"id":"USN-1397-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-03-12T14:37:53.714964","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10,\nUbuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to\nMySQL 5.0.95.\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\n\nhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-x.html\nhttp://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html\n","is_hidden":false,"release_packages":{"hardy":[{"name":"mysql-dfsg-5.0","version":"5.0.95-0ubuntu1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.0","version":"5.0.95-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.95-0ubuntu1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.61-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.61-0ubuntu0.10.04.1"}],"maverick":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.10.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.10.10.1"}],"natty":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.04.1"}],"oneiric":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2007-5925","CVE-2008-3963","CVE-2008-4098","CVE-2008-4456","CVE-2008-7247","CVE-2009-2446","CVE-2009-4019","CVE-2009-4030","CVE-2009-4484","CVE-2010-1621","CVE-2010-1626","CVE-2010-1848","CVE-2010-1849","CVE-2010-1850","CVE-2010-2008","CVE-2010-3677","CVE-2010-3678","CVE-2010-3679","CVE-2010-3680","CVE-2010-3681","CVE-2010-3682","CVE-2010-3683","CVE-2010-3833","CVE-2010-3834","CVE-2010-3835","CVE-2010-3836","CVE-2010-3837","CVE-2010-3838","CVE-2010-3839","CVE-2010-3840","CVE-2011-2262","CVE-2012-0075","CVE-2012-0087","CVE-2012-0101","CVE-2012-0102","CVE-2012-0112","CVE-2012-0113","CVE-2012-0114","CVE-2012-0115","CVE-2012-0116","CVE-2012-0117","CVE-2012-0118","CVE-2012-0119","CVE-2012-0120","CVE-2012-0484","CVE-2012-0485","CVE-2012-0486","CVE-2012-0487","CVE-2012-0488","CVE-2012-0489","CVE-2012-0490","CVE-2012-0491","CVE-2012-0492","CVE-2012-0493","CVE-2012-0494","CVE-2012-0495","CVE-2012-0496"]}]},{"id":"CVE-2011-3328","published":"2012-01-17T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when\ncolor-correction support is enabled, allows remote attackers to cause a\ndenial of service (divide-by-zero error and application crash) via a\nmalformed PNG image containing a cHRM chunk associated with a certain zero\nvalue.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"1.5.x only"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-3328"],"bugs":[""],"patches":{"libpng":[]},"tags":{},"packages":[{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-4868","published":"2012-01-15T03:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe logging functionality in dhcpd in ISC DHCP before 4.2.3-P2, when using\nDynamic DNS (DDNS) and issuing IPv6 addresses, does not properly handle the\nDHCPv6 lease structure, which allows remote attackers to cause a denial of\nservice (NULL pointer dereference and daemon crash) via crafted packets\nrelated to a lease-status update.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"vulnerable code was added in 4.2.2, and fixed in 4.2.3-P2"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.isc.org/software/dhcp/advisories/cve-2011-4868","https://www.cve.org/CVERecord?id=CVE-2011-4868"],"bugs":[""],"patches":{"isc-dhcp":[]},"tags":{},"packages":[{"name":"isc-dhcp","source":"https://ubuntu.com/security/cve?package=isc-dhcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=isc-dhcp","debian":"https://tracker.debian.org/pkg/isc-dhcp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"4.1.ESV-R4-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-5064","published":"2012-01-14T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDigestAuthenticator.java in the HTTP Digest Access Authentication\nimplementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and\n7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka\nprivate key), which makes it easier for remote attackers to bypass\ncryptographic protection mechanisms by leveraging knowledge of this string,\na different vulnerability than CVE-2011-1184.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"MITRE split this out from CVE-2011-1184."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1252-1","https://www.cve.org/CVERecord?id=CVE-2011-5064"],"bugs":[""],"patches":{"tomcat5.5":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1159309"],"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1158180"],"tomcat7":["upstream: http://svn.apache.org/viewvc?view=rev&rev=1087655"]},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.24-2ubuntu1.9","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6.0.28-2ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6.0.28-10ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6.0.32-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"7.0.21-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-5063","published":"2012-01-14T21:55:00","updated_at":"2025-07-17T16:42:36.245039+00:00","description":"\nThe HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x\nbefore 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check\nrealm values, which might allow remote attackers to bypass intended access\nrestrictions by leveraging the availability of a protection space with\nweaker authentication or authorization requirements, a different\nvulnerability than CVE-2011-1184.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"MITRE split this out from CVE-2011-1184."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1252-1","https://www.cve.org/CVERecord?id=CVE-2011-5063"],"bugs":[""],"patches":{"tomcat5.5":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1159309"],"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1158180"],"tomcat7":["upstream: http://svn.apache.org/viewvc?view=rev&rev=1087655"]},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.24-2ubuntu1.9","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6.0.28-2ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6.0.28-10ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6.0.32-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"7.0.21-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-5062","published":"2012-01-14T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x\nbefore 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop\nvalues, which might allow remote attackers to bypass intended\nintegrity-protection requirements via a qop=auth value, a different\nvulnerability than CVE-2011-1184.","ubuntu_description":"\nsbeattie> MITRE split this out from CVE-2011-1184","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.12","http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.33","http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.34","https://ubuntu.com/security/notices/USN-1252-1","https://www.cve.org/CVERecord?id=CVE-2011-5062"],"bugs":[""],"patches":{"tomcat5.5":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1159309"],"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1158180"],"tomcat7":["upstream: http://svn.apache.org/viewvc?view=rev&rev=1087655"]},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.24-2ubuntu1.9","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6.0.28-2ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6.0.28-10ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6.0.32-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"7.0.21-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0039","published":"2012-01-14T17:55:00","updated_at":"2025-08-04T19:24:05.313143+00:00","description":"\nGLib 2.31.8 and earlier, when the g_str_hash function is used, computes\nhash values without restricting the ability to trigger hash collisions\npredictably, which allows context-dependent attackers to cause a denial of\nservice (CPU consumption) via crafted input to an application that\nmaintains a hash table. NOTE: this issue may be disputed by the vendor; the\nexistence of the g_str_hash function is not a vulnerability in the library,\nbecause callers of g_hash_table_new and g_hash_table_new_full can specify\nan arbitrary hash function that is appropriate for the application.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"as of 2012-02-21, upstream has simply added a warning:\nhttp://git.gnome.org/browse/glib/commit/?id=030b3f25e3e5c018247e18bf309e0454ba138898\nhttp://git.gnome.org/browse/glib/commit/?id=12060df9f17a48cd4c7fda27a0af70c17c308ad9\n\nThis CVE is disputed by upstream, we will not be fixing this\nissue in stable releases"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2012/01/10/12","http://mail.gnome.org/archives/gtk-devel-list/2003-May/msg00111.html","https://www.cve.org/CVERecord?id=CVE-2012-0039"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=772720","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655044"],"patches":{"glib2.0":[]},"tags":{},"packages":[{"name":"glib2.0","source":"https://ubuntu.com/security/cve?package=glib2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glib2.0","debian":"https://tracker.debian.org/pkg/glib2.0","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-5060","published":"2012-01-13T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe par_mktmpdir function in the PAR module before 1.003 for Perl creates\ntemporary files in a directory with a predictable name without verifying\nownership and permissions of this directory, which allows local users to\noverwrite files when another user extracts a PAR packed program, a\ndifferent vulnerability in a different package than CVE-2011-4114.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"upstream and debian fixed this issue in libpar-packer-perl\nand libpar-perl identifying it as CVE-2011-4114; libpar-perl\nsubsequently got split off into this cve."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-5060"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=650707"],"patches":{"libpar-perl":[]},"tags":{},"packages":[{"name":"libpar-perl","source":"https://ubuntu.com/security/cve?package=libpar-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpar-perl","debian":"https://tracker.debian.org/pkg/libpar-perl","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.005-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.005-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.005-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.005-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.005","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-4114","published":"2012-01-13T18:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe par_mktmpdir function in the PAR::Packer module before 1.012 for Perl\ncreates temporary files in a directory with a predictable name without\nverifying ownership and permissions of this directory, which allows local\nusers to overwrite files when another user extracts a PAR packed program.\nNOTE: a similar vulnerability was reported for PAR, but this has been\nassigned a different CVE identifier.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"libpar-perl issued the fix for this issue annotated with\nCVE-2011-4114; however, it subsequently got split out into a\nseparate cve, CVE-2011-5060."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-4114"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=650706"],"patches":{"libpar-packer-perl":[],"libpar-perl":[]},"tags":{},"packages":[{"name":"libpar-packer-perl","source":"https://ubuntu.com/security/cve?package=libpar-packer-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpar-packer-perl","debian":"https://tracker.debian.org/pkg/libpar-packer-perl","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.012-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.012-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.012-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.012-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.012","component":null,"pocket":"security"}]},{"name":"libpar-perl","source":"https://ubuntu.com/security/cve?package=libpar-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpar-perl","debian":"https://tracker.debian.org/pkg/libpar-perl","statuses":[{"release_codename":"hardy","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"see CVE-2011-5060","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2776","published":"2012-01-13T18:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the Error function in super.c in Super 3.30.0 might\nallow local users to execute arbitrary code via vectors related to syslog\nlogging. NOTE: some of these details are obtained from third party\ninformation.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.debian.org/security/2012/dsa-2383","https://www.cve.org/CVERecord?id=CVE-2011-2776"],"bugs":[""],"patches":{"super":["upstream: http://anonscm.debian.org/gitweb/?p=users/robert/super.git;a=commitdiff;h=8fe29bb1b3d8d50f24005e9b997363c969973b31","upstream: http://anonscm.debian.org/gitweb/?p=users/robert/super.git;a=commitdiff;h=16bb78ad2bb86ca0576f134ee68490dfe864c947"]},"tags":{},"packages":[{"name":"super","source":"https://ubuntu.com/security/cve?package=super","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=super","debian":"https://tracker.debian.org/pkg/super","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.30.0-3+squeeze1build0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.30.0-3+squeeze1build0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.30.0-3+squeeze1build0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.30.0-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.30.0-6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-4925","published":"2012-01-13T04:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nTerascale Open-Source Resource and Queue Manager (aka TORQUE Resource\nManager) before 2.5.9, when munge authentication is used, allows remote\nauthenticated users to impersonate arbitrary user accounts via unspecified\nvectors.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"munge auth did not get added to torque until 2.5.3\nsee http://www.clusterresources.com/products/torque/docs/changelog.shtml#253"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-4925"],"bugs":[""],"patches":{"torque":[]},"tags":{},"packages":[{"name":"torque","source":"https://ubuntu.com/security/cve?package=torque","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=torque","debian":"https://tracker.debian.org/pkg/torque","statuses":[{"release_codename":"hardy","status":"not-affected","description":"no munge auth support","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"no munge auth support","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"no munge auth support","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"no munge auth support","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"no munge auth support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0207","published":"2012-01-13T00:00:00","updated_at":"2026-07-04T07:34:14.454335+00:00","description":"\nThe igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before\n3.2.1 allows remote attackers to cause a denial of service (divide-by-zero\nerror and panic) via IGMP packets.","ubuntu_description":"\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2012/01/10/5","http://article.gmane.org/gmane.linux.network/217256","https://ubuntu.com/security/notices/USN-1356-1","https://ubuntu.com/security/notices/USN-1363-1","https://ubuntu.com/security/notices/USN-1364-1","https://ubuntu.com/security/notices/USN-1380-1","https://ubuntu.com/security/notices/USN-1384-1","https://ubuntu.com/security/notices/USN-1386-1","https://www.cve.org/CVERecord?id=CVE-2012-0207"],"bugs":["https://launchpad.net/bugs/917848"],"patches":{"linux":["break-fix: 5b7c84066733c5dfb0e4016d939757b38de189e4 a8c1f65c79cbbb2f7da782d4c9d15639a9b94b27"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-13.56","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-16.27","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-9.16","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.4.0-1.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.9.0-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.10","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.18","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.3]","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.24","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.9]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.38-13.56~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.0-16.28~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-5.28","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-6.37","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-3.21]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-6.25","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-6.29","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-7.32","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-4.19]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-1209.21","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-1207.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1405.7","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.5.0-223.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1380-1","USN-1364-1","USN-1356-1","USN-1384-1","USN-1363-1","USN-1386-1"],"notices":[{"id":"USN-1380-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-02-29T01:15:19.881359","description":"\nA flaw was discovered in the TOMOYO LSM's handling of mount system calls.\nAn unprivileged user could oops the system causing a denial of service.\n(CVE-2011-2518)\n\nA bug was discovered in the Linux kernel's calculation of OOM (Out of\nmemory) scores, that would result in the wrong process being killed. A user\ncould use this to kill the process with the highest OOM score, even if that\nprocess belongs to another user or the system. (CVE-2011-4097)\n\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service. (CVE-2012-0207)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux","version":"2.6.38-13.56","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.38-13-powerpc","version":"2.6.38-13.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.56"},{"name":"linux-image-2.6.38-13-powerpc64-smp","version":"2.6.38-13.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.56"},{"name":"linux-image-2.6.38-13-generic-pae","version":"2.6.38-13.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.56"},{"name":"linux-image-2.6.38-13-versatile","version":"2.6.38-13.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.56"},{"name":"linux-image-2.6.38-13-generic","version":"2.6.38-13.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.56"},{"name":"linux-image-2.6.38-13-virtual","version":"2.6.38-13.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.56"},{"name":"linux-image-2.6.38-13-server","version":"2.6.38-13.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.56"},{"name":"linux-image-2.6.38-13-omap","version":"2.6.38-13.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.56"},{"name":"linux-image-2.6.38-13-powerpc-smp","version":"2.6.38-13.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.56"}]},"type":"USN","cves_ids":["CVE-2011-2518","CVE-2011-4097","CVE-2012-0207"]},{"id":"USN-1364-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-02-13T19:47:13.419688","description":"\nA bug was discovered in the Linux kernel's calculation of OOM (Out of\nmemory) scores, that would result in the wrong process being killed. A user\ncould use this to kill the process with the highest OOM score, even if that\nprocess belongs to another user or the system. (CVE-2011-4097)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nAndy Whitcroft discovered a that the Overlayfs filesystem was not doing the\nextended permission checks needed by cgroups and Linux Security Modules\n(LSMs). A local user could exploit this to by-pass security policy and\naccess files that should not be accessible. (CVE-2012-0055)\n\nJüri Aedla discovered that the kernel incorrectly handled /proc//mem\npermissions. A local attacker could exploit this and gain root privileges.\n(CVE-2012-0056)\n\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service. (CVE-2012-0207)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux-ti-omap4","version":"3.0.0-1207.16","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.0.0-1207-omap4","version":"3.0.0-1207.16","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.0.0-1207.16"}]},"type":"USN","cves_ids":["CVE-2011-4097","CVE-2012-0038","CVE-2012-0055","CVE-2012-0056","CVE-2012-0207"]},{"id":"USN-1356-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-02-06T21:30:45.227658","description":"\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service. (CVE-2012-0207)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux-ti-omap4","version":"2.6.38-1209.21","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.38-1209-omap4","version":"2.6.38-1209.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.38-1209.21"}]},"type":"USN","cves_ids":["CVE-2012-0038","CVE-2012-0044","CVE-2012-0207"]},{"id":"USN-1384-1","title":"Linux kernel (Oneiric backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-03-06T15:50:36.079301","description":"\nA bug was discovered in the Linux kernel's calculation of OOM (Out of\nmemory) scores, that would result in the wrong process being killed. A user\ncould use this to kill the process with the highest OOM score, even if that\nprocess belongs to another user or the system. (CVE-2011-4097)\n\nPaolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl\ncommand. A local user, or user in a VM could exploit this flaw to bypass\nrestrictions and gain read/write access to all data on the affected block\ndevice. (CVE-2011-4127)\n\nA flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual\ninterrupt control is not available a local user could use this to cause a\ndenial of service by starting a timer. (CVE-2011-4622)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nAndy Whitcroft discovered a that the Overlayfs filesystem was not doing the\nextended permission checks needed by cgroups and Linux Security Modules\n(LSMs). A local user could exploit this to by-pass security policy and\naccess files that should not be accessible. (CVE-2012-0055)\n\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service. (CVE-2012-0207)\n\nA flaw was found in the Linux kernel's ext4 file system when mounting a\ncorrupt filesystem. A user-assisted remote attacker could exploit this flaw\nto cause a denial of service. (CVE-2012-2100)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-oneiric","version":"3.0.0-16.29~lucid1","description":"Linux kernel backport from Oneiric","is_source":true},{"name":"linux-image-3.0.0-16-virtual","version":"3.0.0-16.29~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-16.29~lucid1"},{"name":"linux-image-3.0.0-16-generic","version":"3.0.0-16.29~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-16.29~lucid1"},{"name":"linux-image-3.0.0-16-server","version":"3.0.0-16.29~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-16.29~lucid1"},{"name":"linux-image-3.0.0-16-generic-pae","version":"3.0.0-16.29~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-16.29~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-4097","CVE-2011-4127","CVE-2011-4622","CVE-2012-0038","CVE-2012-0055","CVE-2012-0207","CVE-2012-2100"]},{"id":"USN-1363-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-02-13T19:21:48.098429","description":"\nA bug was discovered in the Linux kernel's calculation of OOM (Out of\nmemory) scores, that would result in the wrong process being killed. A user\ncould use this to kill the process with the highest OOM score, even if that\nprocess belongs to another user or the system. (CVE-2011-4097)\n\nA flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual\ninterrupt control is not available a local user could use this to cause a\ndenial of service by starting a timer. (CVE-2011-4622)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nAndy Whitcroft discovered a that the Overlayfs filesystem was not doing the\nextended permission checks needed by cgroups and Linux Security Modules\n(LSMs). A local user could exploit this to by-pass security policy and\naccess files that should not be accessible. (CVE-2012-0055)\n\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service. (CVE-2012-0207)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux","version":"3.0.0-16.28","description":"Linux kernel","is_source":true},{"name":"linux-image-3.0.0-16-server","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-powerpc-smp","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-virtual","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-powerpc64-smp","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-powerpc","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-generic-pae","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-omap","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"},{"name":"linux-image-3.0.0-16-generic","version":"3.0.0-16.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-16.28"}]},"type":"USN","cves_ids":["CVE-2012-0055","CVE-2012-0207","CVE-2011-4097","CVE-2011-4622","CVE-2012-0038"]},{"id":"USN-1386-1","title":"Linux kernel (Natty backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-03-06T18:00:29.397456","description":"The linux kernel did not properly account for PTE pages when deciding which\ntask to kill in out of memory conditions. A local, unprivileged could\nexploit this flaw to cause a denial of service. (CVE-2011-2498)\n\nA flaw was discovered in the TOMOYO LSM's handling of mount system calls.\nAn unprivileged user could oops the system causing a denial of service.\n(CVE-2011-2518)\n\nHan-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user\nwho can mount a FUSE file system could cause a denial of service.\n(CVE-2011-3353)\n\nA bug was discovered in the Linux kernel's calculation of OOM (Out of\nmemory) scores, that would result in the wrong process being killed. A user\ncould use this to kill the process with the highest OOM score, even if that\nprocess belongs to another user or the system. (CVE-2011-4097)\n\nA flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual\ninterrupt control is not available a local user could use this to cause a\ndenial of service by starting a timer. (CVE-2011-4622)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n\nA flaw was found in the linux kernels IPv4 IGMP query processing. A remote\nattacker could exploit this to cause a denial of service. (CVE-2012-0207)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-natty","version":"2.6.38-13.56~lucid1","description":"Linux kernel backport from Natty","is_source":true},{"name":"linux-image-2.6.38-13-virtual","version":"2.6.38-13.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.56~lucid1"},{"name":"linux-image-2.6.38-13-server","version":"2.6.38-13.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.56~lucid1"},{"name":"linux-image-2.6.38-13-generic-pae","version":"2.6.38-13.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.56~lucid1"},{"name":"linux-image-2.6.38-13-generic","version":"2.6.38-13.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.56~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-2498","CVE-2011-2518","CVE-2011-3353","CVE-2011-4097","CVE-2011-4622","CVE-2012-0038","CVE-2012-0044","CVE-2012-0207"]}]},{"id":"CVE-2012-0045","published":"2012-01-13T00:00:00","updated_at":"2026-07-04T07:34:14.454335+00:00","description":"\nThe em_syscall function in arch/x86/kvm/emulate.c in the KVM implementation\nin the Linux kernel before 3.2.14 does not properly handle the 0f05 (aka\nsyscall) opcode, which allows guest OS users to cause a denial of service\n(guest OS crash) via a crafted application, as demonstrated by an NASM\nfile.","ubuntu_description":"\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual machine)\nsubsystem of the Linux kernel. A local unprivileged user can crash use this\nflaw to crash VMs causing a deny of service.","notes":[{"author":"apw","note":"introduced by: e66bb2ccdcf76d032bbb464b35c292bb3ee58f9b\ncurrent patches appear to be on github but not approved and merged:\nhttps://github.com/baerwolf/linux-stephan/commit/a5fad9d83c19a4af9f41b48d78eb1688c8289c7e\nnow upstream (see below)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2012/01/11/4","https://lkml.org/lkml/2011/12/28/170","http://www.spinics.net/lists/kvm/msg66633.html","https://ubuntu.com/security/notices/USN-1407-1","https://ubuntu.com/security/notices/USN-1405-1","https://ubuntu.com/security/notices/USN-1406-1","https://ubuntu.com/security/notices/USN-1421-1","https://ubuntu.com/security/notices/USN-1422-1","https://ubuntu.com/security/notices/USN-1425-1","https://ubuntu.com/security/notices/USN-1426-1","https://ubuntu.com/security/notices/USN-1431-1","https://ubuntu.com/security/notices/USN-1433-1","https://ubuntu.com/security/notices/USN-1440-1","https://www.cve.org/CVERecord?id=CVE-2012-0045"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=773370","https://launchpad.net/bugs/917842"],"patches":{"linux":["break-fix: e66bb2ccdcf76d032bbb464b35c292bb3ee58f9b bdb42f5afebe208eae90406959383856ae2caf2b","break-fix: e66bb2ccdcf76d032bbb464b35c292bb3ee58f9b c2226fc9e87ba3da060e47333657cd6616652b84"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-armadaxp":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"oneiric","status":"released","description":"3.0.0-18.31","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-19.30","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.4.0-1.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.9.0-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-41.88","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-32.68","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-14.58","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1601.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-345.47","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.10","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.18","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.3]","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.24","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.9]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-32.68~lucid1","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.38-14.58~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.0-18.31~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-5.28","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-6.37","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-3.21]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-6.25","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-6.29","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-7.32","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-4.19]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1412.15","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.5.0-223.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1440-1","USN-1421-1","USN-1425-1","USN-1433-1","USN-1422-1","USN-1431-1","USN-1426-1"],"notices":[{"id":"USN-1440-1","title":"Linux kernel (Natty backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-05-08T07:41:27.732519","description":"\nA flaw was found in the Linux's kernels ext4 file system when mounted with\na journal. A local, unprivileged user could exploit this flaw to cause a\ndenial of service. (CVE-2011-4086)\n\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n\nA flaw was found in the Linux kernel's ext4 file system when mounting a\ncorrupt filesystem. A user-assisted remote attacker could exploit this flaw\nto cause a denial of service. (CVE-2012-2100)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-natty","version":"2.6.38-15.59~lucid1","description":"Linux kernel backport from Natty","is_source":true},{"name":"linux-image-2.6.38-15-generic","version":"2.6.38-15.59~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-15.59~lucid1"},{"name":"linux-image-2.6.38-15-virtual","version":"2.6.38-15.59~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-15.59~lucid1"},{"name":"linux-image-2.6.38-15-generic-pae","version":"2.6.38-15.59~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-15.59~lucid1"},{"name":"linux-image-2.6.38-15-server","version":"2.6.38-15.59~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-15.59~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-4086","CVE-2011-4347","CVE-2012-0045","CVE-2012-1090","CVE-2012-1097","CVE-2012-1146","CVE-2012-2100","CVE-2012-4398"]},{"id":"USN-1421-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-04-12T18:31:05.582752","description":"Sasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-32.68~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-32-virtual","version":"2.6.35-32.68~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.68~lucid1"},{"name":"linux-image-2.6.35-32-server","version":"2.6.35-32.68~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.68~lucid1"},{"name":"linux-image-2.6.35-32-generic-pae","version":"2.6.35-32.68~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.68~lucid1"},{"name":"linux-image-2.6.35-32-generic","version":"2.6.35-32.68~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.68~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-4347","CVE-2012-0045","CVE-2012-1097","CVE-2012-1146"]},{"id":"USN-1425-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-04-24T10:21:17.098314","description":"\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-41.88","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-41-server","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-preempt","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-ia64","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-generic-pae","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-386","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-generic","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-powerpc","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-sparc64","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-sparc64-smp","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-powerpc-smp","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-virtual","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-powerpc64-smp","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-versatile","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-lpia","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"}]},"type":"USN","cves_ids":["CVE-2011-4347","CVE-2012-0045","CVE-2012-1090","CVE-2012-1097","CVE-2012-4398"]},{"id":"USN-1433-1","title":"Linux kernel (Oneiric backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-05-01T05:24:25.806687","description":"\nA flaw was found in the Linux's kernels ext4 file system when mounted with\na journal. A local, unprivileged user could exploit this flaw to cause a\ndenial of service. (CVE-2011-4086)\n\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n\nA flaw was found in the Linux kernel's handling of paged memory. A local\nunprivileged user, or a privileged user within a KVM guest, could exploit\nthis flaw to crash the system. (CVE-2012-1179)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-oneiric","version":"3.0.0-19.33~lucid1","description":"Linux kernel backport from Oneiric","is_source":true},{"name":"linux-image-3.0.0-19-generic-pae","version":"3.0.0-19.33~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-19.33~lucid1"},{"name":"linux-image-3.0.0-19-server","version":"3.0.0-19.33~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-19.33~lucid1"},{"name":"linux-image-3.0.0-19-generic","version":"3.0.0-19.33~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-19.33~lucid1"},{"name":"linux-image-3.0.0-19-virtual","version":"3.0.0-19.33~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-19.33~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-4086","CVE-2011-4347","CVE-2012-0045","CVE-2012-1090","CVE-2012-1097","CVE-2012-1146","CVE-2012-1179","CVE-2012-4398"]},{"id":"USN-1422-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-04-12T19:09:45.844804","description":"Sasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux","version":"2.6.38-14.58","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.38-14-generic","version":"2.6.38-14.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-14.58"},{"name":"linux-image-2.6.38-14-powerpc-smp","version":"2.6.38-14.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-14.58"},{"name":"linux-image-2.6.38-14-virtual","version":"2.6.38-14.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-14.58"},{"name":"linux-image-2.6.38-14-omap","version":"2.6.38-14.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-14.58"},{"name":"linux-image-2.6.38-14-server","version":"2.6.38-14.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-14.58"},{"name":"linux-image-2.6.38-14-generic-pae","version":"2.6.38-14.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-14.58"},{"name":"linux-image-2.6.38-14-powerpc","version":"2.6.38-14.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-14.58"},{"name":"linux-image-2.6.38-14-powerpc64-smp","version":"2.6.38-14.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-14.58"},{"name":"linux-image-2.6.38-14-versatile","version":"2.6.38-14.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-14.58"}]},"type":"USN","cves_ids":["CVE-2012-1097","CVE-2012-0045","CVE-2011-4347","CVE-2012-1146"]},{"id":"USN-1431-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-05-01T03:41:26.564188","description":"\nA flaw was found in the Linux's kernels ext4 file system when mounted with\na journal. A local, unprivileged user could exploit this flaw to cause a\ndenial of service. (CVE-2011-4086)\n\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n\nA flaw was found in the Linux kernel's handling of paged memory. A local\nunprivileged user, or a privileged user within a KVM guest, could exploit\nthis flaw to crash the system. (CVE-2012-1179)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux","version":"3.0.0-19.33","description":"Linux kernel","is_source":true},{"name":"linux-image-3.0.0-19-generic-pae","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-powerpc","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-server","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-omap","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-generic","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-powerpc-smp","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-powerpc64-smp","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-virtual","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"}]},"type":"USN","cves_ids":["CVE-2012-4398","CVE-2012-1090","CVE-2012-1179","CVE-2011-4086","CVE-2011-4347","CVE-2012-0045","CVE-2012-1097","CVE-2012-1146"]},{"id":"USN-1426-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-04-24T10:29:11.445329","description":"\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-345.47","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-345-ec2","version":"2.6.32-345.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-345.47"}]},"type":"USN","cves_ids":["CVE-2011-4347","CVE-2012-0045","CVE-2012-1090","CVE-2012-1097","CVE-2012-4398"]}]}],"offset":70200,"limit":20,"total_results":79316}