{"cves":[{"id":"CVE-2011-1293","published":"2011-03-25T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the HTMLCollection implementation in Google\nChrome before 10.0.648.204 allows remote attackers to cause a denial of\nservice or possibly have unspecified other impact via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2011/03/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-1293"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=73595"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"10.0.648.204~r79063-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"10.0.648.204~r79063-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.648.204","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1292","published":"2011-03-25T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the frame-loader implementation in Google\nChrome before 10.0.648.204 allows remote attackers to cause a denial of\nservice or possibly have unspecified other impact via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2011/03/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-1292"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=73216"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"10.0.648.204~r79063-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"10.0.648.204~r79063-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.648.204","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1291","published":"2011-03-25T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 10.0.648.204 does not properly handle base strings,\nwhich allows remote attackers to cause a denial of service or possibly have\nunspecified other impact via unknown vectors, related to a \"buffer error.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2011/03/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-1291"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=72517"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"10.0.648.204~r79063-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"10.0.648.204~r79063-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.648.204","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1477","published":"2011-03-25T00:00:00","updated_at":"2026-07-04T07:34:14.454335+00:00","description":"\nMultiple array index errors in sound/oss/opl3.c in the Linux kernel before\n2.6.39 allow local users to cause a denial of service (heap memory\ncorruption) or possibly gain privileges by leveraging write access to\n/dev/sequencer.","ubuntu_description":"\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation.","notes":[{"author":"jdstrand","note":"requires /dev/sequencer and OSS (not ALSA)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=linux-kernel&m=130089499728386&w=2","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1160-1","https://ubuntu.com/security/notices/USN-1141-1","https://ubuntu.com/security/notices/USN-1162-1","https://ubuntu.com/security/notices/USN-1212-1","https://ubuntu.com/security/notices/USN-1159-1","https://ubuntu.com/security/notices/USN-1390-1","https://ubuntu.com/security/notices/USN-1394-1","https://ubuntu.com/security/notices/USN-1187-1","https://www.cve.org/CVERecord?id=CVE-2011-1477"],"bugs":["https://launchpad.net/bugs/925335"],"patches":{"linux":["break-fix: - 4d00135a680727f6c3be78f8befaac009030e4df"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-armadaxp":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"released","description":"2.6.24-31.99","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-32.62","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-29.51","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-9.43","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.39-0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.1.0-1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.1.0-1.0","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1600.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1602.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-316.30","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-30.54~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-9.43~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.0.0-5.6~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-217.34","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-417.34","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.31","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-1209.13","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.38-1309.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.0.0-1401.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.0.0-1401.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1160-1","USN-1141-1","USN-1162-1","USN-1167-1","USN-1394-1","USN-1187-1","USN-1390-1","USN-1212-1","USN-1159-1"],"notices":[{"id":"USN-1160-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerabilities have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-06-28T10:41:47.447924","description":"\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1748)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-30.54","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-30-powerpc-smp","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-versatile","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-powerpc64-smp","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-omap","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-powerpc","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"}]},"type":"USN","cves_ids":["CVE-2010-4529","CVE-2010-4565","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1093","CVE-2011-1160","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1745","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4913"]},{"id":"USN-1141-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerabilities have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-06-01T00:00:41.970993","description":"\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlexander Duyck discovered that the Intel Gigabit Ethernet driver did not\ncorrectly handle certain configurations. If such a device was configured\nwithout VLANs, a remote attacker could crash the system, leading to a\ndenial of service. (CVE-2010-4263)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-316.31","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-32.62","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-32-386","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-316-ec2","version":"2.6.32-316.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-316.31"},{"name":"linux-image-2.6.32-32-lpia","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-ia64","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-versatile","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-server","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-powerpc64-smp","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-generic-pae","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-powerpc-smp","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-generic","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-virtual","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-sparc64-smp","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-powerpc","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-preempt","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-sparc64","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"}]},"type":"USN","cves_ids":["CVE-2011-1573","CVE-2010-4263","CVE-2010-4243","CVE-2010-4342","CVE-2010-4529","CVE-2010-4565","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1093","CVE-2011-1160","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4913"]},{"id":"USN-1162-1","title":"Linux kernel vulnerabilities (Marvell Dove)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-06-29T12:02:55.601188","description":"\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlexander Duyck discovered that the Intel Gigabit Ethernet driver did not\ncorrectly handle certain configurations. If such a device was configured\nwithout VLANs, a remote attacker could crash the system, leading to a\ndenial of service. (CVE-2010-4263)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-217.34","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-217-dove","version":"2.6.32-217.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-217.34"}]},"type":"USN","cves_ids":["CVE-2010-4243","CVE-2010-4263","CVE-2010-4342","CVE-2010-4529","CVE-2010-4565","CVE-2011-0463","CVE-2011-0695","CVE-2011-0711","CVE-2011-0726","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1090","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1573","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1759","CVE-2011-1770","CVE-2011-1776","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-3363","CVE-2011-4611","CVE-2011-4913"]},{"id":"USN-1167-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-13T22:18:00.931979","description":"\nAristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service. (CVE-2011-1927)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nIt was discovered that the security fix for CVE-2010-4250 introduced a\nregression. A remote attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1479)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nBen Greear discovered that CIFS did not correctly handle direct I/O. A\nlocal attacker with access to a CIFS partition could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1771)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nIt was discovered that an mmap() call with the MAP_PRIVATE flag on\n\"/dev/zero\" was incorrectly handled. A local attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2011-2479)\n\nRobert Swiecki discovered that mapping extensions were incorrectly handled.\nA local attacker could exploit this to crash the system, leading to a\ndenial of service. (CVE-2011-2496)\n\nThe linux kernel did not properly account for PTE pages when deciding which\ntask to kill in out of memory conditions. A local, unprivileged could\nexploit this flaw to cause a denial of service. (CVE-2011-2498)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux","version":"2.6.38-10.46","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.38-10-server","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-virtual","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-generic-pae","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-powerpc","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-powerpc-smp","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-versatile","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-omap","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-powerpc64-smp","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-generic","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"}]},"type":"USN","cves_ids":["CVE-2011-1771","CVE-2011-0463","CVE-2011-1017","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1093","CVE-2011-1160","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1476","CVE-2011-1477","CVE-2011-1479","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1759","CVE-2011-1770","CVE-2011-1776","CVE-2011-1927","CVE-2011-2022","CVE-2011-2479","CVE-2011-2496","CVE-2011-2498","CVE-2011-2534","CVE-2011-3359","CVE-2011-3363","CVE-2011-4913"]},{"id":"USN-1394-1","title":"linux-ti-omap4 vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-03-07T17:12:11.888884","description":"Aristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service. (CVE-2011-1927)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nA flaw was found in the Linux Ethernet bridge's handling of IGMP (Internet\nGroup Management Protocol) packets. An unprivileged local user could\nexploit this flaw to crash the system. (CVE-2011-0716)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nBen Hutchings reported a flaw in the kernel's handling of corrupt LDM\npartitions. A local user could exploit this to cause a denial of service or\nescalate privileges. (CVE-2011-2182)\n\nA flaw was discovered in the Linux kernel's AppArmor security interface\nwhen invalid information was written to it. An unprivileged local user\ncould use this to cause a denial of service on the system. (CVE-2011-3619)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.32","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.32"}]},"type":"USN","cves_ids":["CVE-2010-4250","CVE-2010-4650","CVE-2011-0006","CVE-2011-0716","CVE-2011-1476","CVE-2011-1477","CVE-2011-1759","CVE-2011-1927","CVE-2011-2182","CVE-2011-3619","CVE-2011-4621","CVE-2012-0038","CVE-2012-0044"]},{"id":"USN-1187-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-08-09T03:09:05.161378","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-30.56~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4079","CVE-2010-4083","CVE-2010-4163","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529","CVE-2010-4565","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4621","CVE-2011-4913"]},{"id":"USN-1390-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-03-06T19:31:18.741691","description":"Dan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nBen Hutchings reported a flaw in the kernel's handling of corrupt LDM\npartitions. A local user could exploit this to cause a denial of service or\nescalate privileges. (CVE-2011-2182)\n\nA flaw was discovered in the Linux kernel's NFSv4 (Network File System\nversion 4) file system. A local, unprivileged user could use this flaw to\ncause a denial of service by creating a file in a NFSv4 filesystem.\n(CVE-2011-4324)\n\nA flaw was found in how the linux kernel handles user-space held futexs. An\nunprivileged user could exploit this flaw to cause a denial of service or\npossibly elevate privileges. (CVE-2012-0028)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-31.99","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-31-powerpc","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-sparc64","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-virtual","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-server","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-hppa32","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-lpiacompat","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-rt","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-lpia","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-generic","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-hppa64","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-mckinley","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-xen","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-powerpc64-smp","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-itanium","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-openvz","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-386","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-sparc64-smp","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-powerpc-smp","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"}]},"type":"USN","cves_ids":["CVE-2011-1476","CVE-2011-1477","CVE-2011-2182","CVE-2011-4324","CVE-2012-0028"]},{"id":"USN-1212-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple kernel flaws have been fixed. \n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-09-21T12:31:09.943733","description":"\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nIt was discovered that the security fix for CVE-2010-4250 introduced a\nregression. A remote attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1479)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nPhil Oester discovered that the network bonding system did not correctly\nhandle large queues. On some systems, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1581)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nBen Greear discovered that CIFS did not correctly handle direct I/O. A\nlocal attacker with access to a CIFS partition could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1771)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nSami Liedes discovered that ext4 did not correctly handle missing root\ninodes. A local attacker could trigger the mount of a specially crafted\nfilesystem to cause the system to crash, leading to a denial of service.\n(CVE-2011-2493)\n\nIt was discovered that GFS2 did not correctly check block sizes. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2011-2689)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux-ti-omap4","version":"2.6.38-1209.15","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.38-1209-omap4","version":"2.6.38-1209.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.38-1209.15"}]},"type":"USN","cves_ids":["CVE-2011-0463","CVE-2011-1017","CVE-2011-1020","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1160","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1479","CVE-2011-1493","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1581","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1770","CVE-2011-1771","CVE-2011-1833","CVE-2011-2022","CVE-2011-2484","CVE-2011-2492","CVE-2011-2493","CVE-2011-2534","CVE-2011-2689","CVE-2011-2699","CVE-2011-2918","CVE-2011-3359","CVE-2011-3637","CVE-2011-4621","CVE-2011-4913","CVE-2011-4914"]},{"id":"USN-1159-1","title":"Linux kernel vulnerabilities (Marvell Dove)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-13T20:25:16.658771","description":"\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlexander Duyck discovered that the Intel Gigabit Ethernet driver did not\ncorrectly handle certain configurations. If such a device was configured\nwithout VLANs, a remote attacker could crash the system, leading to a\ndenial of service. (CVE-2010-4263)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-417.34","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-417-dove","version":"2.6.32-417.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-417.34"}]},"type":"USN","cves_ids":["CVE-2010-4243","CVE-2010-4263","CVE-2010-4342","CVE-2010-4529","CVE-2010-4565","CVE-2011-0463","CVE-2011-0695","CVE-2011-0711","CVE-2011-0726","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1090","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1573","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1759","CVE-2011-1770","CVE-2011-1776","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-3363","CVE-2011-4611","CVE-2011-4913"]}]},{"id":"CVE-2011-1476","published":"2011-03-25T00:00:00","updated_at":"2026-07-04T07:33:39.706909+00:00","description":"\nInteger underflow in the Open Sound System (OSS) subsystem in the Linux\nkernel before 2.6.39 on unspecified non-x86 platforms allows local users to\ncause a denial of service (memory corruption) by leveraging write access to\n/dev/sequencer.","ubuntu_description":"\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service.","notes":[{"author":"jdstrand","note":"requires /dev/sequencer and OSS (not ALSA)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=linux-kernel&m=130089204124354&w=2","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1160-1","https://ubuntu.com/security/notices/USN-1141-1","https://ubuntu.com/security/notices/USN-1162-1","https://ubuntu.com/security/notices/USN-1212-1","https://ubuntu.com/security/notices/USN-1159-1","https://ubuntu.com/security/notices/USN-1390-1","https://ubuntu.com/security/notices/USN-1394-1","https://ubuntu.com/security/notices/USN-1187-1","https://www.cve.org/CVERecord?id=CVE-2011-1476"],"bugs":["https://launchpad.net/bugs/925337"],"patches":{"linux":["break-fix: - b769f49463711205d57286e64cf535ed4daf59e9"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-armadaxp":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"released","description":"2.6.24-31.99","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-32.62","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-30.52","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-9.43","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.39-0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.1.0-1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.1.0-1.0","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1600.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1602.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-316.30","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-30.54~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-9.43~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.0.0-5.6~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-217.34","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-417.34","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.31","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-1209.13","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.38-1309.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.0.0-1401.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.0.0-1401.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.39~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1160-1","USN-1141-1","USN-1162-1","USN-1167-1","USN-1394-1","USN-1187-1","USN-1390-1","USN-1212-1","USN-1159-1"],"notices":[{"id":"USN-1160-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerabilities have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-06-28T10:41:47.447924","description":"\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1748)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-30.54","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-30-powerpc-smp","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-versatile","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-powerpc64-smp","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-omap","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"},{"name":"linux-image-2.6.35-30-powerpc","version":"2.6.35-30.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.54"}]},"type":"USN","cves_ids":["CVE-2010-4529","CVE-2010-4565","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1093","CVE-2011-1160","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1745","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4913"]},{"id":"USN-1141-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerabilities have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-06-01T00:00:41.970993","description":"\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlexander Duyck discovered that the Intel Gigabit Ethernet driver did not\ncorrectly handle certain configurations. If such a device was configured\nwithout VLANs, a remote attacker could crash the system, leading to a\ndenial of service. (CVE-2010-4263)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-316.31","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-32.62","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-32-386","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-316-ec2","version":"2.6.32-316.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-316.31"},{"name":"linux-image-2.6.32-32-lpia","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-ia64","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-versatile","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-server","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-powerpc64-smp","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-generic-pae","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-powerpc-smp","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-generic","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-virtual","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-sparc64-smp","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-powerpc","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-preempt","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-sparc64","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"}]},"type":"USN","cves_ids":["CVE-2011-1573","CVE-2010-4263","CVE-2010-4243","CVE-2010-4342","CVE-2010-4529","CVE-2010-4565","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1093","CVE-2011-1160","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4913"]},{"id":"USN-1162-1","title":"Linux kernel vulnerabilities (Marvell Dove)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-06-29T12:02:55.601188","description":"\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlexander Duyck discovered that the Intel Gigabit Ethernet driver did not\ncorrectly handle certain configurations. If such a device was configured\nwithout VLANs, a remote attacker could crash the system, leading to a\ndenial of service. (CVE-2010-4263)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-217.34","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-217-dove","version":"2.6.32-217.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-217.34"}]},"type":"USN","cves_ids":["CVE-2010-4243","CVE-2010-4263","CVE-2010-4342","CVE-2010-4529","CVE-2010-4565","CVE-2011-0463","CVE-2011-0695","CVE-2011-0711","CVE-2011-0726","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1090","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1573","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1759","CVE-2011-1770","CVE-2011-1776","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-3363","CVE-2011-4611","CVE-2011-4913"]},{"id":"USN-1167-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-13T22:18:00.931979","description":"\nAristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service. (CVE-2011-1927)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nIt was discovered that the security fix for CVE-2010-4250 introduced a\nregression. A remote attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1479)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nBen Greear discovered that CIFS did not correctly handle direct I/O. A\nlocal attacker with access to a CIFS partition could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1771)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nIt was discovered that an mmap() call with the MAP_PRIVATE flag on\n\"/dev/zero\" was incorrectly handled. A local attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2011-2479)\n\nRobert Swiecki discovered that mapping extensions were incorrectly handled.\nA local attacker could exploit this to crash the system, leading to a\ndenial of service. (CVE-2011-2496)\n\nThe linux kernel did not properly account for PTE pages when deciding which\ntask to kill in out of memory conditions. A local, unprivileged could\nexploit this flaw to cause a denial of service. (CVE-2011-2498)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux","version":"2.6.38-10.46","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.38-10-server","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-virtual","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-generic-pae","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-powerpc","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-powerpc-smp","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-versatile","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-omap","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-powerpc64-smp","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"},{"name":"linux-image-2.6.38-10-generic","version":"2.6.38-10.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-10.46"}]},"type":"USN","cves_ids":["CVE-2011-1771","CVE-2011-0463","CVE-2011-1017","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1093","CVE-2011-1160","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1476","CVE-2011-1477","CVE-2011-1479","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1759","CVE-2011-1770","CVE-2011-1776","CVE-2011-1927","CVE-2011-2022","CVE-2011-2479","CVE-2011-2496","CVE-2011-2498","CVE-2011-2534","CVE-2011-3359","CVE-2011-3363","CVE-2011-4913"]},{"id":"USN-1394-1","title":"linux-ti-omap4 vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-03-07T17:12:11.888884","description":"Aristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's\nhandling of IPv4 icmp packets. A remote user could exploit this to cause a\ndenial of service. (CVE-2011-1927)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nA flaw was found in the Linux Ethernet bridge's handling of IGMP (Internet\nGroup Management Protocol) packets. An unprivileged local user could\nexploit this flaw to crash the system. (CVE-2011-0716)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nBen Hutchings reported a flaw in the kernel's handling of corrupt LDM\npartitions. A local user could exploit this to cause a denial of service or\nescalate privileges. (CVE-2011-2182)\n\nA flaw was discovered in the Linux kernel's AppArmor security interface\nwhen invalid information was written to it. An unprivileged local user\ncould use this to cause a denial of service on the system. (CVE-2011-3619)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nA flaw was discovered in the XFS filesystem. If a local user mounts a\nspecially crafted XFS image it could potential execute arbitrary code on\nthe system. (CVE-2012-0038)\n\nChen Haogang discovered an integer overflow that could result in memory\ncorruption. A local unprivileged user could use this to crash the system.\n(CVE-2012-0044)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.32","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.32"}]},"type":"USN","cves_ids":["CVE-2010-4250","CVE-2010-4650","CVE-2011-0006","CVE-2011-0716","CVE-2011-1476","CVE-2011-1477","CVE-2011-1759","CVE-2011-1927","CVE-2011-2182","CVE-2011-3619","CVE-2011-4621","CVE-2012-0038","CVE-2012-0044"]},{"id":"USN-1187-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-08-09T03:09:05.161378","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-30.56~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4079","CVE-2010-4083","CVE-2010-4163","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529","CVE-2010-4565","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4621","CVE-2011-4913"]},{"id":"USN-1390-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-03-06T19:31:18.741691","description":"Dan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nBen Hutchings reported a flaw in the kernel's handling of corrupt LDM\npartitions. A local user could exploit this to cause a denial of service or\nescalate privileges. (CVE-2011-2182)\n\nA flaw was discovered in the Linux kernel's NFSv4 (Network File System\nversion 4) file system. A local, unprivileged user could use this flaw to\ncause a denial of service by creating a file in a NFSv4 filesystem.\n(CVE-2011-4324)\n\nA flaw was found in how the linux kernel handles user-space held futexs. An\nunprivileged user could exploit this flaw to cause a denial of service or\npossibly elevate privileges. (CVE-2012-0028)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-31.99","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-31-powerpc","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-sparc64","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-virtual","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-server","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-hppa32","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-lpiacompat","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-rt","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-lpia","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-generic","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-hppa64","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-mckinley","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-xen","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-powerpc64-smp","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-itanium","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-openvz","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-386","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-sparc64-smp","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"},{"name":"linux-image-2.6.24-31-powerpc-smp","version":"2.6.24-31.99","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-31.99"}]},"type":"USN","cves_ids":["CVE-2011-1476","CVE-2011-1477","CVE-2011-2182","CVE-2011-4324","CVE-2012-0028"]},{"id":"USN-1212-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple kernel flaws have been fixed. \n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-09-21T12:31:09.943733","description":"\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nIt was discovered that the security fix for CVE-2010-4250 introduced a\nregression. A remote attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1479)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nPhil Oester discovered that the network bonding system did not correctly\nhandle large queues. On some systems, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1581)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nBen Greear discovered that CIFS did not correctly handle direct I/O. A\nlocal attacker with access to a CIFS partition could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1771)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nSami Liedes discovered that ext4 did not correctly handle missing root\ninodes. A local attacker could trigger the mount of a specially crafted\nfilesystem to cause the system to crash, leading to a denial of service.\n(CVE-2011-2493)\n\nIt was discovered that GFS2 did not correctly check block sizes. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2011-2689)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux-ti-omap4","version":"2.6.38-1209.15","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.38-1209-omap4","version":"2.6.38-1209.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.38-1209.15"}]},"type":"USN","cves_ids":["CVE-2011-0463","CVE-2011-1017","CVE-2011-1020","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1160","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1479","CVE-2011-1493","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1581","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1770","CVE-2011-1771","CVE-2011-1833","CVE-2011-2022","CVE-2011-2484","CVE-2011-2492","CVE-2011-2493","CVE-2011-2534","CVE-2011-2689","CVE-2011-2699","CVE-2011-2918","CVE-2011-3359","CVE-2011-3637","CVE-2011-4621","CVE-2011-4913","CVE-2011-4914"]},{"id":"USN-1159-1","title":"Linux kernel vulnerabilities (Marvell Dove)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-13T20:25:16.658771","description":"\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlexander Duyck discovered that the Intel Gigabit Ethernet driver did not\ncorrectly handle certain configurations. If such a device was configured\nwithout VLANs, a remote attacker could crash the system, leading to a\ndenial of service. (CVE-2010-4263)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-417.34","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-417-dove","version":"2.6.32-417.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-417.34"}]},"type":"USN","cves_ids":["CVE-2010-4243","CVE-2010-4263","CVE-2010-4342","CVE-2010-4529","CVE-2010-4565","CVE-2011-0463","CVE-2011-0695","CVE-2011-0711","CVE-2011-0726","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1090","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1573","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1759","CVE-2011-1770","CVE-2011-1776","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-3363","CVE-2011-4611","CVE-2011-4913"]}]},{"id":"CVE-2011-1400","published":"2011-03-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of the shell_escape_commands directive in\nconf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in\nDebian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other\noperating systems lists certain programs, which might allow remote\nattackers to execute arbitrary code via a crafted TeX document.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.debian.org/security/2011/dsa-2198","https://ubuntu.com/security/notices/USN-1103-1","https://www.cve.org/CVERecord?id=CVE-2011-1400"],"bugs":[""],"patches":{"tex-common":[]},"tags":{},"packages":[{"name":"tex-common","source":"https://ubuntu.com/security/cve?package=tex-common","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tex-common","debian":"https://tracker.debian.org/pkg/tex-common","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"disabled","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"disabled","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.06ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.08ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.08.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1103-1"],"notices":[{"id":"USN-1103-1","title":"tex-common vulnerability","summary":"tex-common could be made to run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-04-04T17:11:33.175589","description":"Mathias Svensson discovered that the tex-common package contains an\ninsecure shell_escape_commands configuration item. If a user or automated\nsystem were tricked into opening a specially crafted TeX file, a remote\nattacker could execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"tex-common","version":"2.06ubuntu0.1","description":"common infrastructure for building and installing TeX","is_source":true},{"name":"tex-common","version":"2.06ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tex-common","version_link":"https://launchpad.net/ubuntu/+source/tex-common/2.06ubuntu0.1"}],"maverick":[{"name":"tex-common","version":"2.08ubuntu0.1","description":"common infrastructure for building and installing TeX","is_source":true},{"name":"tex-common","version":"2.08ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tex-common","version_link":"https://launchpad.net/ubuntu/+source/tex-common/2.08ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2011-1400"]}]},{"id":"CVE-2011-1022","published":"2011-03-22T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cgre_receive_netlink_msg function in daemon/cgrulesengd.c in\ncgrulesengd in the Control Group Configuration Library (aka libcgroup or\nlibcg) before 0.37.1 does not verify that netlink messages originated in\nthe kernel, which allows local users to bypass intended resource\nrestrictions via a crafted message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1022"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615987"],"patches":{"libcgroup":["vendor: http://www.debian.org/security/2011/dsa-2193"]},"tags":{},"packages":[{"name":"libcgroup","source":"https://ubuntu.com/security/cve?package=libcgroup","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libcgroup","debian":"https://tracker.debian.org/pkg/libcgroup","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.38-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.36.2-3+squeeze1build0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"0.38-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.37.1-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.38-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1006","published":"2011-03-22T17:55:00","updated_at":"2025-08-04T19:23:59.862189+00:00","description":"\nHeap-based buffer overflow in the parse_cgroup_spec function in\ntools/tools-common.c in the Control Group Configuration Library (aka\nlibcgroup or libcg) before 0.37.1 allows local users to gain privileges via\na crafted controller list on the command line of an application. NOTE: it\nis not clear whether this issue crosses privilege boundaries.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1006"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615987"],"patches":{"libcgroup":["vendor: http://www.debian.org/security/2011/dsa-2193"]},"tags":{},"packages":[{"name":"libcgroup","source":"https://ubuntu.com/security/cve?package=libcgroup","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libcgroup","debian":"https://tracker.debian.org/pkg/libcgroup","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.38-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.36.2-3+squeeze1build0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"0.38-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.37.1-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.38-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-0188","published":"2011-03-22T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby\n1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other\nplatforms, does not properly allocate memory, which allows\ncontext-dependent attackers to execute arbitrary code or cause a denial of\nservice (application crash) via vectors involving creation of a large\nBigDecimal value within a 64-bit process, related to an \"integer truncation\nissue.\"","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Test case in comment #1 of RH tracker"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1377-1","https://www.cve.org/CVERecord?id=CVE-2011-0188"],"bugs":["http://security-tracker.debian.org/tracker/CVE-2011-0188","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-0188"],"patches":{"ruby1.8":["upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ext/bigdecimal/bigdecimal.c?r1=29364&r2=30993"],"ruby1.9":[],"ruby1.9.1":[]},"tags":{},"packages":[{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.8.7.249-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.8.7.299-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.8.7.302-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.8.7.352-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.7.352-1","component":null,"pocket":"security"}]},{"name":"ruby1.9","source":"https://ubuntu.com/security/cve?package=ruby1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9","debian":"https://tracker.debian.org/pkg/ruby1.9","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.9.1","source":"https://ubuntu.com/security/cve?package=ruby1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9.1","debian":"https://tracker.debian.org/pkg/ruby1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.2.290-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.2.290-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1377-1"],"notices":[{"id":"USN-1377-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in ruby1.8.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-28T03:33:06.846369","description":"Drew Yao discovered that the WEBrick HTTP server was vulnerable to cross-site\nscripting attacks when displaying error pages. A remote attacker could use this\nflaw to run arbitrary web script. (CVE-2010-0541)\n\nDrew Yao discovered that Ruby's BigDecimal module did not properly allocate\nmemory on 64-bit platforms. An attacker could use this flaw to cause a denial\nof service or possibly execute arbitrary code with user privileges.\n(CVE-2011-0188)\n\nNicholas Jefferson discovered that the FileUtils.remove_entry_secure method in\nRuby did not properly remove non-empty directories. An attacker could use this\nflaw to possibly delete arbitrary files. (CVE-2011-1004)\n\nIt was discovered that Ruby incorrectly allowed untainted strings to be\nmodified in protective safe levels. An attacker could use this flaw to bypass\nintended access restrictions. (CVE-2011-1005)\n\nEric Wong discovered that Ruby does not properly reseed its pseudorandom number\ngenerator when creating child processes. An attacker could use this flaw to\ngain knowledge of the random numbers used in other Ruby child processes.\n(CVE-2011-2686)\n\nEric Wong discovered that the SecureRandom module in Ruby did not properly seed\nits pseudorandom number generator. An attacker could use this flaw to gain\nknowledge of the random numbers used by another Ruby process with the same\nprocess ID number. (CVE-2011-2705)\n\nAlexander Klink and Julian Wälde discovered that Ruby computed hash values\nwithout restricting the ability to trigger hash collisions predictably. A\nremote attacker could cause a denial of service by crafting values used in hash\ntables. (CVE-2011-4815)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ruby1.8","version":"1.8.7.249-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.249-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.249-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.249-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.249-2ubuntu0.1"}],"maverick":[{"name":"ruby1.8","version":"1.8.7.299-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.299-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.299-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.299-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.299-2ubuntu0.1"}],"natty":[{"name":"ruby1.8","version":"1.8.7.302-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.302-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.302-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.302-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.302-2ubuntu0.1"}],"oneiric":[{"name":"ruby1.8","version":"1.8.7.352-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.352-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.352-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.352-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.352-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2010-0541","CVE-2011-1004","CVE-2011-4815","CVE-2011-0188","CVE-2011-2686","CVE-2011-2705","CVE-2011-1005"]}]},{"id":"CVE-2011-1465","published":"2011-03-20T02:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SPDY implementation in net/http/http_network_transaction.cc in Google\nChrome before 11.0.696.14 drains the bodies from SPDY responses, which\nmight allow remote SPDY servers to cause a denial of service (application\nexit) by canceling a stream.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2011/03/dev-channel-update_17.html","https://www.cve.org/CVERecord?id=CVE-2011-1465"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=75657"],"patches":{"chromium-browser":["upstream: http://src.chromium.org/viewvc/chrome/trunk/src/net/http/http_network_transaction.cc?r1=77893&r2=77892&pathrev=77893"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"14.0.835.202~r103287-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"14.0.835.202~r103287-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1471","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger signedness error in zip_stream.c in the Zip extension in PHP before\n5.3.6 allows context-dependent attackers to cause a denial of service (CPU\nconsumption) via a malformed archive file that triggers errors in zip_fread\nfunction calls.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"newer releases may not need earlier commits.\nphp 5.1 in dapper did not include zip extension"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1126-1","https://www.cve.org/CVERecord?id=CVE-2011-1471"],"bugs":["http://bugs.php.net/bug.php?id=49072"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=307917","upstream: http://svn.php.net/viewvc?view=revision&revision=287095","upstream: http://svn.php.net/viewvc?view=revision&revision=287102"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.22","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.15","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.9","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.3.3-1ubuntu9.4","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.3.5-1ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1126-1"],"notices":[{"id":"USN-1126-1","title":"PHP vulnerabilities","summary":"Multiple vulnerabilities in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-04-29T19:28:25.538353","description":"Stephane Chazelas discovered that the /etc/cron.d/php5 cron job for\nPHP 5.3.5 allows local users to delete arbitrary files via a symlink\nattack on a directory under /var/lib/php5/. (CVE-2011-0441)\n\nRaphael Geisert and Dan Rosenberg discovered that the PEAR installer\nallows local users to overwrite arbitrary files via a symlink attack on\nthe package.xml file, related to the (1) download_dir, (2) cache_dir,\n(3) tmp_dir, and (4) pear-build-download directories. (CVE-2011-1072,\nCVE-2011-1144)\n\nBen Schmidt discovered that a use-after-free vulnerability in the PHP\nZend engine could allow an attacker to cause a denial of service (heap\nmemory corruption) or possibly execute arbitrary code. (CVE-2010-4697)\n\nMartin Barbella discovered a buffer overflow in the PHP GD extension\nthat allows an attacker to cause a denial of service (application crash)\nvia a large number of anti- aliasing steps in an argument to the\nimagepstext function. (CVE-2010-4698)\n\nIt was discovered that PHP accepts the \\0 character in a pathname,\nwhich might allow an attacker to bypass intended access restrictions\nby placing a safe file extension after this character. This issue\nis addressed in Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.\n(CVE-2006-7243)\n\nMaksymilian Arciemowicz discovered that the grapheme_extract function\nin the PHP Internationalization extension (Intl) for ICU allow\nan attacker to cause a denial of service (crash) via an invalid\nsize argument, which triggers a NULL pointer dereference. This\nissue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-0420)\n\nMaksymilian Arciemowicz discovered that the _zip_name_locate\nfunction in the PHP Zip extension does not properly handle a\nZIPARCHIVE::FL_UNCHANGED argument, which might allow an attacker to\ncause a denial of service (NULL pointer dereference) via an empty\nZIP archive. This issue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu\n10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04. (CVE-2011-0421)\n\nLuca Carettoni discovered that the PHP Exif extension performs an\nincorrect cast on 64bit platforms, which allows a remote attacker\nto cause a denial of service (application crash) via an image with\na crafted Image File Directory (IFD). (CVE-2011-0708)\n\nJose Carlos Norte discovered that an integer overflow in the PHP\nshmop extension could allow an attacker to cause a denial of service\n(crash) and possibly read sensitive memory function. (CVE-2011-1092)\n\nFelipe Pena discovered that a use-after-free vulnerability in the\nsubstr_replace function allows an attacker to cause a denial of\nservice (memory corruption) or possibly execute arbitrary code.\n(CVE-2011-1148)\n\nFelipe Pena discovered multiple format string vulnerabilities in the\nPHP phar extension. These could allow an attacker to obtain sensitive\ninformation from process memory, cause a denial of service (memory\ncorruption), or possibly execute arbitrary code. This issue affected\nUbuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.(CVE-2011-1153)\n\nIt was discovered that a buffer overflow occurs in the strval function\nwhen the precision configuration option has a large value. The default\ncompiler options for Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS,\nUbuntu 10.10, and Ubuntu 11.04 should reduce the vulnerability to a\ndenial of service. (CVE-2011-1464)\n\nIt was discovered that an integer overflow in the SdnToJulian function\nin the PHP Calendar extension could allow an attacker to cause a\ndenial of service (application crash). (CVE-2011-1466)\n\nTomas Hoger discovered that an integer overflow in the\nNumberFormatter::setSymbol function in the PHP Intl extension\ncould allow an attacker to cause a denial of service (application\ncrash). This issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-1467)\n\nIt was discovered that multiple memory leaks in the PHP OpenSSL\nextension might allow a remote attacker to cause a denial of service\n(memory consumption). This issue affected Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1468)\n\nDaniel Buschke discovered that the PHP Streams component in PHP\nhandled types improperly, possibly allowing an attacker to cause a\ndenial of service (application crash). (CVE-2011-1469)\n\nIt was discovered that the PHP Zip extension could allow an attacker to\ncause a denial of service (application crash) via a ziparchive stream\nthat is not properly handled by the stream_get_contents function. This\nissue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1470)\n\nIt was discovered that an integer signedness error in the PHP Zip\nextension could allow an attacker to cause a denial of service (CPU\nconsumption) via a malformed archive file. This issue affected\nUbuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu 10.10, and\nUbuntu 11.04. (CVE-2011-1470) (CVE-2011-1471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.8","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php-pear","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-curl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-intl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-common","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-dev","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-gd","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"}],"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php-pear","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-curl","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-common","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-dev","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-gd","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.15","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php-pear","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-curl","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-common","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-dev","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-gd","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.22","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php-pear","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-curl","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-common","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-dev","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-gd","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"}],"maverick":[{"name":"php5","version":"5.3.3-1ubuntu9.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php-pear","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-cgi","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-curl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-intl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-common","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-dev","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-gd","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"libapache2-mod-php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"}],"natty":[{"name":"php5","version":"5.3.5-1ubuntu7.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php-pear","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-cgi","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-curl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-intl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-common","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-dev","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-gd","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"libapache2-mod-php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2011-0421","CVE-2011-0708","CVE-2011-0441","CVE-2011-1144","CVE-2011-1466","CVE-2010-4698","CVE-2011-1471","CVE-2011-1148","CVE-2011-1467","CVE-2010-4697","CVE-2011-1092","CVE-2011-1464","CVE-2011-1072","CVE-2011-0420","CVE-2011-1470","CVE-2011-1468","CVE-2011-1153","CVE-2011-1469","CVE-2006-7243"]}]},{"id":"CVE-2011-1470","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Zip extension in PHP before 5.3.6 allows context-dependent attackers to\ncause a denial of service (application crash) via a ziparchive stream that\nis not properly handled by the stream_get_contents function.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"php 5.1 i dapper does not include zip extension"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1126-1","https://www.cve.org/CVERecord?id=CVE-2011-1470"],"bugs":["http://bugs.php.net/bug.php?id=53579"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=306493"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.15","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.9","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.3.3-1ubuntu9.4","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.3.5-1ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1126-1"],"notices":[{"id":"USN-1126-1","title":"PHP vulnerabilities","summary":"Multiple vulnerabilities in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-04-29T19:28:25.538353","description":"Stephane Chazelas discovered that the /etc/cron.d/php5 cron job for\nPHP 5.3.5 allows local users to delete arbitrary files via a symlink\nattack on a directory under /var/lib/php5/. (CVE-2011-0441)\n\nRaphael Geisert and Dan Rosenberg discovered that the PEAR installer\nallows local users to overwrite arbitrary files via a symlink attack on\nthe package.xml file, related to the (1) download_dir, (2) cache_dir,\n(3) tmp_dir, and (4) pear-build-download directories. (CVE-2011-1072,\nCVE-2011-1144)\n\nBen Schmidt discovered that a use-after-free vulnerability in the PHP\nZend engine could allow an attacker to cause a denial of service (heap\nmemory corruption) or possibly execute arbitrary code. (CVE-2010-4697)\n\nMartin Barbella discovered a buffer overflow in the PHP GD extension\nthat allows an attacker to cause a denial of service (application crash)\nvia a large number of anti- aliasing steps in an argument to the\nimagepstext function. (CVE-2010-4698)\n\nIt was discovered that PHP accepts the \\0 character in a pathname,\nwhich might allow an attacker to bypass intended access restrictions\nby placing a safe file extension after this character. This issue\nis addressed in Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.\n(CVE-2006-7243)\n\nMaksymilian Arciemowicz discovered that the grapheme_extract function\nin the PHP Internationalization extension (Intl) for ICU allow\nan attacker to cause a denial of service (crash) via an invalid\nsize argument, which triggers a NULL pointer dereference. This\nissue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-0420)\n\nMaksymilian Arciemowicz discovered that the _zip_name_locate\nfunction in the PHP Zip extension does not properly handle a\nZIPARCHIVE::FL_UNCHANGED argument, which might allow an attacker to\ncause a denial of service (NULL pointer dereference) via an empty\nZIP archive. This issue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu\n10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04. (CVE-2011-0421)\n\nLuca Carettoni discovered that the PHP Exif extension performs an\nincorrect cast on 64bit platforms, which allows a remote attacker\nto cause a denial of service (application crash) via an image with\na crafted Image File Directory (IFD). (CVE-2011-0708)\n\nJose Carlos Norte discovered that an integer overflow in the PHP\nshmop extension could allow an attacker to cause a denial of service\n(crash) and possibly read sensitive memory function. (CVE-2011-1092)\n\nFelipe Pena discovered that a use-after-free vulnerability in the\nsubstr_replace function allows an attacker to cause a denial of\nservice (memory corruption) or possibly execute arbitrary code.\n(CVE-2011-1148)\n\nFelipe Pena discovered multiple format string vulnerabilities in the\nPHP phar extension. These could allow an attacker to obtain sensitive\ninformation from process memory, cause a denial of service (memory\ncorruption), or possibly execute arbitrary code. This issue affected\nUbuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.(CVE-2011-1153)\n\nIt was discovered that a buffer overflow occurs in the strval function\nwhen the precision configuration option has a large value. The default\ncompiler options for Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS,\nUbuntu 10.10, and Ubuntu 11.04 should reduce the vulnerability to a\ndenial of service. (CVE-2011-1464)\n\nIt was discovered that an integer overflow in the SdnToJulian function\nin the PHP Calendar extension could allow an attacker to cause a\ndenial of service (application crash). (CVE-2011-1466)\n\nTomas Hoger discovered that an integer overflow in the\nNumberFormatter::setSymbol function in the PHP Intl extension\ncould allow an attacker to cause a denial of service (application\ncrash). This issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-1467)\n\nIt was discovered that multiple memory leaks in the PHP OpenSSL\nextension might allow a remote attacker to cause a denial of service\n(memory consumption). This issue affected Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1468)\n\nDaniel Buschke discovered that the PHP Streams component in PHP\nhandled types improperly, possibly allowing an attacker to cause a\ndenial of service (application crash). (CVE-2011-1469)\n\nIt was discovered that the PHP Zip extension could allow an attacker to\ncause a denial of service (application crash) via a ziparchive stream\nthat is not properly handled by the stream_get_contents function. This\nissue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1470)\n\nIt was discovered that an integer signedness error in the PHP Zip\nextension could allow an attacker to cause a denial of service (CPU\nconsumption) via a malformed archive file. This issue affected\nUbuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu 10.10, and\nUbuntu 11.04. (CVE-2011-1470) (CVE-2011-1471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.8","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php-pear","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-curl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-intl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-common","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-dev","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-gd","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"}],"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php-pear","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-curl","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-common","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-dev","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-gd","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.15","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php-pear","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-curl","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-common","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-dev","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-gd","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.22","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php-pear","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-curl","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-common","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-dev","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-gd","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"}],"maverick":[{"name":"php5","version":"5.3.3-1ubuntu9.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php-pear","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-cgi","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-curl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-intl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-common","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-dev","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-gd","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"libapache2-mod-php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"}],"natty":[{"name":"php5","version":"5.3.5-1ubuntu7.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php-pear","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-cgi","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-curl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-intl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-common","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-dev","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-gd","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"libapache2-mod-php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2011-0421","CVE-2011-0708","CVE-2011-0441","CVE-2011-1144","CVE-2011-1466","CVE-2010-4698","CVE-2011-1471","CVE-2011-1148","CVE-2011-1467","CVE-2010-4697","CVE-2011-1092","CVE-2011-1464","CVE-2011-1072","CVE-2011-0420","CVE-2011-1470","CVE-2011-1468","CVE-2011-1153","CVE-2011-1469","CVE-2006-7243"]}]},{"id":"CVE-2011-1469","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Streams component in PHP before 5.3.6\nallows context-dependent attackers to cause a denial of service\n(application crash) by accessing an ftp:// URL during use of an HTTP proxy\nwith the FTP wrapper.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1126-1","https://www.cve.org/CVERecord?id=CVE-2011-1469"],"bugs":["http://bugs.php.net/bug.php?id=54092"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=308734"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.22","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.15","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.9","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.3.3-1ubuntu9.4","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.3.5-1ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1126-1"],"notices":[{"id":"USN-1126-1","title":"PHP vulnerabilities","summary":"Multiple vulnerabilities in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-04-29T19:28:25.538353","description":"Stephane Chazelas discovered that the /etc/cron.d/php5 cron job for\nPHP 5.3.5 allows local users to delete arbitrary files via a symlink\nattack on a directory under /var/lib/php5/. (CVE-2011-0441)\n\nRaphael Geisert and Dan Rosenberg discovered that the PEAR installer\nallows local users to overwrite arbitrary files via a symlink attack on\nthe package.xml file, related to the (1) download_dir, (2) cache_dir,\n(3) tmp_dir, and (4) pear-build-download directories. (CVE-2011-1072,\nCVE-2011-1144)\n\nBen Schmidt discovered that a use-after-free vulnerability in the PHP\nZend engine could allow an attacker to cause a denial of service (heap\nmemory corruption) or possibly execute arbitrary code. (CVE-2010-4697)\n\nMartin Barbella discovered a buffer overflow in the PHP GD extension\nthat allows an attacker to cause a denial of service (application crash)\nvia a large number of anti- aliasing steps in an argument to the\nimagepstext function. (CVE-2010-4698)\n\nIt was discovered that PHP accepts the \\0 character in a pathname,\nwhich might allow an attacker to bypass intended access restrictions\nby placing a safe file extension after this character. This issue\nis addressed in Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.\n(CVE-2006-7243)\n\nMaksymilian Arciemowicz discovered that the grapheme_extract function\nin the PHP Internationalization extension (Intl) for ICU allow\nan attacker to cause a denial of service (crash) via an invalid\nsize argument, which triggers a NULL pointer dereference. This\nissue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-0420)\n\nMaksymilian Arciemowicz discovered that the _zip_name_locate\nfunction in the PHP Zip extension does not properly handle a\nZIPARCHIVE::FL_UNCHANGED argument, which might allow an attacker to\ncause a denial of service (NULL pointer dereference) via an empty\nZIP archive. This issue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu\n10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04. (CVE-2011-0421)\n\nLuca Carettoni discovered that the PHP Exif extension performs an\nincorrect cast on 64bit platforms, which allows a remote attacker\nto cause a denial of service (application crash) via an image with\na crafted Image File Directory (IFD). (CVE-2011-0708)\n\nJose Carlos Norte discovered that an integer overflow in the PHP\nshmop extension could allow an attacker to cause a denial of service\n(crash) and possibly read sensitive memory function. (CVE-2011-1092)\n\nFelipe Pena discovered that a use-after-free vulnerability in the\nsubstr_replace function allows an attacker to cause a denial of\nservice (memory corruption) or possibly execute arbitrary code.\n(CVE-2011-1148)\n\nFelipe Pena discovered multiple format string vulnerabilities in the\nPHP phar extension. These could allow an attacker to obtain sensitive\ninformation from process memory, cause a denial of service (memory\ncorruption), or possibly execute arbitrary code. This issue affected\nUbuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.(CVE-2011-1153)\n\nIt was discovered that a buffer overflow occurs in the strval function\nwhen the precision configuration option has a large value. The default\ncompiler options for Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS,\nUbuntu 10.10, and Ubuntu 11.04 should reduce the vulnerability to a\ndenial of service. (CVE-2011-1464)\n\nIt was discovered that an integer overflow in the SdnToJulian function\nin the PHP Calendar extension could allow an attacker to cause a\ndenial of service (application crash). (CVE-2011-1466)\n\nTomas Hoger discovered that an integer overflow in the\nNumberFormatter::setSymbol function in the PHP Intl extension\ncould allow an attacker to cause a denial of service (application\ncrash). This issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-1467)\n\nIt was discovered that multiple memory leaks in the PHP OpenSSL\nextension might allow a remote attacker to cause a denial of service\n(memory consumption). This issue affected Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1468)\n\nDaniel Buschke discovered that the PHP Streams component in PHP\nhandled types improperly, possibly allowing an attacker to cause a\ndenial of service (application crash). (CVE-2011-1469)\n\nIt was discovered that the PHP Zip extension could allow an attacker to\ncause a denial of service (application crash) via a ziparchive stream\nthat is not properly handled by the stream_get_contents function. This\nissue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1470)\n\nIt was discovered that an integer signedness error in the PHP Zip\nextension could allow an attacker to cause a denial of service (CPU\nconsumption) via a malformed archive file. This issue affected\nUbuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu 10.10, and\nUbuntu 11.04. (CVE-2011-1470) (CVE-2011-1471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.8","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php-pear","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-curl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-intl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-common","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-dev","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-gd","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"}],"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php-pear","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-curl","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-common","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-dev","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-gd","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.15","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php-pear","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-curl","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-common","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-dev","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-gd","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.22","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php-pear","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-curl","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-common","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-dev","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-gd","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"}],"maverick":[{"name":"php5","version":"5.3.3-1ubuntu9.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php-pear","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-cgi","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-curl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-intl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-common","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-dev","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-gd","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"libapache2-mod-php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"}],"natty":[{"name":"php5","version":"5.3.5-1ubuntu7.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php-pear","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-cgi","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-curl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-intl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-common","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-dev","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-gd","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"libapache2-mod-php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2011-0421","CVE-2011-0708","CVE-2011-0441","CVE-2011-1144","CVE-2011-1466","CVE-2010-4698","CVE-2011-1471","CVE-2011-1148","CVE-2011-1467","CVE-2010-4697","CVE-2011-1092","CVE-2011-1464","CVE-2011-1072","CVE-2011-0420","CVE-2011-1470","CVE-2011-1468","CVE-2011-1153","CVE-2011-1469","CVE-2006-7243"]}]},{"id":"CVE-2011-1468","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might\nallow remote attackers to cause a denial of service (memory consumption)\nvia (1) plaintext data to the openssl_encrypt function or (2) ciphertext\ndata to the openssl_decrypt function.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"openssl_{en,de}crypt are not available in php 5.2.x. There\nare possibly other memory leaks in php 5.2.x openssl code."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1126-1","https://www.cve.org/CVERecord?id=CVE-2011-1468"],"bugs":["http://bugs.php.net/bug.php?id=54060","http://bugs.php.net/bug.php?id=54061"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=308531","upstream: http://svn.php.net/viewvc?view=revision&revision=308532","upstream: http://svn.php.net/viewvc?view=revision&revision=308533","upstream: http://svn.php.net/viewvc?view=revision&revision=308534"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.3.3-1ubuntu9.4","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.3.5-1ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1126-1"],"notices":[{"id":"USN-1126-1","title":"PHP vulnerabilities","summary":"Multiple vulnerabilities in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-04-29T19:28:25.538353","description":"Stephane Chazelas discovered that the /etc/cron.d/php5 cron job for\nPHP 5.3.5 allows local users to delete arbitrary files via a symlink\nattack on a directory under /var/lib/php5/. (CVE-2011-0441)\n\nRaphael Geisert and Dan Rosenberg discovered that the PEAR installer\nallows local users to overwrite arbitrary files via a symlink attack on\nthe package.xml file, related to the (1) download_dir, (2) cache_dir,\n(3) tmp_dir, and (4) pear-build-download directories. (CVE-2011-1072,\nCVE-2011-1144)\n\nBen Schmidt discovered that a use-after-free vulnerability in the PHP\nZend engine could allow an attacker to cause a denial of service (heap\nmemory corruption) or possibly execute arbitrary code. (CVE-2010-4697)\n\nMartin Barbella discovered a buffer overflow in the PHP GD extension\nthat allows an attacker to cause a denial of service (application crash)\nvia a large number of anti- aliasing steps in an argument to the\nimagepstext function. (CVE-2010-4698)\n\nIt was discovered that PHP accepts the \\0 character in a pathname,\nwhich might allow an attacker to bypass intended access restrictions\nby placing a safe file extension after this character. This issue\nis addressed in Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.\n(CVE-2006-7243)\n\nMaksymilian Arciemowicz discovered that the grapheme_extract function\nin the PHP Internationalization extension (Intl) for ICU allow\nan attacker to cause a denial of service (crash) via an invalid\nsize argument, which triggers a NULL pointer dereference. This\nissue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-0420)\n\nMaksymilian Arciemowicz discovered that the _zip_name_locate\nfunction in the PHP Zip extension does not properly handle a\nZIPARCHIVE::FL_UNCHANGED argument, which might allow an attacker to\ncause a denial of service (NULL pointer dereference) via an empty\nZIP archive. This issue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu\n10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04. (CVE-2011-0421)\n\nLuca Carettoni discovered that the PHP Exif extension performs an\nincorrect cast on 64bit platforms, which allows a remote attacker\nto cause a denial of service (application crash) via an image with\na crafted Image File Directory (IFD). (CVE-2011-0708)\n\nJose Carlos Norte discovered that an integer overflow in the PHP\nshmop extension could allow an attacker to cause a denial of service\n(crash) and possibly read sensitive memory function. (CVE-2011-1092)\n\nFelipe Pena discovered that a use-after-free vulnerability in the\nsubstr_replace function allows an attacker to cause a denial of\nservice (memory corruption) or possibly execute arbitrary code.\n(CVE-2011-1148)\n\nFelipe Pena discovered multiple format string vulnerabilities in the\nPHP phar extension. These could allow an attacker to obtain sensitive\ninformation from process memory, cause a denial of service (memory\ncorruption), or possibly execute arbitrary code. This issue affected\nUbuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.(CVE-2011-1153)\n\nIt was discovered that a buffer overflow occurs in the strval function\nwhen the precision configuration option has a large value. The default\ncompiler options for Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS,\nUbuntu 10.10, and Ubuntu 11.04 should reduce the vulnerability to a\ndenial of service. (CVE-2011-1464)\n\nIt was discovered that an integer overflow in the SdnToJulian function\nin the PHP Calendar extension could allow an attacker to cause a\ndenial of service (application crash). (CVE-2011-1466)\n\nTomas Hoger discovered that an integer overflow in the\nNumberFormatter::setSymbol function in the PHP Intl extension\ncould allow an attacker to cause a denial of service (application\ncrash). This issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-1467)\n\nIt was discovered that multiple memory leaks in the PHP OpenSSL\nextension might allow a remote attacker to cause a denial of service\n(memory consumption). This issue affected Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1468)\n\nDaniel Buschke discovered that the PHP Streams component in PHP\nhandled types improperly, possibly allowing an attacker to cause a\ndenial of service (application crash). (CVE-2011-1469)\n\nIt was discovered that the PHP Zip extension could allow an attacker to\ncause a denial of service (application crash) via a ziparchive stream\nthat is not properly handled by the stream_get_contents function. This\nissue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1470)\n\nIt was discovered that an integer signedness error in the PHP Zip\nextension could allow an attacker to cause a denial of service (CPU\nconsumption) via a malformed archive file. This issue affected\nUbuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu 10.10, and\nUbuntu 11.04. (CVE-2011-1470) (CVE-2011-1471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.8","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php-pear","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-curl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-intl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-common","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-dev","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-gd","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"}],"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php-pear","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-curl","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-common","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-dev","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-gd","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.15","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php-pear","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-curl","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-common","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-dev","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-gd","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.22","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php-pear","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-curl","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-common","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-dev","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-gd","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"}],"maverick":[{"name":"php5","version":"5.3.3-1ubuntu9.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php-pear","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-cgi","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-curl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-intl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-common","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-dev","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-gd","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"libapache2-mod-php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"}],"natty":[{"name":"php5","version":"5.3.5-1ubuntu7.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php-pear","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-cgi","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-curl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-intl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-common","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-dev","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-gd","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"libapache2-mod-php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2011-0421","CVE-2011-0708","CVE-2011-0441","CVE-2011-1144","CVE-2011-1466","CVE-2010-4698","CVE-2011-1471","CVE-2011-1148","CVE-2011-1467","CVE-2010-4697","CVE-2011-1092","CVE-2011-1464","CVE-2011-1072","CVE-2011-0420","CVE-2011-1470","CVE-2011-1468","CVE-2011-1153","CVE-2011-1469","CVE-2006-7243"]}]},{"id":"CVE-2011-1467","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the NumberFormatter::setSymbol (aka\nnumfmt_set_symbol) function in the Intl extension in PHP before 5.3.6\nallows context-dependent attackers to cause a denial of service\n(application crash) via an invalid argument, a related issue to\nCVE-2010-4409.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"ext/intl had not been merged into core php yet in 5.2.x branch"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1126-1","https://www.cve.org/CVERecord?id=CVE-2011-1467"],"bugs":["http://bugs.php.net/bug.php?id=53512"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=306154","upstream: http://svn.php.net/viewvc?view=revision&revision=306157"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.3.3-1ubuntu9.4","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.3.5-1ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1126-1"],"notices":[{"id":"USN-1126-1","title":"PHP vulnerabilities","summary":"Multiple vulnerabilities in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-04-29T19:28:25.538353","description":"Stephane Chazelas discovered that the /etc/cron.d/php5 cron job for\nPHP 5.3.5 allows local users to delete arbitrary files via a symlink\nattack on a directory under /var/lib/php5/. (CVE-2011-0441)\n\nRaphael Geisert and Dan Rosenberg discovered that the PEAR installer\nallows local users to overwrite arbitrary files via a symlink attack on\nthe package.xml file, related to the (1) download_dir, (2) cache_dir,\n(3) tmp_dir, and (4) pear-build-download directories. (CVE-2011-1072,\nCVE-2011-1144)\n\nBen Schmidt discovered that a use-after-free vulnerability in the PHP\nZend engine could allow an attacker to cause a denial of service (heap\nmemory corruption) or possibly execute arbitrary code. (CVE-2010-4697)\n\nMartin Barbella discovered a buffer overflow in the PHP GD extension\nthat allows an attacker to cause a denial of service (application crash)\nvia a large number of anti- aliasing steps in an argument to the\nimagepstext function. (CVE-2010-4698)\n\nIt was discovered that PHP accepts the \\0 character in a pathname,\nwhich might allow an attacker to bypass intended access restrictions\nby placing a safe file extension after this character. This issue\nis addressed in Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.\n(CVE-2006-7243)\n\nMaksymilian Arciemowicz discovered that the grapheme_extract function\nin the PHP Internationalization extension (Intl) for ICU allow\nan attacker to cause a denial of service (crash) via an invalid\nsize argument, which triggers a NULL pointer dereference. This\nissue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-0420)\n\nMaksymilian Arciemowicz discovered that the _zip_name_locate\nfunction in the PHP Zip extension does not properly handle a\nZIPARCHIVE::FL_UNCHANGED argument, which might allow an attacker to\ncause a denial of service (NULL pointer dereference) via an empty\nZIP archive. This issue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu\n10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04. (CVE-2011-0421)\n\nLuca Carettoni discovered that the PHP Exif extension performs an\nincorrect cast on 64bit platforms, which allows a remote attacker\nto cause a denial of service (application crash) via an image with\na crafted Image File Directory (IFD). (CVE-2011-0708)\n\nJose Carlos Norte discovered that an integer overflow in the PHP\nshmop extension could allow an attacker to cause a denial of service\n(crash) and possibly read sensitive memory function. (CVE-2011-1092)\n\nFelipe Pena discovered that a use-after-free vulnerability in the\nsubstr_replace function allows an attacker to cause a denial of\nservice (memory corruption) or possibly execute arbitrary code.\n(CVE-2011-1148)\n\nFelipe Pena discovered multiple format string vulnerabilities in the\nPHP phar extension. These could allow an attacker to obtain sensitive\ninformation from process memory, cause a denial of service (memory\ncorruption), or possibly execute arbitrary code. This issue affected\nUbuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.(CVE-2011-1153)\n\nIt was discovered that a buffer overflow occurs in the strval function\nwhen the precision configuration option has a large value. The default\ncompiler options for Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS,\nUbuntu 10.10, and Ubuntu 11.04 should reduce the vulnerability to a\ndenial of service. (CVE-2011-1464)\n\nIt was discovered that an integer overflow in the SdnToJulian function\nin the PHP Calendar extension could allow an attacker to cause a\ndenial of service (application crash). (CVE-2011-1466)\n\nTomas Hoger discovered that an integer overflow in the\nNumberFormatter::setSymbol function in the PHP Intl extension\ncould allow an attacker to cause a denial of service (application\ncrash). This issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-1467)\n\nIt was discovered that multiple memory leaks in the PHP OpenSSL\nextension might allow a remote attacker to cause a denial of service\n(memory consumption). This issue affected Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1468)\n\nDaniel Buschke discovered that the PHP Streams component in PHP\nhandled types improperly, possibly allowing an attacker to cause a\ndenial of service (application crash). (CVE-2011-1469)\n\nIt was discovered that the PHP Zip extension could allow an attacker to\ncause a denial of service (application crash) via a ziparchive stream\nthat is not properly handled by the stream_get_contents function. This\nissue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1470)\n\nIt was discovered that an integer signedness error in the PHP Zip\nextension could allow an attacker to cause a denial of service (CPU\nconsumption) via a malformed archive file. This issue affected\nUbuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu 10.10, and\nUbuntu 11.04. (CVE-2011-1470) (CVE-2011-1471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.8","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php-pear","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-curl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-intl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-common","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-dev","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-gd","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"}],"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php-pear","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-curl","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-common","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-dev","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-gd","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.15","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php-pear","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-curl","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-common","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-dev","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-gd","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.22","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php-pear","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-curl","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-common","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-dev","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-gd","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"}],"maverick":[{"name":"php5","version":"5.3.3-1ubuntu9.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php-pear","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-cgi","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-curl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-intl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-common","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-dev","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-gd","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"libapache2-mod-php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"}],"natty":[{"name":"php5","version":"5.3.5-1ubuntu7.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php-pear","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-cgi","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-curl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-intl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-common","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-dev","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-gd","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"libapache2-mod-php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2011-0421","CVE-2011-0708","CVE-2011-0441","CVE-2011-1144","CVE-2011-1466","CVE-2010-4698","CVE-2011-1471","CVE-2011-1148","CVE-2011-1467","CVE-2010-4697","CVE-2011-1092","CVE-2011-1464","CVE-2011-1072","CVE-2011-0420","CVE-2011-1470","CVE-2011-1468","CVE-2011-1153","CVE-2011-1469","CVE-2006-7243"]}]},{"id":"CVE-2011-1466","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the SdnToJulian function in the Calendar extension in\nPHP before 5.3.6 allows context-dependent attackers to cause a denial of\nservice (application crash) via a large integer in the first argument to\nthe cal_from_jd function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1126-1","https://www.cve.org/CVERecord?id=CVE-2011-1466"],"bugs":["http://bugs.php.net/bug.php?id=53574"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=306475"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"maverick","status":"released","description":"5.3.3-1ubuntu9.4","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.22","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.15","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.9","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"5.3.3-7ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1126-1"],"notices":[{"id":"USN-1126-1","title":"PHP vulnerabilities","summary":"Multiple vulnerabilities in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-04-29T19:28:25.538353","description":"Stephane Chazelas discovered that the /etc/cron.d/php5 cron job for\nPHP 5.3.5 allows local users to delete arbitrary files via a symlink\nattack on a directory under /var/lib/php5/. (CVE-2011-0441)\n\nRaphael Geisert and Dan Rosenberg discovered that the PEAR installer\nallows local users to overwrite arbitrary files via a symlink attack on\nthe package.xml file, related to the (1) download_dir, (2) cache_dir,\n(3) tmp_dir, and (4) pear-build-download directories. (CVE-2011-1072,\nCVE-2011-1144)\n\nBen Schmidt discovered that a use-after-free vulnerability in the PHP\nZend engine could allow an attacker to cause a denial of service (heap\nmemory corruption) or possibly execute arbitrary code. (CVE-2010-4697)\n\nMartin Barbella discovered a buffer overflow in the PHP GD extension\nthat allows an attacker to cause a denial of service (application crash)\nvia a large number of anti- aliasing steps in an argument to the\nimagepstext function. (CVE-2010-4698)\n\nIt was discovered that PHP accepts the \\0 character in a pathname,\nwhich might allow an attacker to bypass intended access restrictions\nby placing a safe file extension after this character. This issue\nis addressed in Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.\n(CVE-2006-7243)\n\nMaksymilian Arciemowicz discovered that the grapheme_extract function\nin the PHP Internationalization extension (Intl) for ICU allow\nan attacker to cause a denial of service (crash) via an invalid\nsize argument, which triggers a NULL pointer dereference. This\nissue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-0420)\n\nMaksymilian Arciemowicz discovered that the _zip_name_locate\nfunction in the PHP Zip extension does not properly handle a\nZIPARCHIVE::FL_UNCHANGED argument, which might allow an attacker to\ncause a denial of service (NULL pointer dereference) via an empty\nZIP archive. This issue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu\n10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04. (CVE-2011-0421)\n\nLuca Carettoni discovered that the PHP Exif extension performs an\nincorrect cast on 64bit platforms, which allows a remote attacker\nto cause a denial of service (application crash) via an image with\na crafted Image File Directory (IFD). (CVE-2011-0708)\n\nJose Carlos Norte discovered that an integer overflow in the PHP\nshmop extension could allow an attacker to cause a denial of service\n(crash) and possibly read sensitive memory function. (CVE-2011-1092)\n\nFelipe Pena discovered that a use-after-free vulnerability in the\nsubstr_replace function allows an attacker to cause a denial of\nservice (memory corruption) or possibly execute arbitrary code.\n(CVE-2011-1148)\n\nFelipe Pena discovered multiple format string vulnerabilities in the\nPHP phar extension. These could allow an attacker to obtain sensitive\ninformation from process memory, cause a denial of service (memory\ncorruption), or possibly execute arbitrary code. This issue affected\nUbuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.(CVE-2011-1153)\n\nIt was discovered that a buffer overflow occurs in the strval function\nwhen the precision configuration option has a large value. The default\ncompiler options for Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS,\nUbuntu 10.10, and Ubuntu 11.04 should reduce the vulnerability to a\ndenial of service. (CVE-2011-1464)\n\nIt was discovered that an integer overflow in the SdnToJulian function\nin the PHP Calendar extension could allow an attacker to cause a\ndenial of service (application crash). (CVE-2011-1466)\n\nTomas Hoger discovered that an integer overflow in the\nNumberFormatter::setSymbol function in the PHP Intl extension\ncould allow an attacker to cause a denial of service (application\ncrash). This issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-1467)\n\nIt was discovered that multiple memory leaks in the PHP OpenSSL\nextension might allow a remote attacker to cause a denial of service\n(memory consumption). This issue affected Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1468)\n\nDaniel Buschke discovered that the PHP Streams component in PHP\nhandled types improperly, possibly allowing an attacker to cause a\ndenial of service (application crash). (CVE-2011-1469)\n\nIt was discovered that the PHP Zip extension could allow an attacker to\ncause a denial of service (application crash) via a ziparchive stream\nthat is not properly handled by the stream_get_contents function. This\nissue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1470)\n\nIt was discovered that an integer signedness error in the PHP Zip\nextension could allow an attacker to cause a denial of service (CPU\nconsumption) via a malformed archive file. This issue affected\nUbuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu 10.10, and\nUbuntu 11.04. (CVE-2011-1470) (CVE-2011-1471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.8","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php-pear","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-curl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-intl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-common","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-dev","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-gd","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"}],"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php-pear","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-curl","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-common","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-dev","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-gd","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.15","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php-pear","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-curl","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-common","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-dev","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-gd","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.22","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php-pear","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-curl","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-common","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-dev","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-gd","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"}],"maverick":[{"name":"php5","version":"5.3.3-1ubuntu9.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php-pear","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-cgi","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-curl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-intl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-common","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-dev","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-gd","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"libapache2-mod-php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"}],"natty":[{"name":"php5","version":"5.3.5-1ubuntu7.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php-pear","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-cgi","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-curl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-intl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-common","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-dev","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-gd","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"libapache2-mod-php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2011-0421","CVE-2011-0708","CVE-2011-0441","CVE-2011-1144","CVE-2011-1466","CVE-2010-4698","CVE-2011-1471","CVE-2011-1148","CVE-2011-1467","CVE-2010-4697","CVE-2011-1092","CVE-2011-1464","CVE-2011-1072","CVE-2011-0420","CVE-2011-1470","CVE-2011-1468","CVE-2011-1153","CVE-2011-1469","CVE-2006-7243"]}]},{"id":"CVE-2011-1464","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the strval function in PHP before 5.3.6, when the\nprecision configuration option has a large value, might allow\ncontext-dependent attackers to cause a denial of service (application\ncrash) via a small numerical value in the argument.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1126-1","https://www.cve.org/CVERecord?id=CVE-2011-1464"],"bugs":["http://bugs.php.net/bug.php?id=54055"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=308525"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.22","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.15","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.9","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.3.3-1ubuntu9.4","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"5.3.5-1ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1126-1"],"notices":[{"id":"USN-1126-1","title":"PHP vulnerabilities","summary":"Multiple vulnerabilities in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-04-29T19:28:25.538353","description":"Stephane Chazelas discovered that the /etc/cron.d/php5 cron job for\nPHP 5.3.5 allows local users to delete arbitrary files via a symlink\nattack on a directory under /var/lib/php5/. (CVE-2011-0441)\n\nRaphael Geisert and Dan Rosenberg discovered that the PEAR installer\nallows local users to overwrite arbitrary files via a symlink attack on\nthe package.xml file, related to the (1) download_dir, (2) cache_dir,\n(3) tmp_dir, and (4) pear-build-download directories. (CVE-2011-1072,\nCVE-2011-1144)\n\nBen Schmidt discovered that a use-after-free vulnerability in the PHP\nZend engine could allow an attacker to cause a denial of service (heap\nmemory corruption) or possibly execute arbitrary code. (CVE-2010-4697)\n\nMartin Barbella discovered a buffer overflow in the PHP GD extension\nthat allows an attacker to cause a denial of service (application crash)\nvia a large number of anti- aliasing steps in an argument to the\nimagepstext function. (CVE-2010-4698)\n\nIt was discovered that PHP accepts the \\0 character in a pathname,\nwhich might allow an attacker to bypass intended access restrictions\nby placing a safe file extension after this character. This issue\nis addressed in Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.\n(CVE-2006-7243)\n\nMaksymilian Arciemowicz discovered that the grapheme_extract function\nin the PHP Internationalization extension (Intl) for ICU allow\nan attacker to cause a denial of service (crash) via an invalid\nsize argument, which triggers a NULL pointer dereference. This\nissue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-0420)\n\nMaksymilian Arciemowicz discovered that the _zip_name_locate\nfunction in the PHP Zip extension does not properly handle a\nZIPARCHIVE::FL_UNCHANGED argument, which might allow an attacker to\ncause a denial of service (NULL pointer dereference) via an empty\nZIP archive. This issue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu\n10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04. (CVE-2011-0421)\n\nLuca Carettoni discovered that the PHP Exif extension performs an\nincorrect cast on 64bit platforms, which allows a remote attacker\nto cause a denial of service (application crash) via an image with\na crafted Image File Directory (IFD). (CVE-2011-0708)\n\nJose Carlos Norte discovered that an integer overflow in the PHP\nshmop extension could allow an attacker to cause a denial of service\n(crash) and possibly read sensitive memory function. (CVE-2011-1092)\n\nFelipe Pena discovered that a use-after-free vulnerability in the\nsubstr_replace function allows an attacker to cause a denial of\nservice (memory corruption) or possibly execute arbitrary code.\n(CVE-2011-1148)\n\nFelipe Pena discovered multiple format string vulnerabilities in the\nPHP phar extension. These could allow an attacker to obtain sensitive\ninformation from process memory, cause a denial of service (memory\ncorruption), or possibly execute arbitrary code. This issue affected\nUbuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu 11.04.(CVE-2011-1153)\n\nIt was discovered that a buffer overflow occurs in the strval function\nwhen the precision configuration option has a large value. The default\ncompiler options for Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS,\nUbuntu 10.10, and Ubuntu 11.04 should reduce the vulnerability to a\ndenial of service. (CVE-2011-1464)\n\nIt was discovered that an integer overflow in the SdnToJulian function\nin the PHP Calendar extension could allow an attacker to cause a\ndenial of service (application crash). (CVE-2011-1466)\n\nTomas Hoger discovered that an integer overflow in the\nNumberFormatter::setSymbol function in the PHP Intl extension\ncould allow an attacker to cause a denial of service (application\ncrash). This issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, and Ubuntu\n11.04. (CVE-2011-1467)\n\nIt was discovered that multiple memory leaks in the PHP OpenSSL\nextension might allow a remote attacker to cause a denial of service\n(memory consumption). This issue affected Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1468)\n\nDaniel Buschke discovered that the PHP Streams component in PHP\nhandled types improperly, possibly allowing an attacker to cause a\ndenial of service (application crash). (CVE-2011-1469)\n\nIt was discovered that the PHP Zip extension could allow an attacker to\ncause a denial of service (application crash) via a ziparchive stream\nthat is not properly handled by the stream_get_contents function. This\nissue affected Ubuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu\n10.10, and Ubuntu 11.04. (CVE-2011-1470)\n\nIt was discovered that an integer signedness error in the PHP Zip\nextension could allow an attacker to cause a denial of service (CPU\nconsumption) via a malformed archive file. This issue affected\nUbuntu 8.04 LTS, Ubuntu 9.10, Ubuntu 10.04 LTS, Ubuntu 10.10, and\nUbuntu 11.04. (CVE-2011-1470) (CVE-2011-1471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.8","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php-pear","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-curl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-intl","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-common","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-dev","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5-gd","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.8"}],"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php-pear","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-curl","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-common","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-dev","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5-gd","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.9"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.15","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php-pear","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-curl","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-common","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-dev","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5-gd","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.15"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.22","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php-pear","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-curl","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-common","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-dev","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5-gd","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.22"}],"maverick":[{"name":"php5","version":"5.3.3-1ubuntu9.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php-pear","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-cgi","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-curl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-intl","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-common","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-dev","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5-gd","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"},{"name":"libapache2-mod-php5","version":"5.3.3-1ubuntu9.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.4"}],"natty":[{"name":"php5","version":"5.3.5-1ubuntu7.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php-pear","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-cgi","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-curl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-intl","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-common","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-dev","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5-gd","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"},{"name":"libapache2-mod-php5","version":"5.3.5-1ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2011-0421","CVE-2011-0708","CVE-2011-0441","CVE-2011-1144","CVE-2011-1466","CVE-2010-4698","CVE-2011-1471","CVE-2011-1148","CVE-2011-1467","CVE-2010-4697","CVE-2011-1092","CVE-2011-1464","CVE-2011-1072","CVE-2011-0420","CVE-2011-1470","CVE-2011-1468","CVE-2011-1153","CVE-2011-1469","CVE-2006-7243"]}]},{"id":"CVE-2011-1081","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmodrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers\nto cause a denial of service (daemon crash) via a relative Distinguished\nName (DN) modification request (aka MODRDN operation) that contains an\nempty value for the OldDN field.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"reproducer in oss-security\nOnly affects >= 2.4"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugzilla.novell.com/show_bug.cgi?id=674985#c1","http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6768","https://ubuntu.com/security/notices/USN-1100-1","https://www.cve.org/CVERecord?id=CVE-2011-1081"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openldap/+bug/742104","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=617606"],"patches":{"openldap":["upstream: http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/modrdn.c.diff?r1=1.170.2.8&r2=1.170.2.9&hideattic=1&sortbydate=0","vendor: https://rhn.redhat.com/errata/RHSA-2011-0347.html"],"openldap2.3":[],"openldap2.2":[]},"tags":{},"packages":[{"name":"openldap","source":"https://ubuntu.com/security/cve?package=openldap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap","debian":"https://tracker.debian.org/pkg/openldap","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.4.18-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.4.21-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.4.23-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openldap2.2","source":"https://ubuntu.com/security/cve?package=openldap2.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap2.2","debian":"https://tracker.debian.org/pkg/openldap2.2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openldap2.3","source":"https://ubuntu.com/security/cve?package=openldap2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap2.3","debian":"https://tracker.debian.org/pkg/openldap2.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.4.9-0ubuntu0.8.04.5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1100-1"],"notices":[{"id":"USN-1100-1","title":"OpenLDAP vulnerabilities","summary":"An attacker could send crafted input to OpenLDAP and cause it to crash.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-03-31T14:06:15.828714","description":"It was discovered that OpenLDAP did not properly check forwarded\nauthentication failures when using a consumer server and chain overlay. If\nOpenLDAP were configured in this manner, an attacker could bypass\nauthentication checks by sending an invalid password to a consumer server.\n(CVE-2011-1024)\n\nIt was discovered that OpenLDAP did not properly perform authentication\nchecks to the rootdn when using the back-ndb backend. An attacker could\nexploit this to access the directory by sending an arbitrary password.\nUbuntu does not ship OpenLDAP with back-ndb support by default. This issue\ndid not affect Ubuntu 8.04 LTS. (CVE-2011-1025)\n\nIt was discovered that OpenLDAP did not properly validate modrdn requests.\nAn unauthenticated remote user could use this to cause a denial of service\nvia application crash. (CVE-2011-1081)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"openldap2.3","version":"2.4.9-0ubuntu0.8.04.5","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.9-0ubuntu0.8.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap2.3","version_link":"https://launchpad.net/ubuntu/+source/openldap2.3/2.4.9-0ubuntu0.8.04.5"}],"karmic":[{"name":"openldap","version":"2.4.18-0ubuntu1.2","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.18-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap","version_link":"https://launchpad.net/ubuntu/+source/openldap/2.4.18-0ubuntu1.2"}],"lucid":[{"name":"openldap","version":"2.4.21-0ubuntu5.4","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.21-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap","version_link":"https://launchpad.net/ubuntu/+source/openldap/2.4.21-0ubuntu5.4"}],"maverick":[{"name":"openldap","version":"2.4.23-0ubuntu3.5","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.23-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap","version_link":"https://launchpad.net/ubuntu/+source/openldap/2.4.23-0ubuntu3.5"}]},"type":"USN","cves_ids":["CVE-2011-1025","CVE-2011-1081","CVE-2011-1024"]}]},{"id":"CVE-2011-1025","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nbind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require\nauthentication for the root Distinguished Name (DN), which allows remote\nattackers to bypass intended access restrictions via an arbitrary password.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"code not compiled (requires --enable-ndb)"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6661","https://ubuntu.com/security/notices/USN-1100-1","https://www.cve.org/CVERecord?id=CVE-2011-1025"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openldap/+bug/742104","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=617606"],"patches":{"openldap":["vendor: https://rhn.redhat.com/errata/RHSA-2011-0347.html"],"openldap2.3":[],"openldap2.2":[]},"tags":{},"packages":[{"name":"openldap","source":"https://ubuntu.com/security/cve?package=openldap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap","debian":"https://tracker.debian.org/pkg/openldap","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.4.18-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.4.21-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.4.23-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openldap2.2","source":"https://ubuntu.com/security/cve?package=openldap2.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap2.2","debian":"https://tracker.debian.org/pkg/openldap2.2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openldap2.3","source":"https://ubuntu.com/security/cve?package=openldap2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap2.3","debian":"https://tracker.debian.org/pkg/openldap2.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1100-1"],"notices":[{"id":"USN-1100-1","title":"OpenLDAP vulnerabilities","summary":"An attacker could send crafted input to OpenLDAP and cause it to crash.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-03-31T14:06:15.828714","description":"It was discovered that OpenLDAP did not properly check forwarded\nauthentication failures when using a consumer server and chain overlay. If\nOpenLDAP were configured in this manner, an attacker could bypass\nauthentication checks by sending an invalid password to a consumer server.\n(CVE-2011-1024)\n\nIt was discovered that OpenLDAP did not properly perform authentication\nchecks to the rootdn when using the back-ndb backend. An attacker could\nexploit this to access the directory by sending an arbitrary password.\nUbuntu does not ship OpenLDAP with back-ndb support by default. This issue\ndid not affect Ubuntu 8.04 LTS. (CVE-2011-1025)\n\nIt was discovered that OpenLDAP did not properly validate modrdn requests.\nAn unauthenticated remote user could use this to cause a denial of service\nvia application crash. (CVE-2011-1081)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"openldap2.3","version":"2.4.9-0ubuntu0.8.04.5","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.9-0ubuntu0.8.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap2.3","version_link":"https://launchpad.net/ubuntu/+source/openldap2.3/2.4.9-0ubuntu0.8.04.5"}],"karmic":[{"name":"openldap","version":"2.4.18-0ubuntu1.2","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.18-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap","version_link":"https://launchpad.net/ubuntu/+source/openldap/2.4.18-0ubuntu1.2"}],"lucid":[{"name":"openldap","version":"2.4.21-0ubuntu5.4","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.21-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap","version_link":"https://launchpad.net/ubuntu/+source/openldap/2.4.21-0ubuntu5.4"}],"maverick":[{"name":"openldap","version":"2.4.23-0ubuntu3.5","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.23-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap","version_link":"https://launchpad.net/ubuntu/+source/openldap/2.4.23-0ubuntu3.5"}]},"type":"USN","cves_ids":["CVE-2011-1025","CVE-2011-1081","CVE-2011-1024"]}]},{"id":"CVE-2011-1024","published":"2011-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nchain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave\nconfiguration with a chain overlay and ppolicy_forward_updates (aka\nauthentication-failure forwarding) is used, allows remote authenticated\nusers to bypass external-program authentication by sending an invalid\npassword to a slave server.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"openldap 2.2 does not use callbacks for checking if back-ldap\nreturned any results"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6607","https://ubuntu.com/security/notices/USN-1100-1","https://www.cve.org/CVERecord?id=CVE-2011-1024"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openldap/+bug/742104","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=617606"],"patches":{"openldap":["vendor: https://rhn.redhat.com/errata/RHSA-2011-0347.html"],"openldap2.3":[],"openldap2.2":[]},"tags":{},"packages":[{"name":"openldap","source":"https://ubuntu.com/security/cve?package=openldap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap","debian":"https://tracker.debian.org/pkg/openldap","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.4.18-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.4.21-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.4.23-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openldap2.2","source":"https://ubuntu.com/security/cve?package=openldap2.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap2.2","debian":"https://tracker.debian.org/pkg/openldap2.2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openldap2.3","source":"https://ubuntu.com/security/cve?package=openldap2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap2.3","debian":"https://tracker.debian.org/pkg/openldap2.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.4.9-0ubuntu0.8.04.5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1100-1"],"notices":[{"id":"USN-1100-1","title":"OpenLDAP vulnerabilities","summary":"An attacker could send crafted input to OpenLDAP and cause it to crash.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-03-31T14:06:15.828714","description":"It was discovered that OpenLDAP did not properly check forwarded\nauthentication failures when using a consumer server and chain overlay. If\nOpenLDAP were configured in this manner, an attacker could bypass\nauthentication checks by sending an invalid password to a consumer server.\n(CVE-2011-1024)\n\nIt was discovered that OpenLDAP did not properly perform authentication\nchecks to the rootdn when using the back-ndb backend. An attacker could\nexploit this to access the directory by sending an arbitrary password.\nUbuntu does not ship OpenLDAP with back-ndb support by default. This issue\ndid not affect Ubuntu 8.04 LTS. (CVE-2011-1025)\n\nIt was discovered that OpenLDAP did not properly validate modrdn requests.\nAn unauthenticated remote user could use this to cause a denial of service\nvia application crash. (CVE-2011-1081)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"openldap2.3","version":"2.4.9-0ubuntu0.8.04.5","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.9-0ubuntu0.8.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap2.3","version_link":"https://launchpad.net/ubuntu/+source/openldap2.3/2.4.9-0ubuntu0.8.04.5"}],"karmic":[{"name":"openldap","version":"2.4.18-0ubuntu1.2","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.18-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap","version_link":"https://launchpad.net/ubuntu/+source/openldap/2.4.18-0ubuntu1.2"}],"lucid":[{"name":"openldap","version":"2.4.21-0ubuntu5.4","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.21-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap","version_link":"https://launchpad.net/ubuntu/+source/openldap/2.4.21-0ubuntu5.4"}],"maverick":[{"name":"openldap","version":"2.4.23-0ubuntu3.5","description":"OpenLDAP utilities","is_source":true},{"name":"slapd","version":"2.4.23-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openldap","version_link":"https://launchpad.net/ubuntu/+source/openldap/2.4.23-0ubuntu3.5"}]},"type":"USN","cves_ids":["CVE-2011-1025","CVE-2011-1081","CVE-2011-1024"]}]}],"offset":71400,"limit":20,"total_results":79316}