{"cves":[{"id":"CVE-2011-4110","published":"2011-11-23T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe user_update function in security/keys/user_defined.c in the Linux\nkernel 2.6 allows local users to cause a denial of service (NULL pointer\ndereference and kernel oops) via vectors related to a user-defined key and\n\"updating a negative key into a fully instantiated key.\"","ubuntu_description":"\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2011/11/21/19","https://lkml.org/lkml/2011/11/15/363","https://ubuntu.com/security/notices/USN-1318-1","https://ubuntu.com/security/notices/USN-1319-1","https://ubuntu.com/security/notices/USN-1322-1","https://ubuntu.com/security/notices/USN-1323-1","https://ubuntu.com/security/notices/USN-1325-1","https://ubuntu.com/security/notices/USN-1324-1","https://ubuntu.com/security/notices/USN-1328-1","https://ubuntu.com/security/notices/USN-1330-1","https://ubuntu.com/security/notices/USN-1332-1","https://ubuntu.com/security/notices/USN-1337-1","https://ubuntu.com/security/notices/USN-1340-1","https://ubuntu.com/security/notices/USN-1341-1","https://ubuntu.com/security/notices/USN-1344-1","https://ubuntu.com/security/notices/USN-1345-1","https://ubuntu.com/security/notices/USN-1336-1","https://www.cve.org/CVERecord?id=CVE-2011-4110"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4110","https://launchpad.net/bugs/894369"],"patches":{"linux":["upstream: http://git.kernel.org/linus/9f35a33b8d06263a165efe3541d9aa0cdbd70b3b"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"released","description":"2.6.24-30.98","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-38.83","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-32.64","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-13.54","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-15.24","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-2.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.4.0-1.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.7.0-0.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.9.0-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1600.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1602.5","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-342.43","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.10","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.18","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.3]","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-612.32","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.24","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.9]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-32.64~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.38-13.54~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.0-15.25~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.5.0-18.29~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.8.0-19.30~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.11.0-13.20~precise2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-5.28","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-6.37","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-3.21]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-6.25","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-6.29","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-7.32","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-4.19]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-422.40","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.29","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-1209.19","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-1206.14","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1401.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1401.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.2.0-1401.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.5.0-223.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1319-1","USN-1318-1","USN-1337-1","USN-1341-1","USN-1340-1","USN-1332-1","USN-1328-1","USN-1325-1","USN-1336-1","USN-1344-1","USN-1330-1","USN-1323-1","USN-1345-1","USN-1324-1"],"notices":[{"id":"USN-1319-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-01-09T13:53:06.275164","description":"Peter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux-ti-omap4","version":"2.6.38-1209.19","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.38-1209-omap4","version":"2.6.38-1209.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.38-1209.19"}]},"type":"USN","cves_ids":["CVE-2011-1162","CVE-2011-2203","CVE-2011-4110"]},{"id":"USN-1318-1","title":"Linux kernel (FSL-IMX51) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-01-05T12:54:58.939688","description":"Peter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-612.32","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-612-imx51","version":"2.6.31-612.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-612.32"}]},"type":"USN","cves_ids":["CVE-2011-1162","CVE-2011-2203","CVE-2011-4110"]},{"id":"USN-1337-1","title":"Linux kernel (Natty backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-01-23T18:02:33.095596","description":"Peter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-natty","version":"2.6.38-13.54~lucid1","description":"Linux kernel backport from Natty","is_source":true},{"name":"linux-image-2.6.38-13-virtual","version":"2.6.38-13.54~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.54~lucid1"},{"name":"linux-image-2.6.38-13-server","version":"2.6.38-13.54~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.54~lucid1"},{"name":"linux-image-2.6.38-13-generic-pae","version":"2.6.38-13.54~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.54~lucid1"},{"name":"linux-image-2.6.38-13-generic","version":"2.6.38-13.54~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.54~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-1162","CVE-2011-2203","CVE-2011-4110"]},{"id":"USN-1341-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-01-23T21:59:39.620070","description":"\nPeter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nBen Hutchings reported a flaw in the kernel's handling of corrupt LDM\npartitions. A local user could exploit this to cause a denial of service or\nescalate privileges. (CVE-2011-2182)\n\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-32.64","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-32-powerpc64-smp","version":"2.6.35-32.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.64"},{"name":"linux-image-2.6.35-32-generic-pae","version":"2.6.35-32.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.64"},{"name":"linux-image-2.6.35-32-versatile","version":"2.6.35-32.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.64"},{"name":"linux-image-2.6.35-32-generic","version":"2.6.35-32.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.64"},{"name":"linux-image-2.6.35-32-virtual","version":"2.6.35-32.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.64"},{"name":"linux-image-2.6.35-32-powerpc-smp","version":"2.6.35-32.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.64"},{"name":"linux-image-2.6.35-32-powerpc","version":"2.6.35-32.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.64"},{"name":"linux-image-2.6.35-32-server","version":"2.6.35-32.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.64"},{"name":"linux-image-2.6.35-32-omap","version":"2.6.35-32.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.64"}]},"type":"USN","cves_ids":["CVE-2011-1162","CVE-2011-1759","CVE-2011-2182","CVE-2011-2203","CVE-2011-4110"]},{"id":"USN-1340-1","title":"Linux kernel (Oneiric backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-01-23T21:47:29.653032","description":"Clement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-oneiric","version":"3.0.0-15.25~lucid1","description":"Linux kernel backport from Oneiric","is_source":true},{"name":"linux-image-3.0.0-15-server","version":"3.0.0-15.25~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-15.25~lucid1"},{"name":"linux-image-3.0.0-15-generic","version":"3.0.0-15.25~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-15.25~lucid1"},{"name":"linux-image-3.0.0-15-virtual","version":"3.0.0-15.25~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-15.25~lucid1"},{"name":"linux-image-3.0.0-15-generic-pae","version":"3.0.0-15.25~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-15.25~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-2203","CVE-2011-4077","CVE-2011-4110","CVE-2011-4132","CVE-2011-4330","CVE-2012-0044"]},{"id":"USN-1332-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-01-13T05:52:56.298767","description":"\nPeter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nBen Hutchings reported a flaw in the kernel's handling of corrupt LDM\npartitions. A local user could exploit this to cause a denial of service or\nescalate privileges. (CVE-2011-2182)\n\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-32.64~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-32-virtual","version":"2.6.35-32.64~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.64~lucid1"},{"name":"linux-image-2.6.35-32-server","version":"2.6.35-32.64~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.64~lucid1"},{"name":"linux-image-2.6.35-32-generic-pae","version":"2.6.35-32.64~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.64~lucid1"},{"name":"linux-image-2.6.35-32-generic","version":"2.6.35-32.64~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.64~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-1162","CVE-2011-1759","CVE-2011-2182","CVE-2011-2203","CVE-2011-4110"]},{"id":"USN-1328-1","title":"Linux kernel (Marvell DOVE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-01-13T05:28:40.591318","description":"Clement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-422.40","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-422-dove","version":"2.6.32-422.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-422.40"}]},"type":"USN","cves_ids":["CVE-2011-2203","CVE-2011-4110"]},{"id":"USN-1325-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-01-11T10:56:12.558080","description":"Peter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nHan-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user\nwho can mount a FUSE file system could cause a denial of service.\n(CVE-2011-3353)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.29","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.29","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.29"}]},"type":"USN","cves_ids":["CVE-2011-3359","CVE-2011-4110","CVE-2011-1162","CVE-2011-2203","CVE-2011-3353"]},{"id":"USN-1336-1","title":"Linux kernel vulnerability","summary":"The system could be made to run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-01-23T15:02:11.134528","description":"\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n\nJüri Aedla discovered that the kernel incorrectly handled /proc//mem\npermissions. A local attacker could exploit this and gain root privileges.\n(CVE-2012-0056)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux","version":"3.0.0-15.26","description":"Linux kernel","is_source":true},{"name":"linux-image-3.0.0-15-omap","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-generic","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-powerpc-smp","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-server","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-generic-pae","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-powerpc64-smp","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-powerpc","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-virtual","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"}]},"type":"USN","cves_ids":["CVE-2011-2203","CVE-2011-4077","CVE-2011-4110","CVE-2011-4132","CVE-2011-4330","CVE-2012-0044","CVE-2012-0056"]},{"id":"USN-1344-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-01-24T17:29:37.333204","description":"Clement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-38.83","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-38-powerpc","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-386","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-sparc64","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-generic-pae","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-preempt","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-lpia","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-sparc64-smp","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-powerpc64-smp","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-versatile","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-generic","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-ia64","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-server","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-powerpc-smp","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"},{"name":"linux-image-2.6.32-38-virtual","version":"2.6.32-38.83","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-38.83"}]},"type":"USN","cves_ids":["CVE-2011-2203","CVE-2011-4110"]},{"id":"USN-1330-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-01-13T05:41:54.078481","description":"\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux-ti-omap4","version":"3.0.0-1206.15","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.0.0-1206-omap4","version":"3.0.0-1206.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.0.0-1206.15"}]},"type":"USN","cves_ids":["CVE-2011-2203","CVE-2011-4077","CVE-2011-4110","CVE-2011-4132","CVE-2011-4330","CVE-2012-0044"]},{"id":"USN-1323-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-01-11T10:20:56.116126","description":"Peter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-30.98","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-30-virtual","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-server","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-mckinley","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-sparc64-smp","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-xen","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-powerpc-smp","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-lpiacompat","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-sparc64","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-rt","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-openvz","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-lpia","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-hppa64","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-386","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-powerpc","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-powerpc64-smp","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-itanium","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-hppa32","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"},{"name":"linux-image-2.6.24-30-generic","version":"2.6.24-30.98","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.98"}]},"type":"USN","cves_ids":["CVE-2011-1162","CVE-2011-2203","CVE-2011-3359","CVE-2011-4110"]},{"id":"USN-1345-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-01-24T17:38:31.838199","description":"Peter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux","version":"2.6.38-13.54","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.38-13-powerpc","version":"2.6.38-13.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.54"},{"name":"linux-image-2.6.38-13-powerpc64-smp","version":"2.6.38-13.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.54"},{"name":"linux-image-2.6.38-13-generic-pae","version":"2.6.38-13.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.54"},{"name":"linux-image-2.6.38-13-versatile","version":"2.6.38-13.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.54"},{"name":"linux-image-2.6.38-13-generic","version":"2.6.38-13.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.54"},{"name":"linux-image-2.6.38-13-virtual","version":"2.6.38-13.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.54"},{"name":"linux-image-2.6.38-13-server","version":"2.6.38-13.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.54"},{"name":"linux-image-2.6.38-13-omap","version":"2.6.38-13.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.54"},{"name":"linux-image-2.6.38-13-powerpc-smp","version":"2.6.38-13.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.54"}]},"type":"USN","cves_ids":["CVE-2011-1162","CVE-2011-2203","CVE-2011-4110"]},{"id":"USN-1324-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Two security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-01-11T11:30:27.373045","description":"Clement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-342.43","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-342-ec2","version":"2.6.32-342.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-342.43"}]},"type":"USN","cves_ids":["CVE-2011-2203","CVE-2011-4110"]}]},{"id":"CVE-2011-3150","published":"2011-11-21T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSoftware Center in Ubuntu 11.10, 11.04 10.10 does not properly validate\nserver certificates, which allows remote attackers to execute arbitrary\ncode or obtain sensitive information via a man-in-the-middle (MITM) attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1270-1","https://www.cve.org/CVERecord?id=CVE-2011-3150"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/software-center/+bug/874242"],"patches":{"software-center":[]},"tags":{},"packages":[{"name":"software-center","source":"https://ubuntu.com/security/cve?package=software-center","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=software-center","debian":"https://tracker.debian.org/pkg/software-center","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.10ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"4.0.5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"5.0.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1270-1"],"notices":[{"id":"USN-1270-1","title":"Software Center vulnerability","summary":"An attacker could trick Software Center into installing altered packages\nand repositories or exposing sensitive information over the network.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-11-21T18:20:15.362891","description":"David B. discovered that Software Center incorrectly validated server\ncertificates when performing secure connections. If a remote attacker were\nable to perform a machine-in-the-middle attack, this flaw could be exploited to\nview sensitive information or install altered packages and repositories.\n","is_hidden":false,"release_packages":{"maverick":[{"name":"software-center","version":"3.0.10ubuntu0.1","description":"Utility for browsing, installing, and removing applications","is_source":true},{"name":"software-center","version":"3.0.10ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/software-center","version_link":"https://launchpad.net/ubuntu/+source/software-center/3.0.10ubuntu0.1"}],"natty":[{"name":"software-center","version":"4.0.5ubuntu0.1","description":"Utility for browsing, installing, and removing applications","is_source":true},{"name":"software-center","version":"4.0.5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/software-center","version_link":"https://launchpad.net/ubuntu/+source/software-center/4.0.5ubuntu0.1"}],"oneiric":[{"name":"software-center","version":"5.0.2ubuntu0.1","description":"Utility for browsing, installing, and removing software","is_source":true},{"name":"software-center","version":"5.0.2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/software-center","version_link":"https://launchpad.net/ubuntu/+source/software-center/5.0.2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2011-3150"]}]},{"id":"CVE-2011-4404","published":"2011-11-19T03:58:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of the HTTP server in Jetty in vSphere Update\nManager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before\nUpdate 2 allows remote attackers to conduct directory traversal attacks and\nread arbitrary files via unspecified vectors, a related issue to\nCVE-2009-1523.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"There are few details at this point and it isn't clear if jetty in\nUbuntu is affected or not.\nDebian marked this CVE as NOT-FOR-US"},{"author":"mdeslaur","note":"looks like the bundled jetty in vsphere had not been fixed for\nCVE-2009-1523. Marking as not-affected."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-4404"],"bugs":[""],"patches":{"jetty":[]},"tags":{},"packages":[{"name":"jetty","source":"https://ubuntu.com/security/cve?package=jetty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jetty","debian":"https://tracker.debian.org/pkg/jetty","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-4318","published":"2011-11-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname\nis used to define the proxy destination, does not verify that the server\nhostname matches a domain name in the subject's Common Name (CN) of the\nX.509 certificate, which allows man-in-the-middle attackers to spoof SSL\nservers via a valid certificate for a different hostname.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"SSL proxy connections were added in some Dovecot v1.x versions, but\nbut v1.x doesn't support giving hostname as proxy destination, only IP\naddress. (per upstream)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2011/11/18/4","http://www.dovecot.org/list/dovecot-news/2011-November/000200.html","https://ubuntu.com/security/notices/USN-1295-1","https://www.cve.org/CVERecord?id=CVE-2011-4318"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=649511"],"patches":{"dovecot":["upstream: http://hg.dovecot.org/dovecot-2.0/rev/5e9eaf63a6b1","upstream: http://hg.dovecot.org/dovecot-2.0/rev/de8715e4d793","upstream: http://hg.dovecot.org/dovecot-2.0/rev/4294e9136cd6"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1:1.2.15-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1:2.0.13-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.16","component":null,"pocket":"security"}]}],"notices_ids":["USN-1295-1"],"notices":[{"id":"USN-1295-1","title":"Dovecot vulnerability","summary":"Dovecot could be made to expose sensitive information over the network.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-12-08T19:31:54.468121","description":"It was discovered that Dovecot incorrectly validated certificate hostnames\nwhen being used as a POP3 and IMAP proxy. If a remote attacker were able to\nperform a machine-in-the-middle attack, this flaw could be exploited to view\nsensitive information.\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"dovecot","version":"1:2.0.13-1ubuntu3.2","description":"IMAP and POP3 email server","is_source":true},{"name":"dovecot-common","version":"1:2.0.13-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dovecot","version_link":"https://launchpad.net/ubuntu/+source/dovecot/1:2.0.13-1ubuntu3.2"}]},"type":"USN","cves_ids":["CVE-2011-4318"]}]},{"id":"CVE-2011-4132","published":"2011-11-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cleanup_journal_tail function in the Journaling Block Device (JBD)\nfunctionality in the Linux kernel 2.6 allows local users to cause a denial\nof service (assertion error and kernel oops) via an ext3 or ext4 image with\nan \"invalid log first block value.\"","ubuntu_description":"\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2011/11/13/4","https://ubuntu.com/security/notices/USN-1286-1","https://ubuntu.com/security/notices/USN-1291-1","https://ubuntu.com/security/notices/USN-1292-1","https://ubuntu.com/security/notices/USN-1293-1","https://ubuntu.com/security/notices/USN-1302-1","https://ubuntu.com/security/notices/USN-1301-1","https://ubuntu.com/security/notices/USN-1303-1","https://ubuntu.com/security/notices/USN-1299-1","https://ubuntu.com/security/notices/USN-1304-1","https://ubuntu.com/security/notices/USN-1300-1","https://ubuntu.com/security/notices/USN-1311-1","https://ubuntu.com/security/notices/USN-1312-1","https://ubuntu.com/security/notices/USN-1322-1","https://ubuntu.com/security/notices/USN-1330-1","https://ubuntu.com/security/notices/USN-1340-1","https://ubuntu.com/security/notices/USN-1336-1","https://www.cve.org/CVERecord?id=CVE-2011-4132"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=753341","https://launchpad.net/bugs/893148"],"patches":{"linux":["upstream: 8762202dd0d6e46854f786bdb6fb3780a1625efe"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"released","description":"2.6.24-30.97","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-37.81","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-31.63","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-13.53","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-15.24","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.4.0-1.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.7.0-0.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.9.0-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1600.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1602.5","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-341.42","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.10","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.18","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.3]","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-612.31","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.24","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.9]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-31.63~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.38-13.53~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.0-15.25~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.5.0-18.29~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.8.0-19.30~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.11.0-13.20~precise2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-5.28","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-6.37","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-3.21]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-6.25","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-6.29","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-7.32","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-4.19]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-421.39","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.28","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-1209.18","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-1206.14","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1401.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1401.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.2.0-1401.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.5.0-223.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1292-1","USN-1302-1","USN-1299-1","USN-1340-1","USN-1301-1","USN-1336-1","USN-1312-1","USN-1303-1","USN-1293-1","USN-1311-1","USN-1330-1","USN-1300-1","USN-1304-1","USN-1291-1"],"notices":[{"id":"USN-1292-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-12-08T11:24:44.418848","description":"A bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nNick Bowler discovered the kernel GHASH message digest algorithm\nincorrectly handled error conditions. A local attacker could exploit this\nto cause a kernel oops. (CVE-2011-4081)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nA bug was found in the way headroom check was performed in\nudp6_ufo_fragment() function. A remote attacker could use this flaw to\ncrash the system. (CVE-2011-4326)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-31.63~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-31-generic-pae","version":"2.6.35-31.63~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-31.63~lucid1"},{"name":"linux-image-2.6.35-31-server","version":"2.6.35-31.63~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-31.63~lucid1"},{"name":"linux-image-2.6.35-31-virtual","version":"2.6.35-31.63~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-31.63~lucid1"},{"name":"linux-image-2.6.35-31-generic","version":"2.6.35-31.63~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-31.63~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-4077","CVE-2011-4081","CVE-2011-4132","CVE-2011-4326","CVE-2011-4330"]},{"id":"USN-1302-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-12-13T13:05:40.662943","description":"A bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nNick Bowler discovered the kernel GHASH message digest algorithm\nincorrectly handled error conditions. A local attacker could exploit this\nto cause a kernel oops. (CVE-2011-4081)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nA bug was found in the way headroom check was performed in\nudp6_ufo_fragment() function. A remote attacker could use this flaw to\ncrash the system. (CVE-2011-4326)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.28","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.28"}]},"type":"USN","cves_ids":["CVE-2011-4077","CVE-2011-4081","CVE-2011-4132","CVE-2011-4326","CVE-2011-4330"]},{"id":"USN-1299-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-12-13T10:25:47.860638","description":"\nPeter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nZheng Liu discovered a flaw in how the ext4 filesystem splits extents. A\nlocal unprivileged attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-3638)\n\nA bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nNick Bowler discovered the kernel GHASH message digest algorithm\nincorrectly handled error conditions. A local attacker could exploit this\nto cause a kernel oops. (CVE-2011-4081)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nA bug was found in the way headroom check was performed in\nudp6_ufo_fragment() function. A remote attacker could use this flaw to\ncrash the system. (CVE-2011-4326)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-341.42","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-341-ec2","version":"2.6.32-341.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-341.42"}]},"type":"USN","cves_ids":["CVE-2011-1162","CVE-2011-3638","CVE-2011-4077","CVE-2011-4081","CVE-2011-4132","CVE-2011-4326","CVE-2011-4330"]},{"id":"USN-1340-1","title":"Linux kernel (Oneiric backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-01-23T21:47:29.653032","description":"Clement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-oneiric","version":"3.0.0-15.25~lucid1","description":"Linux kernel backport from Oneiric","is_source":true},{"name":"linux-image-3.0.0-15-server","version":"3.0.0-15.25~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-15.25~lucid1"},{"name":"linux-image-3.0.0-15-generic","version":"3.0.0-15.25~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-15.25~lucid1"},{"name":"linux-image-3.0.0-15-virtual","version":"3.0.0-15.25~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-15.25~lucid1"},{"name":"linux-image-3.0.0-15-generic-pae","version":"3.0.0-15.25~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-15.25~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-2203","CVE-2011-4077","CVE-2011-4110","CVE-2011-4132","CVE-2011-4330","CVE-2012-0044"]},{"id":"USN-1301-1","title":"Linux kernel (Natty backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-12-13T12:56:44.790383","description":"A bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nNick Bowler discovered the kernel GHASH message digest algorithm\nincorrectly handled error conditions. A local attacker could exploit this\nto cause a kernel oops. (CVE-2011-4081)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-natty","version":"2.6.38-13.53~lucid1","description":"Linux kernel backport from Natty","is_source":true},{"name":"linux-image-2.6.38-13-virtual","version":"2.6.38-13.53~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.53~lucid1"},{"name":"linux-image-2.6.38-13-server","version":"2.6.38-13.53~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.53~lucid1"},{"name":"linux-image-2.6.38-13-generic-pae","version":"2.6.38-13.53~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.53~lucid1"},{"name":"linux-image-2.6.38-13-generic","version":"2.6.38-13.53~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-13.53~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-4077","CVE-2011-4081","CVE-2011-4132","CVE-2011-4330"]},{"id":"USN-1336-1","title":"Linux kernel vulnerability","summary":"The system could be made to run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-01-23T15:02:11.134528","description":"\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n\nJüri Aedla discovered that the kernel incorrectly handled /proc//mem\npermissions. A local attacker could exploit this and gain root privileges.\n(CVE-2012-0056)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux","version":"3.0.0-15.26","description":"Linux kernel","is_source":true},{"name":"linux-image-3.0.0-15-omap","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-generic","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-powerpc-smp","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-server","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-generic-pae","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-powerpc64-smp","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-powerpc","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"},{"name":"linux-image-3.0.0-15-virtual","version":"3.0.0-15.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-15.26"}]},"type":"USN","cves_ids":["CVE-2011-2203","CVE-2011-4077","CVE-2011-4110","CVE-2011-4132","CVE-2011-4330","CVE-2012-0044","CVE-2012-0056"]},{"id":"USN-1312-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-12-19T19:57:22.414970","description":"A bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nNick Bowler discovered the kernel GHASH message digest algorithm\nincorrectly handled error conditions. A local attacker could exploit this\nto cause a kernel oops. (CVE-2011-4081)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux","version":"2.6.38-13.53","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.38-13-powerpc","version":"2.6.38-13.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.53"},{"name":"linux-image-2.6.38-13-powerpc64-smp","version":"2.6.38-13.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.53"},{"name":"linux-image-2.6.38-13-generic-pae","version":"2.6.38-13.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.53"},{"name":"linux-image-2.6.38-13-versatile","version":"2.6.38-13.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.53"},{"name":"linux-image-2.6.38-13-generic","version":"2.6.38-13.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.53"},{"name":"linux-image-2.6.38-13-virtual","version":"2.6.38-13.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.53"},{"name":"linux-image-2.6.38-13-server","version":"2.6.38-13.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.53"},{"name":"linux-image-2.6.38-13-omap","version":"2.6.38-13.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.53"},{"name":"linux-image-2.6.38-13-powerpc-smp","version":"2.6.38-13.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-13.53"}]},"type":"USN","cves_ids":["CVE-2011-4077","CVE-2011-4081","CVE-2011-4132","CVE-2011-4330"]},{"id":"USN-1303-1","title":"Linux kernel (Marvell DOVE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-12-13T13:11:45.163100","description":"Peter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nA bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nNick Bowler discovered the kernel GHASH message digest algorithm\nincorrectly handled error conditions. A local attacker could exploit this\nto cause a kernel oops. (CVE-2011-4081)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nA bug was found in the way headroom check was performed in\nudp6_ufo_fragment() function. A remote attacker could use this flaw to\ncrash the system. (CVE-2011-4326)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-421.39","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-421-dove","version":"2.6.32-421.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-421.39"}]},"type":"USN","cves_ids":["CVE-2011-1162","CVE-2011-4077","CVE-2011-4081","CVE-2011-4132","CVE-2011-4326","CVE-2011-4330"]},{"id":"USN-1293-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-12-08T11:36:00.759518","description":"A bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nNick Bowler discovered the kernel GHASH message digest algorithm\nincorrectly handled error conditions. A local attacker could exploit this\nto cause a kernel oops. (CVE-2011-4081)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nA bug was found in the way headroom check was performed in\nudp6_ufo_fragment() function. A remote attacker could use this flaw to\ncrash the system. (CVE-2011-4326)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-31.63","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-31-generic-pae","version":"2.6.35-31.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63"},{"name":"linux-image-2.6.35-31-omap","version":"2.6.35-31.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63"},{"name":"linux-image-2.6.35-31-server","version":"2.6.35-31.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63"},{"name":"linux-image-2.6.35-31-powerpc-smp","version":"2.6.35-31.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63"},{"name":"linux-image-2.6.35-31-versatile","version":"2.6.35-31.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63"},{"name":"linux-image-2.6.35-31-powerpc64-smp","version":"2.6.35-31.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63"},{"name":"linux-image-2.6.35-31-generic","version":"2.6.35-31.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63"},{"name":"linux-image-2.6.35-31-powerpc","version":"2.6.35-31.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63"},{"name":"linux-image-2.6.35-31-virtual","version":"2.6.35-31.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63"}]},"type":"USN","cves_ids":["CVE-2011-4326","CVE-2011-4077","CVE-2011-4081","CVE-2011-4132","CVE-2011-4330"]},{"id":"USN-1311-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-12-19T19:53:00.811536","description":"\nPeter Huewe discovered an information leak in the handling of reading\nsecurity-related TPM data. A local, unprivileged user could read the\nresults of a previous TPM command. (CVE-2011-1162)\n\nZheng Liu discovered a flaw in how the ext4 filesystem splits extents. A\nlocal unprivileged attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-3638)\n\nA bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nNick Bowler discovered the kernel GHASH message digest algorithm\nincorrectly handled error conditions. A local attacker could exploit this\nto cause a kernel oops. (CVE-2011-4081)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nA bug was found in the way headroom check was performed in\nudp6_ufo_fragment() function. A remote attacker could use this flaw to\ncrash the system. (CVE-2011-4326)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-37.81","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-37-386","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-powerpc","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-powerpc64-smp","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-generic-pae","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-sparc64","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-generic","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-virtual","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-server","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-ia64","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-sparc64-smp","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-preempt","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-powerpc-smp","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-lpia","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"},{"name":"linux-image-2.6.32-37-versatile","version":"2.6.32-37.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-37.81"}]},"type":"USN","cves_ids":["CVE-2011-3638","CVE-2011-1162","CVE-2011-4077","CVE-2011-4081","CVE-2011-4132","CVE-2011-4326","CVE-2011-4330"]},{"id":"USN-1330-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-01-13T05:41:54.078481","description":"\nClement Lecigne discovered a bug in the HFS filesystem. A local attacker\ncould exploit this to cause a kernel oops. (CVE-2011-2203)\n\nA bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nA flaw was found in how the Linux kernel handles user-defined key types. An\nunprivileged local user could exploit this to crash the system.\n(CVE-2011-4110)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux-ti-omap4","version":"3.0.0-1206.15","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.0.0-1206-omap4","version":"3.0.0-1206.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.0.0-1206.15"}]},"type":"USN","cves_ids":["CVE-2011-2203","CVE-2011-4077","CVE-2011-4110","CVE-2011-4132","CVE-2011-4330","CVE-2012-0044"]},{"id":"USN-1300-1","title":"Linux kernel (FSL-IMX51) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-12-13T12:41:45.459725","description":"A bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-612.31","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-612-imx51","version":"2.6.31-612.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-612.31"}]},"type":"USN","cves_ids":["CVE-2011-4077","CVE-2011-4132","CVE-2011-4330"]},{"id":"USN-1304-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-12-13T13:18:26.994218","description":"A bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nNick Bowler discovered the kernel GHASH message digest algorithm\nincorrectly handled error conditions. A local attacker could exploit this\nto cause a kernel oops. (CVE-2011-4081)\n\nScot Doyle discovered that the bridge networking interface incorrectly\nhandled certain network packets. A remote attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2011-4087)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nA bug was found in the way headroom check was performed in\nudp6_ufo_fragment() function. A remote attacker could use this flaw to\ncrash the system. (CVE-2011-4326)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux-ti-omap4","version":"2.6.38-1209.18","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.38-1209-omap4","version":"2.6.38-1209.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.38-1209.18"}]},"type":"USN","cves_ids":["CVE-2011-4077","CVE-2011-4081","CVE-2011-4087","CVE-2011-4132","CVE-2011-4326","CVE-2011-4330"]},{"id":"USN-1291-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-12-08T10:50:31.335829","description":"A bug was discovered in the XFS filesystem's handling of pathnames. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or gain root privileges. (CVE-2011-4077)\n\nA flaw was found in the Journaling Block Device (JBD). A local attacker\nable to mount ext3 or ext4 file systems could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-4132)\n\nClement Lecigne discovered a bug in the HFS file system bounds checking.\nWhen a malformed HFS file system is mounted a local user could crash the\nsystem or gain root privileges. (CVE-2011-4330)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-30.97","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-30-virtual","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-server","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-mckinley","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-sparc64-smp","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-xen","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-powerpc-smp","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-lpiacompat","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-sparc64","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-rt","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-openvz","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-lpia","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-hppa64","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-386","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-powerpc","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-powerpc64-smp","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-itanium","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-hppa32","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"},{"name":"linux-image-2.6.24-30-generic","version":"2.6.24-30.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97"}]},"type":"USN","cves_ids":["CVE-2011-4077","CVE-2011-4132","CVE-2011-4330"]}]},{"id":"CVE-2011-3900","published":"2011-11-17T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle V8, as used in Google Chrome before 15.0.874.121, allows remote\nattackers to cause a denial of service or possibly have unspecified other\nimpact via unknown vectors that trigger an out-of-bounds write operation.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-3900"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"15.0.874.121","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-4107","published":"2011-11-17T19:55:00","updated_at":"2025-08-25T20:18:35.914923+00:00","description":"\nThe simplexml_load_string function in the XML import plug-in\n(libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x\nbefore 3.3.10.5 allows remote authenticated users to read arbitrary files\nvia XML data containing external entity references, aka an XML external\nentity (XXE) injection attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-4107"],"bugs":[""],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"4:3.4.7.1-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"4:3.4.7.1-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"4:3.4.7.1-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"4:3.4.7.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:3.4.7.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-4096","published":"2011-11-17T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe idnsGrokReply function in Squid before 3.1.16 does not properly free\nmemory, which allows remote attackers to cause a denial of service (daemon\nabort) via a DNS reply containing a CNAME record that references another\nCNAME record that contains an empty A record.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-4096"],"bugs":[""],"patches":{"squid3":["vendor: https://rhn.redhat.com/errata/RHSA-2011-1791.html","vendor: http://www.debian.org/security/2012/dsa-2381"]},"tags":{},"packages":[{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.1.6-1.1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.1.11-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.1.14-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.16-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-4073","published":"2011-11-17T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the cryptographic helper handler\nfunctionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated\nusers to cause a denial of service (pluto IKE daemon crash) via vectors\nrelated to the (1) quick_outI1_continue and (2) quick_outI1 functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://openswan.org/security/CVE-2011-4073.php","https://www.cve.org/CVERecord?id=CVE-2011-4073"],"bugs":[""],"patches":{"openswan":["upstream: http://openswan.org/download/CVE-2011-4073/openswan-2.x.x-CVE-2011-4073.patch","vendor: http://www.debian.org/security/2011/dsa-2374"]},"tags":{},"packages":[{"name":"openswan","source":"https://ubuntu.com/security/cve?package=openswan","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openswan","debian":"https://tracker.debian.org/pkg/openswan","statuses":[{"release_codename":"hardy","status":"released","description":"1:2.4.9+dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1:2.6.28+dfsg-5squeeze1build0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1:2.6.37-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1:2.6.37-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1:2.6.37-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1:2.6.37-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3646","published":"2011-11-17T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nphpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers\nto obtain sensitive information via an array-typed js_frame parameter to\nphpmyadmin.css.php, which reveals the installation path in an error\nmessage.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-3646"],"bugs":[""],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4:3.3.10-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"4:3.4.6-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"4:3.4.6-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"4:3.4.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:3.4.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3380","published":"2011-11-17T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of\nservice (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP\nmessage with an invalid KEY_LENGTH attribute, which is not properly handled\nby the error handling function.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in openswan 2.6.29"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-3380"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3380"],"patches":{"openswan":[]},"tags":{},"packages":[{"name":"openswan","source":"https://ubuntu.com/security/cve?package=openswan","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openswan","debian":"https://tracker.debian.org/pkg/openswan","statuses":[{"release_codename":"hardy","status":"not-affected","description":"1:2.4.9+dfsg-1build1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1:2.6.23+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1:2.6.28+dfsg-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1:2.6.28+dfsg-5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2770","published":"2011-11-17T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in man2html.cgi.c in man2html 1.6,\nand possibly other version, allows remote attackers to inject arbitrary web\nscript or HTML via unspecified vectors related to error messages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2770"],"bugs":[""],"patches":{"man2html":["vendor: http://www.debian.org/security/2011/dsa-2335"]},"tags":{},"packages":[{"name":"man2html","source":"https://ubuntu.com/security/cve?package=man2html","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=man2html","debian":"https://tracker.debian.org/pkg/man2html","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.6g-6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.6g-6","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.6g-6","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.6g-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-4405","published":"2011-11-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cupshelpers scripts in system-config-printer in Ubuntu 11.04 and 11.10,\nas used by the automatic printer driver download service, uses an \"insecure\nconnection\" for queries to the OpenPrinting database, which allows remote\nattackers to execute arbitrary code via a man-in-the-middle (MITM) attack\nthat modifies packages or repositories.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"fingerprints are only supported on natty+"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1265-1","https://www.cve.org/CVERecord?id=CVE-2011-4405"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/system-config-printer/+bug/882553"],"patches":{"system-config-printer":[]},"tags":{},"packages":[{"name":"system-config-printer","source":"https://ubuntu.com/security/cve?package=system-config-printer","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=system-config-printer","debian":"https://tracker.debian.org/pkg/system-config-printer","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.3.1+20110222-0ubuntu16.5","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.3.6+20110831-0ubuntu9.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1265-1"],"notices":[{"id":"USN-1265-1","title":"system-config-printer vulnerability","summary":"An attacker could trick system-config-printer into installing altered\npackages and repositories.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-11-17T15:05:11.250400","description":"Marc Deslauriers discovered that system-config-printer's cupshelpers\nscripts used by the Ubuntu automatic printer driver download service\nqueried the OpenPrinting database using an insecure connection. If a remote\nattacker were able to perform a machine-in-the-middle attack, this flaw could\nbe exploited to install altered packages and repositories.\n","is_hidden":false,"release_packages":{"natty":[{"name":"system-config-printer","version":"1.3.1+20110222-0ubuntu16.5","description":"CUPS integration with HAL","is_source":true},{"name":"python-cupshelpers","version":"1.3.1+20110222-0ubuntu16.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/system-config-printer","version_link":"https://launchpad.net/ubuntu/+source/system-config-printer/1.3.1+20110222-0ubuntu16.5"}],"oneiric":[{"name":"system-config-printer","version":"1.3.6+20110831-0ubuntu9.4","description":"Python modules for printer configuration with CUPS","is_source":true},{"name":"python-cupshelpers","version":"1.3.6+20110831-0ubuntu9.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/system-config-printer","version_link":"https://launchpad.net/ubuntu/+source/system-config-printer/1.3.6+20110831-0ubuntu9.4"}]},"type":"USN","cves_ids":["CVE-2011-4405"]}]},{"id":"CVE-2011-4313","published":"2011-11-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nquery.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5,\n9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and\n9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of\nservice (assertion failure and named exit) via unknown vectors related to\nrecursive DNS queries, error logging, and the caching of an invalid record\nby the resolver.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.isc.org/software/bind/advisories/cve-2011-4313","https://ubuntu.com/security/notices/USN-1264-1","https://www.cve.org/CVERecord?id=CVE-2011-4313"],"bugs":[""],"patches":{"bind9":[]},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"hardy","status":"released","description":"1:9.4.2.dfsg.P2-2ubuntu0.9","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1:9.7.0.dfsg.P1-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1:9.7.1.dfsg.P2-2ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1:9.7.3.dfsg-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1:9.7.3.dfsg-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.8.1p1,9.7.4p1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1264-1"],"notices":[{"id":"USN-1264-1","title":"Bind vulnerability","summary":"Bind could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-11-16T22:38:55.121250","description":"It was discovered that Bind incorrectly handled certain specially crafted\npackets. A remote attacker could use this flaw to cause Bind to crash,\nresulting in a denial of service.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"bind9","version":"1:9.4.2.dfsg.P2-2ubuntu0.9","description":"Internet Domain Name Server","is_source":true},{"name":"libdns36","version":"1:9.4.2.dfsg.P2-2ubuntu0.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.4.2.dfsg.P2-2ubuntu0.9"}],"lucid":[{"name":"bind9","version":"1:9.7.0.dfsg.P1-1ubuntu0.4","description":"Internet Domain Name Server","is_source":true},{"name":"libdns64","version":"1:9.7.0.dfsg.P1-1ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.7.0.dfsg.P1-1ubuntu0.4"}],"maverick":[{"name":"bind9","version":"1:9.7.1.dfsg.P2-2ubuntu0.5","description":"Internet Domain Name Server","is_source":true},{"name":"libdns66","version":"1:9.7.1.dfsg.P2-2ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.7.1.dfsg.P2-2ubuntu0.5"}],"natty":[{"name":"bind9","version":"1:9.7.3.dfsg-1ubuntu2.3","description":"Internet Domain Name Server","is_source":true},{"name":"libdns69","version":"1:9.7.3.dfsg-1ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.7.3.dfsg-1ubuntu2.3"}],"oneiric":[{"name":"bind9","version":"1:9.7.3.dfsg-1ubuntu4.1","description":"Internet Domain Name Server","is_source":true},{"name":"libdns69","version":"1:9.7.3.dfsg-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.7.3.dfsg-1ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2011-4313"]}]},{"id":"CVE-2011-3389","published":"2011-11-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SSL protocol, as used in certain configurations in Microsoft Windows\nand Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and\nother products, encrypts data by using CBC mode with chained initialization\nvectors, which allows man-in-the-middle attackers to obtain plaintext HTTP\nheaders via a blockwise chosen-boundary attack (BCBA) on an HTTPS session,\nin conjunction with JavaScript code that uses (1) the HTML5 WebSocket API,\n(2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a\n\"BEAST\" attack.","ubuntu_description":"\nJuliano Rizzo and Thai Duong discovered that the block-wise AES\nencryption algorithm block-wise as used in TLS/SSL was vulnerable\nto a chosen-plaintext attack. This could allow a remote attacker to\nview confidential data.","notes":[{"author":"mdeslaur","note":"in natty+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"this is not a lighttpd issue, however dsa-2368 disabled CBC ciphers\nby default. Ignoring as this is a configuration issue."},{"author":"sbeattie","note":"openssl contains a countermeasure since openssl 0.9.8d,\nthough it can be disabled with the SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS\noption (which is included in SSL_OP_ALL). Need to search through\nopenssl user that enable the option."},{"author":"tyhicks","note":"All versions of gnutls in supported releases have TLS 1.1 and 1.2\nsupport. TLS 1.1 and 1.2 are not affected by this attack. Upstream advised\napplications to use 1.1 and 1.2 in GNUTLS-SA-2011-1. Additionally, DTLS 1.0\ncan be used or RC4 can be used with TLS 1.0 if TLS 1.1 or 1.2 are not viable\noptions."},{"author":"jdstrand","note":"arcticdog blog points out that users of SSL_OP_ALL should be updated\nto use 'SSL_OP_ALL & ~SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS' to not be\nvulnerable to this attack"},{"author":"mdeslaur","note":"removing SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS will break\ncompatibility with certain SSL implementations, which is why it's\nincluded in SSL_OP_ALL in the first place. Since the BEAST attack is only\npractical in web browsers where you can run arbitrary code, and current\nweb browsers are already fixed, modifying other software in the archive\nto enable the work around will break compatibility with no added security\nbenefit."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1263-1","http://arcticdog.wordpress.com/2012/08/29/beast-openssl-and-apache/","https://www.cve.org/CVERecord?id=CVE-2011-3389"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[],"openjdk-7":[],"gnutls26":[],"openssl":[],"icedtea-web":[],"lighttpd":["vendor: http://www.debian.org/security/2011/dsa-2368"]},"tags":{},"packages":[{"name":"gnutls26","source":"https://ubuntu.com/security/cve?package=gnutls26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls26","debian":"https://tracker.debian.org/pkg/gnutls26","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lighttpd","source":"https://ubuntu.com/security/cve?package=lighttpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lighttpd","debian":"https://tracker.debian.org/pkg/lighttpd","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.30-1","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b20-1.9.10-0ubuntu1~10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6b20-1.9.10-0ubuntu1~10.10.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6b22-1.10.4-0ubuntu1~11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b23~pre11-0ubuntu1.11.10","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"6b23~pre11-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"6b23~pre11-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b18-1.8.10-0ubuntu1~10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6b18-1.8.10-0ubuntu1~10.10.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6b18-1.8.10-0ubuntu1~11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7~b147-2.0-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7~b147-2.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7~b147-2.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"hardy","status":"not-affected","description":"countermeasure in place","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"countermeasure in place","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"countermeasure in place","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"countermeasure in place","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"countermeasure in place","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"countermeasure in place","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"countermeasure in place","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1263-1"],"notices":[{"id":"USN-1263-1","title":"IcedTea-Web, OpenJDK 6 vulnerabilities","summary":"Multiple OpenJDK 6 and IcedTea-Web vulnerabilities have been fixed.\n","instructions":"After a standard system update you need to restart any Java applications\nor applets to make all the necessary changes.\n","references":[],"published":"2011-11-16T20:31:21.510497","description":"Deepak Bhole discovered a flaw in the Same Origin Policy (SOP)\nimplementation in the IcedTea web browser plugin. This could allow a\nremote attacker to open connections to certain hosts that should\nnot be permitted. (CVE-2011-3377)\n\nJuliano Rizzo and Thai Duong discovered that the block-wise AES\nencryption algorithm block-wise as used in TLS/SSL was vulnerable to\na chosen-plaintext attack. This could allow a remote attacker to view\nconfidential data. (CVE-2011-3389)\n\nIt was discovered that a type confusion flaw existed in the in\nthe Internet Inter-Orb Protocol (IIOP) deserialization code. A\nremote attacker could use this to cause an untrusted application\nor applet to execute arbitrary code by deserializing malicious\ninput. (CVE-2011-3521)\n\nIt was discovered that the Java scripting engine did not perform\nSecurityManager checks. This could allow a remote attacker to cause\nan untrusted application or applet to execute arbitrary code with\nthe full privileges of the JVM. (CVE-2011-3544)\n\nIt was discovered that the InputStream class used a global buffer to\nstore input bytes skipped. An attacker could possibly use this to gain\naccess to sensitive information. (CVE-2011-3547)\n\nIt was discovered that a vulnerability existed in the AWTKeyStroke\nclass. A remote attacker could cause an untrusted application or applet\nto execute arbitrary code. (CVE-2011-3548)\n\nIt was discovered that an integer overflow vulnerability existed\nin the TransformHelper class in the Java2D implementation. A remote\nattacker could use this cause a denial of service via an application\nor applet crash or possibly execute arbitrary code. (CVE-2011-3551)\n\nIt was discovered that the default number of available UDP sockets for\napplications running under SecurityManager restrictions was set too\nhigh. A remote attacker could use this with a malicious application or\napplet exhaust the number of available UDP sockets to cause a denial\nof service for other applets or applications running within the same\nJVM. (CVE-2011-3552)\n\nIt was discovered that Java API for XML Web Services (JAX-WS) could\nincorrectly expose a stack trace. A remote attacker could potentially\nuse this to gain access to sensitive information. (CVE-2011-3553)\n\nIt was discovered that the unpacker for pack200 JAR files did not\nsufficiently check for errors. An attacker could cause a denial of\nservice or possibly execute arbitrary code through a specially crafted\npack200 JAR file. (CVE-2011-3554)\n\nIt was discovered that the RMI registration implementation did not\nproperly restrict privileges of remotely executed code. A remote\nattacker could use this to execute code with elevated privileges.\n(CVE-2011-3556, CVE-2011-3557)\n\nIt was discovered that the HotSpot VM could be made to crash, allowing\nan attacker to cause a denial of service or possibly leak sensitive\ninformation. (CVE-2011-3558)\n\nIt was discovered that the HttpsURLConnection class did not\nproperly perform SecurityManager checks in certain situations. This\ncould allow a remote attacker to bypass restrictions on HTTPS\nconnections. (CVE-2011-3560)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"openjdk-6","version":"6b20-1.9.10-0ubuntu1~10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6b18","version":"6b18-1.8.10-0ubuntu1~10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b20-1.9.10-0ubuntu1~10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.04.2"},{"name":"openjdk-6-jre","version":"6b20-1.9.10-0ubuntu1~10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.04.2"},{"name":"openjdk-6-jre-headless","version":"6b20-1.9.10-0ubuntu1~10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.04.2"},{"name":"openjdk-6-demo","version":"6b20-1.9.10-0ubuntu1~10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b20-1.9.10-0ubuntu1~10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b20-1.9.10-0ubuntu1~10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.04.2"},{"name":"icedtea6-plugin","version":"6b20-1.9.10-0ubuntu1~10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.04.2"}],"maverick":[{"name":"openjdk-6","version":"6b20-1.9.10-0ubuntu1~10.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6b18","version":"6b18-1.8.10-0ubuntu1~10.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b20-1.9.10-0ubuntu1~10.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.10.2"},{"name":"openjdk-6-jre-zero","version":"6b20-1.9.10-0ubuntu1~10.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.10.2"},{"name":"openjdk-6-jre","version":"6b20-1.9.10-0ubuntu1~10.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.10.2"},{"name":"openjdk-6-jre-headless","version":"6b20-1.9.10-0ubuntu1~10.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.10.2"},{"name":"openjdk-6-demo","version":"6b20-1.9.10-0ubuntu1~10.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.10.2"},{"name":"openjdk-6-jdk","version":"6b20-1.9.10-0ubuntu1~10.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.10.2"},{"name":"openjdk-6-jre-lib","version":"6b20-1.9.10-0ubuntu1~10.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.10-0ubuntu1~10.10.2"}],"natty":[{"name":"icedtea-web","version":"1.1.1-0ubuntu1~11.04.2","description":"A web browser plugin to execute Java applets","is_source":true},{"name":"openjdk-6","version":"6b22-1.10.4-0ubuntu1~11.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6b18","version":"6b18-1.8.10-0ubuntu1~11.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b22-1.10.4-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.4-0ubuntu1~11.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b22-1.10.4-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.4-0ubuntu1~11.04.1"},{"name":"icedtea-plugin","version":"1.1.1-0ubuntu1~11.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icedtea-web","version_link":"https://launchpad.net/ubuntu/+source/icedtea-web/1.1.1-0ubuntu1~11.04.2"},{"name":"icedtea-netx","version":"1.1.1-0ubuntu1~11.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icedtea-web","version_link":"https://launchpad.net/ubuntu/+source/icedtea-web/1.1.1-0ubuntu1~11.04.2"},{"name":"openjdk-6-jre","version":"6b22-1.10.4-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.4-0ubuntu1~11.04.1"},{"name":"openjdk-6-jre-headless","version":"6b22-1.10.4-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.4-0ubuntu1~11.04.1"},{"name":"openjdk-6-jre-zero","version":"6b22-1.10.4-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.4-0ubuntu1~11.04.1"},{"name":"openjdk-6-jre-lib","version":"6b22-1.10.4-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.4-0ubuntu1~11.04.1"}],"oneiric":[{"name":"icedtea-web","version":"1.1.3-1ubuntu1.1","description":"A web browser plugin to execute Java applets","is_source":true},{"name":"openjdk-6","version":"6b23~pre11-0ubuntu1.11.10","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b23~pre11-0ubuntu1.11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10"},{"name":"icedtea-6-jre-jamvm","version":"6b23~pre11-0ubuntu1.11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10"},{"name":"icedtea-plugin","version":"1.1.3-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icedtea-web","version_link":"https://launchpad.net/ubuntu/+source/icedtea-web/1.1.3-1ubuntu1.1"},{"name":"icedtea-netx","version":"1.1.3-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icedtea-web","version_link":"https://launchpad.net/ubuntu/+source/icedtea-web/1.1.3-1ubuntu1.1"},{"name":"openjdk-6-jre","version":"6b23~pre11-0ubuntu1.11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10"},{"name":"openjdk-6-jre-headless","version":"6b23~pre11-0ubuntu1.11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10"},{"name":"openjdk-6-jre-zero","version":"6b23~pre11-0ubuntu1.11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10"},{"name":"openjdk-6-jre-lib","version":"6b23~pre11-0ubuntu1.11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10"}]},"type":"USN","cves_ids":["CVE-2011-3389","CVE-2011-3556","CVE-2011-3552","CVE-2011-3558","CVE-2011-3547","CVE-2011-3554","CVE-2011-3521","CVE-2011-3377","CVE-2011-3560","CVE-2011-3557","CVE-2011-3553","CVE-2011-3551","CVE-2011-3548","CVE-2011-3544"]}]},{"id":"CVE-2011-4118","published":"2011-11-15T03:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMahara before 1.4.1, when MNet (aka the Moodle network feature) is used,\nallows remote authenticated users to gain privileges via a jump to an\nXMLRPC target.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-4118"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/888358"],"patches":{"mahara":["debdiff: https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/888358"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.7-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.4.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2774","published":"2011-11-15T03:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe \"Reply to message\" feature in Mahara 1.3.x and 1.4.x before 1.4.1\nallows remote authenticated users to read the messages of a different user\nvia a modified replyto parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2774"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/888358"],"patches":{"mahara":["debdiff: https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/888358"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.4 only","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.4 only","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.4 only","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.4.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2773","published":"2011-11-15T03:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1\nallows remote attackers to hijack the authentication of administrators for\nrequests that add a user to an institution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2773"],"bugs":[""],"patches":{"mahara":["vendor: http://www.debian.org/security/2011/dsa-2334"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.7-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.4.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2772","published":"2011-11-15T03:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1\ndoes not properly validate uploaded image files, which allows remote\nattackers to cause a denial of service (memory consumption) via a (1) large\nor (2) invalid image.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2772"],"bugs":[""],"patches":{"mahara":["vendor: http://www.debian.org/security/2011/dsa-2334"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.7-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.4.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2771","published":"2011-11-15T03:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.4.1\nallow remote attackers to inject arbitrary web script or HTML via vectors\nrelated to (1) URI attributes and (2) the External Feed component, as\ndemonstrated by the guid element in an RSS feed.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2771"],"bugs":[""],"patches":{"mahara":["vendor: http://www.debian.org/security/2011/dsa-2334"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.7-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.4.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":70400,"limit":20,"total_results":79316}