{"cves":[{"id":"CVE-2011-1920","published":"2011-05-23T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe make include files in NetBSD before 1.6.2, as used in pmake 1.111 and\nother products, allow local users to overwrite arbitrary files via a\nsymlink attack on a /tmp/_depend##### temporary file, related to (1)\nbsd.lib.mk and (2) bsd.prog.mk.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1920"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=626673"],"patches":{"pmake":[]},"tags":{},"packages":[{"name":"pmake","source":"https://ubuntu.com/security/cve?package=pmake","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pmake","debian":"https://tracker.debian.org/pkg/pmake","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.111-3.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.111-3.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.111-3.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.111-3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.111-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1766","published":"2011-05-23T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nincludes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is\nenabled, does not clear certain cached data after verification of an auth\ntoken fails, which allows remote attackers to bypass authentication by\ncreating crafted wikiUserID and wikiUserName cookies, or by leveraging an\nunattended workstation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1766"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.16.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [1:1.19.2-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1765","published":"2011-05-23T22:55:00","updated_at":"2025-08-04T19:24:03.044298+00:00","description":"\nCross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5, when\nInternet Explorer 6 or earlier is used, allows remote attackers to inject\narbitrary web script or HTML via an uploaded file accessed with a dangerous\nextension such as .shtml at the end of the query string, in conjunction\nwith a modified URI path that has a %2E sequence in place of the . (dot)\ncharacter.  NOTE: this vulnerability exists because of an incomplete fix\nfor CVE-2011-1578 and CVE-2011-1587.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1765"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.16.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1:1.19.2-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [1:1.19.2-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1575","published":"2011-05-23T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does\nnot properly restrict I/O buffering, which allows man-in-the-middle\nattackers to insert commands into encrypted FTP sessions by sending a\ncleartext command that is processed after TLS is in place, related to a\n\"plaintext command injection\" attack, a similar issue to CVE-2011-0411.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1575"],"bugs":[""],"patches":{"pure-ftpd":[]},"tags":{},"packages":[{"name":"pure-ftpd","source":"https://ubuntu.com/security/cve?package=pure-ftpd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pure-ftpd","debian":"https://tracker.debian.org/pkg/pure-ftpd","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.30","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-5024","published":"2011-05-23T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit\nconfiguration setting, and consequently conduct resource-consumption\nattacks, via the limit parameter, as demonstrated by a \"query revision\nhistory\" request.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-5024"],"bugs":[""],"patches":{"viewvc":[]},"tags":{},"packages":[{"name":"viewvc","source":"https://ubuntu.com/security/cve?package=viewvc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=viewvc","debian":"https://tracker.debian.org/pkg/viewvc","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.1.5-1.1+squeeze2build0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.11","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2162","published":"2011-05-20T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used\nin MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and\n2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5\n(aka MES5) have unknown impact and attack vectors, related to issues\n\"originally discovered by Google Chrome developers.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"ffmpeg-extra in multiverse needs to have matching version\nthis CVE likely originates from the Mandriva update announcement\nhere: http://lwn.net/Alerts/436853/\nthey have three patches from google:\nffmpeg-mov_dref_looping.patch:\nhttp://git.videolan.org/?p=ffmpeg.git;a=commit;f=libavformat/mov.c;h=0e7d436d924a42ef6e8ab628a1f10d72801d1395\nnot security - see thread here:\nhttp://lists.mplayerhq.hu/pipermail/ffmpeg-devel/2010-March/094630.html\nffmpeg-mp3_outlen.patch:\nhttp://src.chromium.org/viewvc/chrome/trunk/deps/third_party/ffmpeg/patches/to_upstream/31_mp3_outlen.patch?revision=25031&view=markup&pathrev=28635\nhttp://git.libav.org/?p=libav.git;a=commit;f=libavcodec/mpegaudiodec.c;h=45a014d75efd043aa432b87869f898e552cbbb75\nall releases have this commit already\nffmpeg-vorbis_zero_samplerate.patch:\nhttp://src.chromium.org/viewvc/chrome/trunk/deps/third_party/ffmpeg/patches/to_upstream/41_vorbis_zero_samplerate.patch?revision=25230&view=markup&pathrev=28635\nSIGFPE = not security\nhttp://git.libav.org/?p=libav.git;a=commit;f=libavformat/oggparsevorbis.c;h=ce20edb7bd6c1768ef5f4d181d7ba27a0e7945bd\nMarking as ignored"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2162"],"bugs":[""],"patches":{"ffmpeg":[],"ffmpeg-extra":[],"libav":[],"libav-extra":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ffmpeg-extra","source":"https://ubuntu.com/security/cve?package=ffmpeg-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg-extra","debian":"https://tracker.debian.org/pkg/ffmpeg-extra","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav-extra","source":"https://ubuntu.com/security/cve?package=libav-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libav-extra","debian":"https://tracker.debian.org/pkg/libav-extra","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2160","published":"2011-05-20T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer\nand other products, does not properly restrict read operations, which\nallows remote attackers to have an unspecified impact via a crafted VC-1\nfile, a related issue to CVE-2011-0723.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"ffmpeg-extra in multiverse needs to have matching version\nwe already fixed this as part of CVE-2011-0723"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2160"],"bugs":[""],"patches":{"ffmpeg":["upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=8069e2f6fbd79e3d3d2ba17f5f097475b43e2921"],"ffmpeg-extra":[],"libav":[],"libav-extra":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"4:0.5.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.6-2ubuntu6","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.5.4","component":null,"pocket":"security"}]},{"name":"ffmpeg-extra","source":"https://ubuntu.com/security/cve?package=ffmpeg-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg-extra","debian":"https://tracker.debian.org/pkg/ffmpeg-extra","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"4:0.5.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.6-2ubuntu6","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.5.4","component":null,"pocket":"security"}]},{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"libav-extra","source":"https://ubuntu.com/security/cve?package=libav-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libav-extra","debian":"https://tracker.debian.org/pkg/libav-extra","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2147","published":"2011-05-20T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenswan 2.2.x does not properly restrict permissions for (1)\n/var/run/starter.pid, related to starter.c in the IPsec starter, and (2)\n/var/lock/subsys/ipsec, which allows local users to kill arbitrary\nprocesses by writing a PID to a file, or possibly bypass disk quotas by\nwriting arbitrary data to a file, as demonstrated by files with 0666\npermissions, a different vulnerability than CVE-2011-1784.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"according to debian bug, 2.4.x and newer is not affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2147"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628449"],"patches":{"openswan":[]},"tags":{},"packages":[{"name":"openswan","source":"https://ubuntu.com/security/cve?package=openswan","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openswan","debian":"https://tracker.debian.org/pkg/openswan","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1784","published":"2011-05-20T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe pidfile_write function in core/pidfile.c in keepalived 1.2.2 and\nearlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.pid,\nand (3) vrrp.pid files in /var/run/, which allows local users to kill\narbitrary processes by writing a PID to one of these files.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=626281","https://www.cve.org/CVERecord?id=CVE-2011-1784"],"bugs":[""],"patches":{"keepalived":[]},"tags":{},"packages":[{"name":"keepalived","source":"https://ubuntu.com/security/cve?package=keepalived","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=keepalived","debian":"https://tracker.debian.org/pkg/keepalived","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.3.9-1ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.3.9-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1:1.2.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.2.2-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:1.2.24-1ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1582","published":"2011-05-20T22:55:00","updated_at":"2025-08-04T19:23:59.862189+00:00","description":"\nApache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet\nwithout following security constraints that have been configured through\nannotations, which allows remote attackers to bypass intended access\nrestrictions via HTTP requests.  NOTE: this vulnerability exists because of\nan incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1582"],"bugs":[""],"patches":{"tomcat6":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"tomcat 7 only","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"tomcat 7 only","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"tomcat 7 only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2161","published":"2011-05-20T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ape_read_header function in ape.c in libavformat in FFmpeg before\n0.5.4, as used in MPlayer, VideoLAN VLC media player, and other products,\nallows remote attackers to cause a denial of service (application crash)\nvia an APE (aka Monkey's Audio) file that contains a header but no frames.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"ffmpeg-extra in multiverse needs to have matching version\nPoC: http://packetstorm.linuxsecurity.com/1103-exploits/vlc105-dos.txt"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1209-1","https://www.cve.org/CVERecord?id=CVE-2011-2161"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628448"],"patches":{"ffmpeg":["upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=18c5fe919f4b1818ebdf405812c5a2d16174688f","upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=f17b89278709423b7eb76d7ed5eec5f82df57329"],"ffmpeg-extra":[],"libav":["upstream: http://git.libav.org/?p=libav.git;a=commit;h=8312e3fc9041027a33c8bc667bb99740fdf41dd5"],"libav-extra":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"4:0.5.1-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"4:0.6-2ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.5.4","component":null,"pocket":"security"}]},{"name":"ffmpeg-extra","source":"https://ubuntu.com/security/cve?package=ffmpeg-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg-extra","debian":"https://tracker.debian.org/pkg/ffmpeg-extra","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"4:0.5.1-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"4:0.6-2ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4:0.6.2-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"4:0.7~beta2-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav-extra","source":"https://ubuntu.com/security/cve?package=libav-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libav-extra","debian":"https://tracker.debian.org/pkg/libav-extra","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4:0.6.2-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"4:0.7~beta2-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1209-1"],"notices":[{"id":"USN-1209-1","title":"FFmpeg vulnerabilities","summary":"FFmpeg could be made to run programs as your login if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-09-19T17:51:08.756042","description":"It was discovered that FFmpeg incorrectly handled certain malformed ogg\nfiles. If a user were tricked into opening a crafted ogg file, an attacker\ncould cause a denial of service via application crash, or possibly execute\narbitrary code with the privileges of the user invoking the program. This\nissue only affected Ubuntu 10.10. (CVE-2011-1196)\n\nIt was discovered that FFmpeg incorrectly handled certain malformed AMV\nfiles. If a user were tricked into opening a crafted AMV file, an attacker\ncould cause a denial of service via application crash, or possibly execute\narbitrary code with the privileges of the user invoking the program. This\nissue only affected Ubuntu 10.10. (CVE-2011-1931)\n\nIt was discovered that FFmpeg incorrectly handled certain malformed APE\nfiles. If a user were tricked into opening a crafted APE file, an attacker\ncould cause a denial of service via application crash. (CVE-2011-2161)\n\nEmmanouel Kellinis discovered that FFmpeg incorrectly handled certain\nmalformed CAVS files. If a user were tricked into opening a crafted CAVS\nfile, an attacker could cause a denial of service via application crash, or\npossibly execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2011-3362)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ffmpeg","version":"4:0.5.1-1ubuntu1.2","description":"multimedia player, server and encoder","is_source":true},{"name":"libavformat52","version":"4:0.5.1-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg/4:0.5.1-1ubuntu1.2"},{"name":"libavcodec52","version":"4:0.5.1-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg/4:0.5.1-1ubuntu1.2"}],"maverick":[{"name":"ffmpeg","version":"4:0.6-2ubuntu6.2","description":"multimedia player, server and encoder","is_source":true},{"name":"libavformat52","version":"4:0.6-2ubuntu6.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg/4:0.6-2ubuntu6.2"},{"name":"libavcodec52","version":"4:0.6-2ubuntu6.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg/4:0.6-2ubuntu6.2"}]},"type":"USN","cves_ids":["CVE-2011-2161","CVE-2011-1931","CVE-2011-1196","CVE-2011-3362"]}]},{"id":"CVE-2011-1595","published":"2011-05-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in the disk_create function in disk.c in\nrdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP\nservers to read or overwrite arbitrary files via a .. (dot dot) in a\npathname.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"PoC in bug"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2011-0506.html","https://ubuntu.com/security/notices/USN-1136-1","https://www.cve.org/CVERecord?id=CVE-2011-1595"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=623552","https://bugzilla.redhat.com/show_bug.cgi?id=676252"],"patches":{"rdesktop":["upstream: http://rdesktop.svn.sourceforge.net/viewvc/rdesktop?view=revision&revision=1626"]},"tags":{},"packages":[{"name":"rdesktop","source":"https://ubuntu.com/security/cve?package=rdesktop","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rdesktop","debian":"https://tracker.debian.org/pkg/rdesktop","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.6.0-2ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.6.0-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.6.0-3ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-1136-1"],"notices":[{"id":"USN-1136-1","title":"rdesktop vulnerability","summary":"An attacker could access your files if rdesktop connected to a malicious\nserver.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-05-25T17:03:04.089619","description":"It was discovered that rdesktop incorrectly handled specially crafted\npaths when using disk redirection. If a user were tricked into connecting\nto a malicious server, an attacker could access arbitrary files on the\nuser's filesystem.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"rdesktop","version":"1.6.0-2ubuntu3.1","description":"RDP client for Windows NT/2000 Terminal Server","is_source":true},{"name":"rdesktop","version":"1.6.0-2ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/rdesktop","version_link":"https://launchpad.net/ubuntu/+source/rdesktop/1.6.0-2ubuntu3.1"}],"maverick":[{"name":"rdesktop","version":"1.6.0-3ubuntu2.1","description":"RDP client for Windows NT/2000 Terminal Server","is_source":true},{"name":"rdesktop","version":"1.6.0-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/rdesktop","version_link":"https://launchpad.net/ubuntu/+source/rdesktop/1.6.0-3ubuntu2.1"}],"natty":[{"name":"rdesktop","version":"1.6.0-3ubuntu4.1","description":"RDP client for Windows NT/2000 Terminal Server","is_source":true},{"name":"rdesktop","version":"1.6.0-3ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/rdesktop","version_link":"https://launchpad.net/ubuntu/+source/rdesktop/1.6.0-3ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2011-1595"]}]},{"id":"CVE-2011-1927","published":"2011-05-18T00:00:00","updated_at":"2026-07-04T07:32:59.792963+00:00","description":"\nThe ip_expire function in net/ipv4/ip_fragment.c in the Linux kernel before\n2.6.39 does not properly construct ICMP_TIME_EXCEEDED packets after a\ntimeout, which allows remote attackers to cause a denial of service\n(invalid pointer dereference) via crafted fragmented packets.","ubuntu_description":"\nAristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service.","notes":[{"author":"jdstrand","note":"2.6.38 only?"},{"author":"apw","note":"this report and the fix overlapped with each other commit below was\nidentified as the fix:\n64f3b9e203bd06855072e295557dca1485a2ecba"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://seclists.org/bugtraq/2011/May/123","http://packetstormsecurity.org/files/view/101475/linux2638-null.txt","http://marc.info/?l=linux-netdev&m=130558001727019&w=2","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1379-1","https://ubuntu.com/security/notices/USN-1383-1","https://ubuntu.com/security/notices/USN-1387-1","https://ubuntu.com/security/notices/USN-1394-1","https://www.cve.org/CVERecord?id=CVE-2011-1927"],"bugs":["https://launchpad.net/bugs/922051"],"patches":{"linux":["break-fix: 4a94445c9a5cf5461fb41d80040033b9a8e2a85a 64f3b9e203bd06855072e295557dca1485a2ecba"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-32.66","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-10.44","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.6.39-3.9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-32.66~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.38-10.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.0-5.6~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.31","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-1209.22","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-1200.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39","component":null,"pocket":"security"}]}],"notices_ids":["USN-1379-1","USN-1387-1","USN-1383-1","USN-1167-1","USN-1394-1"],"notices":[{"id":"USN-1379-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-02-28T23:48:33.275827","description":"Aristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service. (CVE-2011-1927)\n\nA flaw was found in the Linux Ethernet bridge's handling of IGMP (Internet\nGroup Management Protocol) packets. An unprivileged local user could\nexploit this flaw to crash the system. (CVE-2011-0716)\n\nA flaw was discovered in the Linux kernel's AppArmor security interface\nwhen invalid information was written to it. An unprivileged local user\ncould use this to cause a denial of service on the system. (CVE-2011-3619)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-32.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-32-powerpc64-smp","version":"2.6.35-32.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.66"},{"name":"linux-image-2.6.35-32-generic-pae","version":"2.6.35-32.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.66"},{"name":"linux-image-2.6.35-32-versatile","version":"2.6.35-32.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.66"},{"name":"linux-image-2.6.35-32-generic","version":"2.6.35-32.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.66"},{"name":"linux-image-2.6.35-32-virtual","version":"2.6.35-32.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.66"},{"name":"linux-image-2.6.35-32-powerpc-smp","version":"2.6.35-32.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.66"},{"name":"linux-image-2.6.35-32-powerpc","version":"2.6.35-32.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.66"},{"name":"linux-image-2.6.35-32-server","version":"2.6.35-32.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.66"},{"name":"linux-image-2.6.35-32-omap","version":"2.6.35-32.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-32.66"}]},"type":"USN","cves_ids":["CVE-2011-0716","CVE-2011-1927","CVE-2011-3619"]},{"id":"USN-1387-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-03-06T18:25:01.507657","description":"Aristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service. (CVE-2011-1927)\n\nA flaw was found in the Linux Ethernet bridge's handling of IGMP (Internet\nGroup Management Protocol) packets. An unprivileged local user could\nexploit this flaw to crash the system. (CVE-2011-0716)\n\nHan-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user\nwho can mount a FUSE file system could cause a denial of service.\n(CVE-2011-3353)\n\nA flaw was discovered in the Linux kernel's AppArmor security interface\nwhen invalid information was written to it. An unprivileged local user\ncould use this to cause a denial of service on the system. (CVE-2011-3619)\n\nA flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual\ninterrupt control is not available a local user could use this to cause a\ndenial of service by starting a timer. (CVE-2011-4622)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-32.66~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-32-virtual","version":"2.6.35-32.66~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.66~lucid1"},{"name":"linux-image-2.6.35-32-server","version":"2.6.35-32.66~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.66~lucid1"},{"name":"linux-image-2.6.35-32-generic-pae","version":"2.6.35-32.66~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.66~lucid1"},{"name":"linux-image-2.6.35-32-generic","version":"2.6.35-32.66~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-32.66~lucid1"}]},"type":"USN","cves_ids":["CVE-2012-0044","CVE-2011-0716","CVE-2011-1927","CVE-2011-3353","CVE-2011-3619","CVE-2011-4622","CVE-2012-0038"]},{"id":"USN-1383-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-03-06T14:52:29.773873","description":"Aristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service. (CVE-2011-1927)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nBen Hutchings reported a flaw in the kernel's handling of corrupt LDM\npartitions. A local user could exploit this to cause a denial of service or\nescalate privileges. (CVE-2011-2182)\n\nThe linux kernel did not properly account for PTE pages when deciding which\ntask to kill in out of memory conditions. A local, unprivileged could\nexploit this flaw to cause a denial of service. (CVE-2011-2498)\n\nA flaw was discovered in the TOMOYO LSM's handling of mount system calls.\nAn unprivileged user could oops the system causing a denial of service.\n(CVE-2011-2518)\n\nA flaw was discovered in the Linux kernel's AppArmor security interface\nwhen invalid information was written to it. An unprivileged local user\ncould use this to cause a denial of service on the system. (CVE-2011-3619)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux-ti-omap4","version":"2.6.38-1209.22","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.38-1209-omap4","version":"2.6.38-1209.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.38-1209.22"}]},"type":"USN","cves_ids":["CVE-2011-1759","CVE-2011-2498","CVE-2011-2518","CVE-2011-1927","CVE-2011-2182","CVE-2011-3619"]},{"id":"USN-1167-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-13T22:18:00.931979","description":"\nAristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service. (CVE-2011-1927)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nIt was discovered that the security fix for CVE-2010-4250 introduced a\nregression. A remote attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1479)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nBen Greear discovered that CIFS did not correctly handle direct I/O. A\nlocal attacker with access to a CIFS partition could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1771)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nIt was discovered that an mmap() call with the MAP_PRIVATE flag on\n\"/dev/zero\" was incorrectly handled. A local attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2011-2479)\n\nRobert Swiecki discovered that mapping extensions were incorrectly handled.\nA local attacker could exploit this to crash the system, leading to a\ndenial of service. (CVE-2011-2496)\n\nThe linux kernel did not properly account for PTE pages when deciding which\ntask to kill in out of memory conditions. A local, unprivileged could\nexploit this flaw to cause a denial of service. (CVE-2011-2498)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux","version":"2.6.38-10.46","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.38-10-server","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-virtual","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-generic-pae","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-powerpc","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-powerpc-smp","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-versatile","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-omap","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-powerpc64-smp","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-generic","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"}]},"type":"USN","cves_ids":["CVE-2011-1771","CVE-2011-0463","CVE-2011-1017","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1093","CVE-2011-1160","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1476","CVE-2011-1477","CVE-2011-1479","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1759","CVE-2011-1770","CVE-2011-1776","CVE-2011-1927","CVE-2011-2022","CVE-2011-2479","CVE-2011-2496","CVE-2011-2498","CVE-2011-2534","CVE-2011-3359","CVE-2011-3363","CVE-2011-4913"]},{"id":"USN-1394-1","title":"linux-ti-omap4 vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-03-07T17:12:11.888884","description":"Aristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service. (CVE-2011-1927)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nA flaw was found in the Linux Ethernet bridge's handling of IGMP (Internet\nGroup Management Protocol) packets. An unprivileged local user could\nexploit this flaw to crash the system. (CVE-2011-0716)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nBen Hutchings reported a flaw in the kernel's handling of corrupt LDM\npartitions. A local user could exploit this to cause a denial of service or\nescalate privileges. (CVE-2011-2182)\n\nA flaw was discovered in the Linux kernel's AppArmor security interface\nwhen invalid information was written to it. An unprivileged local user\ncould use this to cause a denial of service on the system. (CVE-2011-3619)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.32","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.32"}]},"type":"USN","cves_ids":["CVE-2010-4250","CVE-2010-4650","CVE-2011-0006","CVE-2011-0716","CVE-2011-1476","CVE-2011-1477","CVE-2011-1759","CVE-2011-1927","CVE-2011-2182","CVE-2011-3619","CVE-2011-4621","CVE-2012-0038","CVE-2012-0044"]}]},{"id":"CVE-2011-1800","published":"2011-05-16T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in the SVG Filters implementation in WebCore in\nWebKit in Google Chrome before 11.0.696.68 allow remote attackers to cause\na denial of service or possibly have unspecified other impact via unknown\nvectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1800"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qt4-x11":[],"qtwebkit-source":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.1271.97-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"11.0.696.68r84545-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"11.0.696.68r84545-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.1271.97-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.1271.97-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.0.1271.97-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.0.696.68","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1799","published":"2011-05-16T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 11.0.696.68 does not properly perform casts of\nvariables during interaction with the WebKit engine, which allows remote\nattackers to cause a denial of service or possibly have unspecified other\nimpact via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1799"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qt4-x11":[],"qtwebkit-source":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.1271.97-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"11.0.696.68r84545-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"11.0.696.68r84545-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.1271.97-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.1271.97-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.0.1271.97-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.0.696.68","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"11.0.696.68r84545-0ubuntu1","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1407","published":"2011-05-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM\nidentities to apply to lookup items, instead of only strings, which allows\nremote attackers to execute arbitrary code or access a filesystem via a\ncrafted identity.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects 4.7x and higher"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1135-1","https://www.cve.org/CVERecord?id=CVE-2011-1407"],"bugs":[""],"patches":{"exim4":["upstream: http://git.exim.org/exim.git/commit/ae9094bfe313aeb9ffefc7566bd4dae49ada3cf5"]},"tags":{},"packages":[{"name":"exim4","source":"https://ubuntu.com/security/cve?package=exim4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exim4","debian":"https://tracker.debian.org/pkg/exim4","statuses":[{"release_codename":"dapper","status":"not-affected","description":"4.60-3ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"4.69-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"4.71-3ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"4.72-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"4.74-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.76","component":null,"pocket":"security"}]}],"notices_ids":["USN-1135-1"],"notices":[{"id":"USN-1135-1","title":"Exim vulnerability","summary":"An attacker could send crafted input to Exim and cause it to run programs\nas the Exim user.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-05-25T16:44:21.939781","description":"It was discovered that the Exim daemon did not correctly handle certain\nDKIM identities. A remote attacker could send specially crafted email to\nrun arbitrary code as the Exim user.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"exim4","version":"4.71-3ubuntu1.3","description":"metapackage to ease Exim MTA (v4) installation","is_source":true},{"name":"exim4-daemon-heavy","version":"4.71-3ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.71-3ubuntu1.3"},{"name":"exim4-daemon-custom","version":"4.71-3ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.71-3ubuntu1.3"},{"name":"exim4-daemon-light","version":"4.71-3ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.71-3ubuntu1.3"}],"maverick":[{"name":"exim4","version":"4.72-1ubuntu1.3","description":"metapackage to ease Exim MTA (v4) installation","is_source":true},{"name":"exim4-daemon-heavy","version":"4.72-1ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.72-1ubuntu1.3"},{"name":"exim4-daemon-custom","version":"4.72-1ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.72-1ubuntu1.3"},{"name":"exim4-daemon-light","version":"4.72-1ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.72-1ubuntu1.3"}],"natty":[{"name":"exim4","version":"4.74-1ubuntu1.2","description":"metapackage to ease Exim MTA (v4) installation","is_source":true},{"name":"exim4-daemon-heavy","version":"4.74-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.74-1ubuntu1.2"},{"name":"exim4-daemon-custom","version":"4.74-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.74-1ubuntu1.2"},{"name":"exim4-daemon-light","version":"4.74-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.74-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2011-1407"]}]},{"id":"CVE-2011-0419","published":"2011-05-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack consumption vulnerability in the fnmatch implementation in\napr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and\nthe Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD\n5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and\nAndroid, allows context-dependent attackers to cause a denial of service\n(CPU and memory consumption) via *? sequences in the first argument, as\ndemonstrated by attacks against mod_autoindex in httpd.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"TODO: also check apr-util"},{"author":"sbeattie","note":"update for apr-util is not needed."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1134-1","https://www.cve.org/CVERecord?id=CVE-2011-0419"],"bugs":[""],"patches":{"apr":["vendor: http://www.debian.org/security/2011/dsa-2237","vendor: https://rhn.redhat.com/errata/RHSA-2011-0507.html"],"apache2":[]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.13","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"uses system apr","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"uses system apr","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"uses system apr","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"uses system apr","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"apr","source":"https://ubuntu.com/security/cve?package=apr","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apr","debian":"https://tracker.debian.org/pkg/apr","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.11-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.3.8-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.4.2-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.4.2-7ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1134-1"],"notices":[{"id":"USN-1134-1","title":"APR vulnerabilities","summary":"A denial of service issue exists that affects the Apache web server.\n","instructions":"After a standard system update you need to restart the Apache web\nserver or any other service that depends on the APR library to make\nall the necessary changes.\n","references":[],"published":"2011-05-24T20:26:50.375620","description":"Maksymilian Arciemowicz reported that a flaw in the fnmatch()\nimplementation in the Apache Portable Runtime (APR) library could allow\nan attacker to cause a denial of service. This can be demonstrated\nin a remote denial of service attack against mod_autoindex in the\nApache web server. (CVE-2011-0419)\n\nIs was discovered that the fix for CVE-2011-0419 introduced a different\nflaw in the fnmatch() implementation that could also result in a\ndenial of service. (CVE-2011-1928)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"apr","version":"1.2.11-1ubuntu0.2","description":"The Apache Portable Runtime Library","is_source":true},{"name":"libapr1","version":"1.2.11-1ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr","version_link":"https://launchpad.net/ubuntu/+source/apr/1.2.11-1ubuntu0.2"}],"dapper":[{"name":"apache2","version":"2.0.55-4ubuntu2.13","description":"a scalable, extensible web server","is_source":true},{"name":"libapr0","version":"2.0.55-4ubuntu2.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.13"}],"maverick":[{"name":"apr","version":"1.4.2-3ubuntu1.1","description":"The Apache Portable Runtime Library","is_source":true},{"name":"libapr1","version":"1.4.2-3ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr","version_link":"https://launchpad.net/ubuntu/+source/apr/1.4.2-3ubuntu1.1"}],"lucid":[{"name":"apr","version":"1.3.8-1ubuntu0.3","description":"The Apache Portable Runtime Library","is_source":true},{"name":"libapr1","version":"1.3.8-1ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr","version_link":"https://launchpad.net/ubuntu/+source/apr/1.3.8-1ubuntu0.3"}],"natty":[{"name":"apr","version":"1.4.2-7ubuntu2.1","description":"The Apache Portable Runtime Library","is_source":true},{"name":"libapr1","version":"1.4.2-7ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr","version_link":"https://launchpad.net/ubuntu/+source/apr/1.4.2-7ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2011-0419","CVE-2011-1928"]}]},{"id":"CVE-2011-1406","published":"2011-05-13T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMahara before 1.3.6 does not properly handle an https URL in the wwwroot\nconfiguration setting, which makes it easier for user-assisted remote\nattackers to obtain credentials by sniffing the network at a time when an\nhttp URL is used for a login.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1406"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/780917"],"patches":{"mahara":[]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.7-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1405","published":"2011-05-13T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows\nremote authenticated users to inject arbitrary web script or HTML via\nvectors associated with HTML e-mail messages, related to\nartefact/comment/lib.php and interaction/forum/lib.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1405"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/780917"],"patches":{"mahara":[]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.7-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1404","published":"2011-05-13T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMahara before 1.3.6 does not properly restrict the data in responses to\nAJAX calls, which allows remote authenticated users to obtain sensitive\ninformation via a request associated with (1)\nblocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3)\ngroup/membersearchresults.json.php, or (4) json/friendsearch.php, as\ndemonstrated by information about friends and e-mail addresses.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1404"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/780917"],"patches":{"mahara":[]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.2.7-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":71180,"limit":20,"total_results":79316}