{"cves":[{"id":"CVE-2011-2753","published":"2011-07-17T20:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail\n1.4.21 and earlier allow remote attackers to hijack the authentication of\nunspecified victims via vectors involving (1) the empty trash\nimplementation and (2) the Index Order (aka options_order) page, a\ndifferent issue than CVE-2010-4555.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.squirrelmail.org/security/issue/2011-07-11","https://www.cve.org/CVERecord?id=CVE-2011-2753"],"bugs":[""],"patches":{"squirrelmail":[]},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"trusty","status":"not-affected","description":"2:1.4.23~svn20120406-2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:1.4.23~svn20120406-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2:1.4.23~svn20120406-2ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2752","published":"2011-07-17T20:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows\nremote attackers to modify or add preference values via a \\n (newline)\ncharacter, a different vulnerability than CVE-2010-4555.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2752"],"bugs":[""],"patches":{"squirrelmail":[]},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"trusty","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2691","published":"2011-07-17T20:55:00","updated_at":"2025-08-25T20:13:55.854913+00:00","description":"\nThe png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x\nbefore 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function\ncall using a NULL pointer argument instead of an empty-string argument,\nwhich allows remote attackers to cause a denial of service (application\ncrash) via a crafted PNG image.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"On Ubuntu, the affected code isn't compiled in libpng."},{"author":"jdstrand","note":"firefox 3.6.23 has 1.2.35 and 7.0.1 has 1.4.7"},{"author":"micahg","note":"firefox 8 will have 1.4.8"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2691"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=633871","https://bugzilla.mozilla.org/show_bug.cgi?id=669863"],"patches":{"libpng":["upstream: http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commit;h=9dad5e37aef295b4ef8dea39392b652deebc9261"],"firefox":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"14.0.835.202~r103287-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"14.0.835.202~r103287-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"14.0.835.202~r103287-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.0+build1-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"8.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"8.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8.0~b4+build1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.45","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2692","published":"2011-07-17T00:00:00","updated_at":"2025-08-25T20:13:55.854913+00:00","description":"\nThe png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55,\n1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not\nproperly handle invalid sCAL chunks, which allows remote attackers to cause\na denial of service (memory corruption and application crash) or possibly\nhave unspecified other impact via a crafted PNG image that triggers the\nreading of uninitialized memory.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"firefox 3.6.23 has 1.2.35 and 7.0.1 has 1.4.7"},{"author":"micahg","note":"firefox 8 will have 1.4.8"}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1175-1","https://www.cve.org/CVERecord?id=CVE-2011-2692"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=633871","https://bugzilla.mozilla.org/show_bug.cgi?id=669863"],"patches":{"libpng":["upstream: http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commit;h=61a2d8a2a7b03023e63eae9a3e64607aaaa6d339"],"firefox":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"14.0.835.202~r103287-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"14.0.835.202~r103287-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"14.0.835.202~r103287-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.0+build1-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"8.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"8.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8.0~b4+build1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"hardy","status":"released","description":"1.2.15~beta5-3ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.42-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.44-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.44-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.46-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.2.46-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.45","component":null,"pocket":"security"}]}],"notices_ids":["USN-1175-1"],"notices":[{"id":"USN-1175-1","title":"libpng vulnerabilities","summary":"Libpng could be made to run programs as your login if it opened a\nspecially crafted file.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-07-26T16:36:21.288037","description":"Frank Busse discovered that libpng did not properly handle certain\nmalformed PNG images. If a user or automated system were tricked into\nopening a crafted PNG file, an attacker could cause libpng to crash,\nresulting in a denial of service. This issue only affected Ubuntu\n10.04 LTS, 10.10, and 11.04. (CVE-2011-2501)\n\nIt was discovered that libpng did not properly handle certain malformed PNG\nimages. If a user or automated system were tricked into opening a crafted\nPNG file, an attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2011-2690)\n\nFrank Busse discovered that libpng did not properly handle certain PNG\nimages with invalid sCAL chunks. If a user or automated system were tricked\ninto opening a crafted PNG file, an attacker could cause a denial of\nservice or possibly execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2011-2692)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libpng","version":"1.2.15~beta5-3ubuntu0.4","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.15~beta5-3ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.15~beta5-3ubuntu0.4"}],"lucid":[{"name":"libpng","version":"1.2.42-1ubuntu2.2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.42-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.42-1ubuntu2.2"}],"maverick":[{"name":"libpng","version":"1.2.44-1ubuntu0.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.44-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu0.1"}],"natty":[{"name":"libpng","version":"1.2.44-1ubuntu3.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.44-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2011-2692","CVE-2011-2501","CVE-2011-2690"]}]},{"id":"CVE-2011-2690","published":"2011-07-17T00:00:00","updated_at":"2025-08-25T20:13:55.854913+00:00","description":"\nBuffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x\nbefore 1.4.8, and 1.5.x before 1.5.4, when used by an application that\ncalls the png_rgb_to_gray function but not the png_set_expand function,\nallows remote attackers to overwrite memory with an arbitrary amount of\ndata, and possibly have unspecified other impact, via a crafted PNG image.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"firefox 3.6.23 has 1.2.35 and 7.0.1 has 1.4.7"},{"author":"micahg","note":"per https://bugzilla.mozilla.org/show_bug.cgi?id=669863#c2 Firefox 7+\nisn't vulnerable"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1175-1","https://www.cve.org/CVERecord?id=CVE-2011-2690"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=633871","https://bugzilla.mozilla.org/show_bug.cgi?id=669863"],"patches":{"libpng":["upstream: http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commit;h=d572394c2a018ef22e9685ac189f5f05c08ea6f5"],"firefox":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"14.0.835.202~r103287-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"14.0.835.202~r103287-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.6.23+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.6.23+build1+nobinonly-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"7.0.1+build1+nobinonly-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"7.0.1+build1+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"7.0.1","component":null,"pocket":"security"}]},{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"hardy","status":"released","description":"1.2.15~beta5-3ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.42-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.44-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.44-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.46-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.45","component":null,"pocket":"security"}]}],"notices_ids":["USN-1175-1"],"notices":[{"id":"USN-1175-1","title":"libpng vulnerabilities","summary":"Libpng could be made to run programs as your login if it opened a\nspecially crafted file.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-07-26T16:36:21.288037","description":"Frank Busse discovered that libpng did not properly handle certain\nmalformed PNG images. If a user or automated system were tricked into\nopening a crafted PNG file, an attacker could cause libpng to crash,\nresulting in a denial of service. This issue only affected Ubuntu\n10.04 LTS, 10.10, and 11.04. (CVE-2011-2501)\n\nIt was discovered that libpng did not properly handle certain malformed PNG\nimages. If a user or automated system were tricked into opening a crafted\nPNG file, an attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2011-2690)\n\nFrank Busse discovered that libpng did not properly handle certain PNG\nimages with invalid sCAL chunks. If a user or automated system were tricked\ninto opening a crafted PNG file, an attacker could cause a denial of\nservice or possibly execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2011-2692)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libpng","version":"1.2.15~beta5-3ubuntu0.4","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.15~beta5-3ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.15~beta5-3ubuntu0.4"}],"lucid":[{"name":"libpng","version":"1.2.42-1ubuntu2.2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.42-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.42-1ubuntu2.2"}],"maverick":[{"name":"libpng","version":"1.2.44-1ubuntu0.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.44-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu0.1"}],"natty":[{"name":"libpng","version":"1.2.44-1ubuntu3.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.44-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2011-2692","CVE-2011-2501","CVE-2011-2690"]}]},{"id":"CVE-2011-2501","published":"2011-07-17T00:00:00","updated_at":"2025-08-25T20:13:27.189915+00:00","description":"\nThe png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55,\n1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows\nremote attackers to cause a denial of service (application crash) via a\ncrafted PNG image that triggers an out-of-bounds read during the copying of\nerror-message data. NOTE: this vulnerability exists because of a\nCVE-2004-0421 regression. NOTE: this is called an off-by-one error by some\nsources.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"re-introduced in 1.2.23"},{"author":"jdstrand","note":"firefox 3.6.23 has 1.2.35 and 7.0.1 has 1.4.7"},{"author":"micahg","note":"firefox 8 will have 1.4.8"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1175-1","https://www.cve.org/CVERecord?id=CVE-2011-2501"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=632786","https://bugzilla.mozilla.org/show_bug.cgi?id=669863"],"patches":{"libpng":["upstream: http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=65e6d5a34f49acdb362a0625a706c6b914e670af"],"firefox":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"14.0.835.202~r103287-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"14.0.835.202~r103287-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"14.0.835.202~r103287-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.0+build1-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"8.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"8.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8.0~b4+build1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"hardy","status":"not-affected","description":"1.2.15~beta5-3ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.42-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.44-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.44-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.46-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.2.46-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.44-3","component":null,"pocket":"security"}]}],"notices_ids":["USN-1175-1"],"notices":[{"id":"USN-1175-1","title":"libpng vulnerabilities","summary":"Libpng could be made to run programs as your login if it opened a\nspecially crafted file.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-07-26T16:36:21.288037","description":"Frank Busse discovered that libpng did not properly handle certain\nmalformed PNG images. If a user or automated system were tricked into\nopening a crafted PNG file, an attacker could cause libpng to crash,\nresulting in a denial of service. This issue only affected Ubuntu\n10.04 LTS, 10.10, and 11.04. (CVE-2011-2501)\n\nIt was discovered that libpng did not properly handle certain malformed PNG\nimages. If a user or automated system were tricked into opening a crafted\nPNG file, an attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2011-2690)\n\nFrank Busse discovered that libpng did not properly handle certain PNG\nimages with invalid sCAL chunks. If a user or automated system were tricked\ninto opening a crafted PNG file, an attacker could cause a denial of\nservice or possibly execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2011-2692)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libpng","version":"1.2.15~beta5-3ubuntu0.4","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.15~beta5-3ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.15~beta5-3ubuntu0.4"}],"lucid":[{"name":"libpng","version":"1.2.42-1ubuntu2.2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.42-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.42-1ubuntu2.2"}],"maverick":[{"name":"libpng","version":"1.2.44-1ubuntu0.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.44-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu0.1"}],"natty":[{"name":"libpng","version":"1.2.44-1ubuntu3.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.44-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.44-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2011-2692","CVE-2011-2501","CVE-2011-2690"]}]},{"id":"CVE-2011-2510","published":"2011-07-14T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the RSS embedding feature in\nDokuWiki before 2011-05-25a Rincewind allows remote attackers to inject\narbitrary web script or HTML via a link.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2510"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631818"],"patches":{"dokuwiki":["vendor: http://www.debian.org/security/2011/dsa-2320"]},"tags":{},"packages":[{"name":"dokuwiki","source":"https://ubuntu.com/security/cve?package=dokuwiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dokuwiki","debian":"https://tracker.debian.org/pkg/dokuwiki","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2011-05-25a","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.0.20110525a-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"0.0.20110525a-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"0.0.20110525a-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"0.0.20110525a-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"0.0.20110525a-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2508","published":"2011-07-14T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in libraries/display_tbl.lib.php in\nphpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain\nMIME transformation feature is enabled, allows remote authenticated users\nto include and execute arbitrary local files via a .. (dot dot) in a\nGLOBALS[mime_map][$meta->name][transformation] parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2508"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/806788"],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2507","published":"2011-07-14T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibraries/server_synchronize.lib.php in the Synchronize implementation in\nphpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly\nquote regular expressions, which allows remote authenticated users to\ninject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute\narbitrary PHP code, by leveraging the ability to modify the SESSION\nsuperglobal array.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2507"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/806788"],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2506","published":"2011-07-14T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsetup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and\n3.4.x before 3.4.3.1 does not properly restrict the presence of comment\nclosing delimiters, which allows remote attackers to conduct static code\ninjection attacks by leveraging the ability to modify the SESSION\nsuperglobal array.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2506"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/806788"],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2505","published":"2011-07-14T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication\nfeature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns\nvalues to arbitrary parameters referenced in the query string, which allows\nremote attackers to modify the SESSION superglobal array via a crafted\nrequest, related to a \"remote variable manipulation vulnerability.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2505"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/806788"],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:3.4.3.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2023","published":"2011-07-14T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in functions/mime.php in\nSquirrelMail before 1.4.22 allows remote attackers to inject arbitrary web\nscript or HTML via a crafted STYLE element in an e-mail message.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.squirrelmail.org/security/issue/2011-07-10","https://www.cve.org/CVERecord?id=CVE-2011-2023"],"bugs":[""],"patches":{"squirrelmail":["upstream: http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/mime.php?view=patch&r1=14133&r2=14120&pathrev=14133"]},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.22","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4555","published":"2011-07-14T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.21\nand earlier allow remote attackers to inject arbitrary web script or HTML\nvia vectors involving (1) drop-down selection lists, (2) the > (greater\nthan) character in the SquirrelSpell spellchecking plugin, and (3) errors\nassociated with the Index Order (aka options_order) page.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.squirrelmail.org/security/issue/2011-07-11","https://www.cve.org/CVERecord?id=CVE-2010-4555"],"bugs":[""],"patches":{"squirrelmail":["upstream: http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=revision&revision=14119"]},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.22","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4554","published":"2011-07-14T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfunctions/page_header.php in SquirrelMail 1.4.21 and earlier does not\nprevent page rendering inside a frame in a third-party HTML document, which\nmakes it easier for remote attackers to conduct clickjacking attacks via a\ncrafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.squirrelmail.org/security/issue/2011-07-12","https://www.cve.org/CVERecord?id=CVE-2010-4554"],"bugs":[""],"patches":{"squirrelmail":["upstream: http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/page_header.php?view=patch&r1=14117&r2=14116&pathrev=14117"]},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2:1.4.22-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.22","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2526","published":"2011-07-14T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before\n7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector,\ndoes not validate certain request attributes, which allows local users to\nbypass intended file access restrictions or cause a denial of service\n(infinite loop or JVM crash) by leveraging an untrusted web application.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1252-1","https://www.cve.org/CVERecord?id=CVE-2011-2526"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=634992"],"patches":{"tomcat5.5":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1158244"],"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1146703"],"tomcat7":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1146005","upstream: http://svn.apache.org/viewvc?view=revision&revision=1145694","upstream: http://svn.apache.org/viewvc?view=revision&revision=1145571","upstream: http://svn.apache.org/viewvc?view=revision&revision=1145489","upstream: http://svn.apache.org/viewvc?view=revision&revision=1145383"]},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.34","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.24-2ubuntu1.9","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6.0.28-2ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6.0.28-10ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6.0.32-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.33","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"7.0.21-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.19","component":null,"pocket":"security"}]}],"notices_ids":["USN-1252-1"],"notices":[{"id":"USN-1252-1","title":"Tomcat vulnerabilities","summary":"Tomcat could be made to crash or expose sensitive information over the\nnetwork.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-11-08T13:46:08.955457","description":"It was discovered that Tomcat incorrectly implemented HTTP DIGEST\nauthentication. An attacker could use this flaw to perform a variety of\nauthentication attacks. (CVE-2011-1184)\n\nPolina Genova discovered that Tomcat incorrectly created log entries with\npasswords when encountering errors during JMX user creation. A local\nattacker could possibly use this flaw to obtain sensitive information. This\nissue only affected Ubuntu 10.04 LTS, 10.10 and 11.04. (CVE-2011-2204)\n\nIt was discovered that Tomcat incorrectly validated certain request\nattributes when sendfile is enabled. A local attacker could bypass intended\nrestrictions, or cause the JVM to crash, resulting in a denial of service.\n(CVE-2011-2526)\n\nIt was discovered that Tomcat incorrectly handled certain AJP requests. A\nremote attacker could use this flaw to spoof requests, bypass\nauthentication, and obtain sensitive information. This issue only affected\nUbuntu 10.04 LTS, 10.10 and 11.04. (CVE-2011-3190)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"tomcat6","version":"6.0.24-2ubuntu1.9","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.24-2ubuntu1.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.24-2ubuntu1.9"}],"maverick":[{"name":"tomcat6","version":"6.0.28-2ubuntu1.5","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.28-2ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.28-2ubuntu1.5"}],"natty":[{"name":"tomcat6","version":"6.0.28-10ubuntu2.2","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.28-10ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.28-10ubuntu2.2"}],"oneiric":[{"name":"tomcat6","version":"6.0.32-5ubuntu1.1","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.32-5ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.32-5ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2011-3190","CVE-2011-1184","CVE-2011-2204","CVE-2011-2526"]}]},{"id":"CVE-2011-1829","published":"2011-07-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAPT before 0.8.15.2 does not properly validate inline GPG signatures, which\nallows man-in-the-middle attackers to install modified packages via vectors\ninvolving lack of an initial clearsigned message.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only apt in natty+ support InRelease files"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1169-1","https://www.cve.org/CVERecord?id=CVE-2011-1829"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/apt/+bug/784473"],"patches":{"apt":[]},"tags":{},"packages":[{"name":"apt","source":"https://ubuntu.com/security/cve?package=apt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apt","debian":"https://tracker.debian.org/pkg/apt","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"0.8.13.2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1169-1"],"notices":[{"id":"USN-1169-1","title":"APT vulnerability","summary":"An attacker could trick APT into installing altered packages.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-07-13T17:05:07.315355","description":"William Grant discovered that APT incorrectly validated inline GPG\nsignatures. If a remote attacker were able to perform a machine-in-the-middle\nattack, this flaw could potentially be used to install altered packages.\n","is_hidden":false,"release_packages":{"natty":[{"name":"apt","version":"0.8.13.2ubuntu4.1","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"0.8.13.2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/0.8.13.2ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2011-1829"]}]},{"id":"CVE-2011-2511","published":"2011-07-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in libvirt before 0.9.3 allows remote authenticated users\nto cause a denial of service (libvirtd crash) and possibly execute\narbitrary code via a crafted VirDomainGetVcpus RPC call that triggers\nmemory corruption.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"DoS is confirmed by a remote authenticated user\n89d994ad6b0e8ebe9a2cd4e0e37119ff4c917550 (gnulib) may not actually\nbe required to fix in stable releases.\nfixed in 0.8.3-5+squeeze2"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1180-1","https://www.cve.org/CVERecord?id=CVE-2011-2511"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=633630"],"patches":{"libvirt":["upstream: https://www.redhat.com/archives/libvir-list/2011-June/msg01278.html","upstream: 774b21c163845170c9ffa873f5720d318812eaf6","upstream: 89d994ad6b0e8ebe9a2cd4e0e37119ff4c917550","vendor: https://rhn.redhat.com/errata/RHSA-2011-1019.html"]},"tags":{},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.7.5-5ubuntu27.16","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.8.3-1ubuntu19.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"0.8.8-1ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.3, 0.9.2-7","component":null,"pocket":"security"}]}],"notices_ids":["USN-1180-1"],"notices":[{"id":"USN-1180-1","title":"libvirt vulnerability","summary":"An authenticated attacker could send crafted input to libvirt and cause it\nto crash.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-07-28T17:10:49.695603","description":"Eric Blake discovered an integer overflow flaw in libvirt. A remote\nauthenticated attacker could exploit this by sending a crafted VCPU RPC\ncall and cause a denial of service via application crash.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"libvirt","version":"0.7.5-5ubuntu27.16","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libvirt-bin","version":"0.7.5-5ubuntu27.16","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.5-5ubuntu27.16"}],"maverick":[{"name":"libvirt","version":"0.8.3-1ubuntu19.1","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libvirt-bin","version":"0.8.3-1ubuntu19.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.8.3-1ubuntu19.1"}],"natty":[{"name":"libvirt","version":"0.8.8-1ubuntu6.5","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libvirt-bin","version":"0.8.8-1ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.8.8-1ubuntu6.5"}]},"type":"USN","cves_ids":["CVE-2011-2511"]}]},{"id":"CVE-2011-2516","published":"2011-07-11T20:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the XML signature feature in Apache XML Security for\nC++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products,\nallows remote attackers to cause a denial of service (crash) via a\nsignature using a large RSA key, which triggers a buffer overflow.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"shibboleth-sp2 apparently needs to be recompiled after the\nfix to xml-security-c"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://santuario.apache.org/secadv/CVE-2011-2516.txt","https://www.cve.org/CVERecord?id=CVE-2011-2516"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/xml-security-c/+bug/807414","https://bugs.launchpad.net/ubuntu/+source/shibboleth-sp2/+bug/807416","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=632973"],"patches":{"xml-security-c":[],"shibboleth-sp2":[]},"tags":{},"packages":[{"name":"shibboleth-sp2","source":"https://ubuntu.com/security/cve?package=shibboleth-sp2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=shibboleth-sp2","debian":"https://tracker.debian.org/pkg/shibboleth-sp2","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.5.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.5.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.5.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.5.2+dfsg-2]","component":null,"pocket":"security"}]},{"name":"xml-security-c","source":"https://ubuntu.com/security/cve?package=xml-security-c","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xml-security-c","debian":"https://tracker.debian.org/pkg/xml-security-c","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.5.1-3+squeeze1build0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.5.1-3+squeeze1build0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.5.1-3+squeeze1build0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.6.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [1.6.1-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1951","published":"2011-07-11T20:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is\nset and when using PCRE 8.12 and possibly other versions, allows remote\nattackers to cause a denial of service (memory consumption) via a message\nthat does not match a regular expression.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"may not affect releases where libpcre3 is < 8.12"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1951"],"bugs":[""],"patches":{"syslog-ng":["upstream: http://git.balabit.hu/?p=bazsi/syslog-ng-3.2.git;a=commitdiff;h=09710c0b105e579d35c7b5f6c66d1ea5e3a3d3ff;hp=21a455ecdf808cbd0c57428d1bd3f9feec58419e","upstream: http://git.balabit.hu/?p=bazsi/syslog-ng-3.1.git;a=commitdiff;h=35de55e53dd653c50c8da5daf41a99ab22e7e8aa"]},"tags":{},"packages":[{"name":"syslog-ng","source":"https://ubuntu.com/security/cve?package=syslog-ng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=syslog-ng","debian":"https://tracker.debian.org/pkg/syslog-ng","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.4-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.4-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.4-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.2.4-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.2.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1526","published":"2011-07-11T20:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications\n(aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return\nvalue, which allows remote authenticated users to bypass intended group\naccess restrictions, and create, overwrite, delete, or read files, via\nstandard FTP commands, related to missing autoconf tests in a configure\nscript.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"krb5-appl was split out from the krb5 package between hardy\nand lucid by upstream; the CVE covers two issues:\n* the configure test for setegid() wasn't included when\nkrb5-appl was split out and so setegid is defined to\nalways return an error, which thus doesn't affect hardy\n* the code never checks the return value of setegid, which\nis a problem when setegid always fails, but less so when\nthe setegid() is a real call, though still a real issue.\nhardy is affected by this, but less so than the split out\nkrb5-appl packages.\nTherefore I'm marking this priority low for hardy/krb5"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-005.txt","https://www.cve.org/CVERecord?id=CVE-2011-1526"],"bugs":[""],"patches":{"krb5":[],"krb5-appl":["upstream: http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-005.txt"]},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"krb5-appl separate pkg","component":null,"pocket":"security"}]},{"name":"krb5-appl","source":"https://ubuntu.com/security/cve?package=krb5-appl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5-appl","debian":"https://tracker.debian.org/pkg/krb5-appl","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":70980,"limit":20,"total_results":79316}