{"cves":[{"id":"CVE-2010-3063","published":"2010-08-20T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe php_mysqlnd_read_error_from_line function in the Mysqlnd extension in\nPHP 5.3 through 5.3.2 does not properly calculate a buffer length, which\nallows context-dependent attackers to trigger a heap-based buffer overflow\nvia crafted inputs that cause a negative length value to be used.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3063"],"bugs":[""],"patches":{"php5":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3062","published":"2010-08-20T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2\nallows remote attackers to (1) read sensitive memory via a modified length\nvalue, which is not properly handled by the php_mysqlnd_ok_read function;\nor (2) trigger a heap-based buffer overflow via a modified length value,\nwhich is not properly handled by the php_mysqlnd_rset_header_read function.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3062"],"bugs":[""],"patches":{"php5":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2944","published":"2010-08-20T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe authenticate function in LDAPUserFolder/LDAPUserFolder.py in\nzope-ldapuserfolder 2.9-1 does not verify the password for the emergency\naccount, which allows remote attackers to gain privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2944"],"bugs":[""],"patches":{"zope-ldapuserfolder":[]},"tags":{},"packages":[{"name":"zope-ldapuserfolder","source":"https://ubuntu.com/security/cve?package=zope-ldapuserfolder","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zope-ldapuserfolder","debian":"https://tracker.debian.org/pkg/zope-ldapuserfolder","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2937","published":"2010-08-20T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in\nVideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process\nID3v2 tags, which allows remote attackers to cause a denial of service\n(application crash) via a crafted media file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.videolan.org/security/sa1004.html","https://www.cve.org/CVERecord?id=CVE-2010-2937"],"bugs":[""],"patches":{"vlc":["upstream: http://git.videolan.org/?p=vlc/vlc-1.1.git;a=commit;h=24918843e57c7962e28fcb01845adce82bed6516","upstream: http://git.videolan.org/?p=vlc/vlc-1.0.git;a=commit;h=22a22e356c9d93993086810b2e25b59b55925b3a"]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.0.6-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.1.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2628","published":"2010-08-20T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does\nnot properly check the return values of snprintf calls, which allows remote\nattackers to execute arbitrary code via crafted (1) certificate or (2)\nidentity data that triggers buffer overflows.","ubuntu_description":"","notes":[{"author":"kees","note":"this may already be mitigated by FORTIFY_SOURCE"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2628"],"bugs":[""],"patches":{"strongswan":[]},"tags":{},"packages":[{"name":"strongswan","source":"https://ubuntu.com/security/cve?package=strongswan","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=strongswan","debian":"https://tracker.debian.org/pkg/strongswan","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4.4.1-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"4.4.1-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"4.4.1-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"4.4.1-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"4.4.1-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"4.4.1-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-7258","published":"2010-08-20T18:00:00","updated_at":"2025-08-04T19:23:22.792771+00:00","description":"\nThe standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62\nallows local users to cause a denial of service (application exit) via an\ne-mail message containing a long line that begins with a . (dot) character.\n NOTE: CVE disputes this issue because it is solely a usability problem for\nsenders of messages with certain long lines, and has no security impact","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-7258"],"bugs":[""],"patches":{"ssmtp":[]},"tags":{},"packages":[{"name":"ssmtp","source":"https://ubuntu.com/security/cve?package=ssmtp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ssmtp","debian":"https://tracker.debian.org/pkg/ssmtp","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"not a security issue","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3065","published":"2010-08-20T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default session serializer in PHP 5.2 through 5.2.13 and 5.3 through\n5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows\ncontext-dependent attackers to modify arbitrary session variables via a\ncrafted session variable name.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is MOPS-2010-060"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/31/mops-2010-060-php-session-serializer-session-data-injection-vulnerability/index.html","http://www.debian.org/security/2010/dsa-2089","https://ubuntu.com/security/notices/USN-989-1","https://www.cve.org/CVERecord?id=CVE-2010-3065"],"bugs":[""],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=298608"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.19","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.12","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.2.6.dfsg.1-3ubuntu4.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3, 5.2.14","component":null,"pocket":"security"}]}],"notices_ids":["USN-989-1"],"notices":[{"id":"USN-989-1","title":"PHP vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-20T18:22:04.757285","description":"Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc\nrequests. An attacker could exploit this issue to cause the PHP server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2010-0397)\n\nIt was discovered that the pseudorandom number generator in PHP did not\nprovide the expected entropy. An attacker could exploit this issue to\npredict values that were intended to be random, such as session cookies.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10.\n(CVE-2010-1128)\n\nIt was discovered that PHP did not properly handle directory pathnames that\nlacked a trailing slash character. An attacker could exploit this issue to\nbypass safe_mode restrictions. This issue only affected Ubuntu 6.06 LTS,\n8.04 LTS, 9.04 and 9.10. (CVE-2010-1129)\n\nGrzegorz Stachowiak discovered that the PHP session extension did not\nproperly handle semicolon characters. An attacker could exploit this issue\nto bypass safe_mode restrictions. This issue only affected Ubuntu 8.04 LTS,\n9.04 and 9.10. (CVE-2010-1130)\n\nStefan Esser discovered that PHP incorrectly decoded remote HTTP chunked\nencoding streams. An attacker could exploit this issue to cause the PHP\nserver to crash and possibly execute arbitrary code with application\nprivileges. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-1866)\n\nMateusz Kocielski discovered that certain PHP SQLite functions incorrectly\nhandled empty SQL queries. An attacker could exploit this issue to possibly\nexecute arbitrary code with application privileges. (CVE-2010-1868)\n\nMateusz Kocielski discovered that PHP incorrectly handled certain arguments\nto the fnmatch function. An attacker could exploit this flaw and cause the\nPHP server to consume all available stack memory, resulting in a denial of\nservice. (CVE-2010-1917)\n\nStefan Esser discovered that PHP incorrectly handled certain strings in the\nphar extension. An attacker could exploit this flaw to possibly view\nsensitive information. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2010-2094, CVE-2010-2950)\n\nStefan Esser discovered that PHP incorrectly handled deserialization of\nSPLObjectStorage objects. A remote attacker could exploit this issue to\nview sensitive information and possibly execute arbitrary code with\napplication privileges. This issue only affected Ubuntu 8.04 LTS, 9.04,\n9.10 and 10.04 LTS. (CVE-2010-2225)\n\nIt was discovered that PHP incorrectly filtered error messages when limits\nfor memory, execution time, or recursion were exceeded. A remote attacker\ncould exploit this issue to possibly view sensitive information.\n(CVE-2010-2531)\n\nStefan Esser discovered that the PHP session serializer incorrectly handled\nthe PS_UNDEF_MARKER marker. An attacker could exploit this issue to alter\narbitrary session variables. (CVE-2010-3065)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.12","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.5","description":"","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.19","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"}],"jaunty":[{"name":"php5","version":"5.2.6.dfsg.1-3ubuntu4.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"php5-cgi","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"libapache2-mod-php5","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"}]},"type":"USN","cves_ids":["CVE-2010-0397","CVE-2010-1128","CVE-2010-1129","CVE-2010-1130","CVE-2010-1866","CVE-2010-1868","CVE-2010-1917","CVE-2010-2094","CVE-2010-2225","CVE-2010-2531","CVE-2010-2950","CVE-2010-3065"]}]},{"id":"CVE-2010-3015","published":"2010-08-20T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the ext4_ext_get_blocks function in fs/ext4/extents.c\nin the Linux kernel before 2.6.34 allows local users to cause a denial of\nservice (BUG and system crash) via a write operation on the last block of a\nlarge file, followed by a sync operation.","ubuntu_description":"\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://www.cve.org/CVERecord?id=CVE-2010-3015"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["hardy: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-3015/patches/hardy/linux/0001-ext4-consolidate-in_range-definitions.txt","jaunty: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-3015/patches/jaunty/linux/0001-ext4-consolidate-in_range-definitions.txt","karmic: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-3015/patches/karmic/linux/0001-ext4-consolidate-in_range-definitions.txt","lucid: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-3015/patches/lucid/linux/0001-ext4-consolidate-in_range-definitions.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-lts-backport-maverick":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.80","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.66","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-25.43","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1083-1","USN-1074-1","USN-1000-1","USN-1074-2"],"notices":[{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-2810","published":"2010-08-20T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the convert_to_idna function in\nWWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4\nallows remote attackers to cause a denial of service (application crash) or\npossibly execute arbitrary code via a malformed URL containing a %\n(percent) character in the domain name.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1642-1","https://www.cve.org/CVERecord?id=CVE-2010-2810"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/lynx-cur/+bug/613254"],"patches":{"lynx-cur":["other: https://bugs.edge.launchpad.net/ubuntu/+source/lynx-cur/+bug/613254"]},"tags":{},"packages":[{"name":"lynx-cur","source":"https://ubuntu.com/security/cve?package=lynx-cur","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lynx-cur","debian":"https://tracker.debian.org/pkg/lynx-cur","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.8.8dev.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.8.8dev.7-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.8.8dev.7-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.8.8dev.7-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2.8.8dev.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.8.8dev.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1642-1"],"notices":[{"id":"USN-1642-1","title":"Lynx vulnerabilities","summary":"Two security issues were fixed in Lynx.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-11-29T21:37:14.571636","description":"Dan Rosenberg discovered a heap-based buffer overflow in Lynx. If a user\nwere tricked into opening a specially crafted page, a remote attacker could\ncause a denial of service via application crash, or possibly execute\narbitrary code as the user invoking the program. This issue only affected\nUbuntu 10.04 LTS. (CVE-2010-2810)\n\nIt was discovered that Lynx did not properly verify that an HTTPS\ncertificate was signed by a trusted certificate authority. This could allow\nan attacker to perform a \"machine-in-the-middle\" (MITM) attack which would make\nthe user believe their connection is secure, but is actually being\nmonitored. This update changes the behavior of Lynx such that self-signed\ncertificates no longer validate. Users requiring the previous behavior can\nuse the 'FORCE_SSL_PROMPT' option in lynx.cfg. (CVE-2012-5821)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"lynx-cur","version":"2.8.8dev.2-1ubuntu0.1","description":"Text-mode WWW Browser with NLS support","is_source":true},{"name":"lynx-cur","version":"2.8.8dev.2-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx-cur","version_link":"https://launchpad.net/ubuntu/+source/lynx-cur/2.8.8dev.2-1ubuntu0.1"}],"oneiric":[{"name":"lynx-cur","version":"2.8.8dev.9-2ubuntu0.11.10.1","description":"Text-mode WWW Browser with NLS support","is_source":true},{"name":"lynx-cur","version":"2.8.8dev.9-2ubuntu0.11.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx-cur","version_link":"https://launchpad.net/ubuntu/+source/lynx-cur/2.8.8dev.9-2ubuntu0.11.10.1"}],"precise":[{"name":"lynx-cur","version":"2.8.8dev.9-2ubuntu0.12.04.1","description":"Text-mode WWW Browser with NLS support","is_source":true},{"name":"lynx-cur","version":"2.8.8dev.9-2ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx-cur","version_link":"https://launchpad.net/ubuntu/+source/lynx-cur/2.8.8dev.9-2ubuntu0.12.04.1"}],"quantal":[{"name":"lynx-cur","version":"2.8.8dev.12-2ubuntu0.1","description":"Text-mode WWW Browser with NLS support","is_source":true},{"name":"lynx-cur","version":"2.8.8dev.12-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx-cur","version_link":"https://launchpad.net/ubuntu/+source/lynx-cur/2.8.8dev.12-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2010-2810","CVE-2012-5821"]}]},{"id":"CVE-2010-2531","published":"2010-08-20T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3\nflushes the output buffer to the user when certain fatal errors occur, even\nif display_errors is off, which allows remote attackers to obtain sensitive\ninformation by causing the application to exceed limits for memory,\nexecution time, or recursion.","ubuntu_description":"","notes":[{"author":"kees","note":"5.2.14 and 5.3.3"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-989-1","https://www.cve.org/CVERecord?id=CVE-2010-2531"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2531"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=301143","upstream: http://svn.php.net/viewvc?view=revision&revision=301144","upstream: http://svn.php.net/viewvc?view=revision&revision=301245","upstream: http://svn.php.net/viewvc?view=revision&revision=301863"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.19","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.12","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.2.6.dfsg.1-3ubuntu4.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-989-1"],"notices":[{"id":"USN-989-1","title":"PHP vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-20T18:22:04.757285","description":"Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc\nrequests. An attacker could exploit this issue to cause the PHP server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2010-0397)\n\nIt was discovered that the pseudorandom number generator in PHP did not\nprovide the expected entropy. An attacker could exploit this issue to\npredict values that were intended to be random, such as session cookies.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10.\n(CVE-2010-1128)\n\nIt was discovered that PHP did not properly handle directory pathnames that\nlacked a trailing slash character. An attacker could exploit this issue to\nbypass safe_mode restrictions. This issue only affected Ubuntu 6.06 LTS,\n8.04 LTS, 9.04 and 9.10. (CVE-2010-1129)\n\nGrzegorz Stachowiak discovered that the PHP session extension did not\nproperly handle semicolon characters. An attacker could exploit this issue\nto bypass safe_mode restrictions. This issue only affected Ubuntu 8.04 LTS,\n9.04 and 9.10. (CVE-2010-1130)\n\nStefan Esser discovered that PHP incorrectly decoded remote HTTP chunked\nencoding streams. An attacker could exploit this issue to cause the PHP\nserver to crash and possibly execute arbitrary code with application\nprivileges. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-1866)\n\nMateusz Kocielski discovered that certain PHP SQLite functions incorrectly\nhandled empty SQL queries. An attacker could exploit this issue to possibly\nexecute arbitrary code with application privileges. (CVE-2010-1868)\n\nMateusz Kocielski discovered that PHP incorrectly handled certain arguments\nto the fnmatch function. An attacker could exploit this flaw and cause the\nPHP server to consume all available stack memory, resulting in a denial of\nservice. (CVE-2010-1917)\n\nStefan Esser discovered that PHP incorrectly handled certain strings in the\nphar extension. An attacker could exploit this flaw to possibly view\nsensitive information. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2010-2094, CVE-2010-2950)\n\nStefan Esser discovered that PHP incorrectly handled deserialization of\nSPLObjectStorage objects. A remote attacker could exploit this issue to\nview sensitive information and possibly execute arbitrary code with\napplication privileges. This issue only affected Ubuntu 8.04 LTS, 9.04,\n9.10 and 10.04 LTS. (CVE-2010-2225)\n\nIt was discovered that PHP incorrectly filtered error messages when limits\nfor memory, execution time, or recursion were exceeded. A remote attacker\ncould exploit this issue to possibly view sensitive information.\n(CVE-2010-2531)\n\nStefan Esser discovered that the PHP session serializer incorrectly handled\nthe PS_UNDEF_MARKER marker. An attacker could exploit this issue to alter\narbitrary session variables. (CVE-2010-3065)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.12","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.5","description":"","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.19","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"}],"jaunty":[{"name":"php5","version":"5.2.6.dfsg.1-3ubuntu4.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"php5-cgi","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"libapache2-mod-php5","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"}]},"type":"USN","cves_ids":["CVE-2010-0397","CVE-2010-1128","CVE-2010-1129","CVE-2010-1130","CVE-2010-1866","CVE-2010-1868","CVE-2010-1917","CVE-2010-2094","CVE-2010-2225","CVE-2010-2531","CVE-2010-2950","CVE-2010-3065"]}]},{"id":"CVE-2010-2484","published":"2010-08-20T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe strrchr function in PHP 5.2 before 5.2.14 allows context-dependent\nattackers to obtain sensitive information (memory contents) or trigger\nmemory corruption by causing a userspace interruption of an internal\nfunction or handler.","ubuntu_description":"","notes":[{"author":"kees","note":"5.3.3, and 5.2.14"},{"author":"mdeslaur","note":"looks like it's 5.2 only\ninterruption issue, safe_mode - open_basedir bypass, ignoring"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1231-1","https://www.cve.org/CVERecord?id=CVE-2010-2484"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=619324"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=300916"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.18","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"5.3.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"5.3.3-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"5.3.3-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"5.3.3-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-1231-1"],"notices":[{"id":"USN-1231-1","title":"PHP Vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-10-18T06:22:20.140056","description":"Mateusz Kocielski, Marek Kroemeke and Filip Palian discovered that a\nstack-based buffer overflow existed in the socket_connect function's\nhandling of long pathnames for AF_UNIX sockets. A remote attacker\nmight be able to exploit this to execute arbitrary code; however,\nthe default compiler options for affected releases should reduce\nthe vulnerability to a denial of service. This issue affected Ubuntu\n10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04. (CVE-2011-1938)\n\nKrzysztof Kotowicz discovered that the PHP post handler function\ndoes not properly restrict filenames in multipart/form-data POST\nrequests. This may allow remote attackers to conduct absolute\npath traversal attacks and possibly create or overwrite arbitrary\nfiles. This issue affected Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu\n10.10 and Ubuntu 11.04. (CVE-2011-2202)\n\nIt was discovered that the crypt function for blowfish does not\nproperly handle 8-bit characters. This could make it easier for an\nattacker to discover a cleartext password containing an 8-bit character\nthat has a matching blowfish crypt value. This issue affected Ubuntu\n10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04. (CVE-2011-2483)\n\nIt was discovered that PHP did not properly check the return values of\nthe malloc(3), calloc(3) and realloc(3) library functions in multiple\nlocations. This could allow an attacker to cause a denial of service\nvia a NULL pointer dereference or possibly execute arbitrary code.\nThis issue affected Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 10.10\nand Ubuntu 11.04. (CVE-2011-3182)\n\nMaksymilian Arciemowicz discovered that PHP did not properly implement\nthe error_log function. This could allow an attacker to cause a denial\nof service via an application crash. This issue affected Ubuntu 10.04\nLTS, Ubuntu 10.10, Ubuntu 11.04 and Ubuntu 11.10. (CVE-2011-3267)\n\nMaksymilian Arciemowicz discovered that the ZipArchive functions\naddGlob() and addPattern() did not properly check their flag arguments.\nThis could allow a malicious script author to cause a denial of\nservice via application crash. This issue affected Ubuntu 10.04 LTS,\nUbuntu 10.10, Ubuntu 11.04 and Ubuntu 11.10. (CVE-2011-1657)\n\nIt was discovered that the Xend opcode parser in PHP could be interrupted\nwhile handling the shift-left, shift-right, and bitwise-xor opcodes.\nThis could allow a malicious script author to expose memory\ncontents. This issue affected Ubuntu 10.04 LTS. (CVE-2010-1914)\n\nIt was discovered that the strrchr function in PHP could be interrupted\nby a malicious script, allowing the exposure of memory contents. This\nissue affected Ubuntu 8.04 LTS. (CVE-2010-2484)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.18","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.18"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.18"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.18"},{"name":"php5-common","version":"5.2.4-2ubuntu5.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.18"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.10","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.10"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.10"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.10"},{"name":"php5-common","version":"5.3.2-1ubuntu4.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.10"}],"maverick":[{"name":"php5","version":"5.3.3-1ubuntu9.6","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.3-1ubuntu9.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.6"},{"name":"php5-cgi","version":"5.3.3-1ubuntu9.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.6"},{"name":"libapache2-mod-php5","version":"5.3.3-1ubuntu9.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.6"},{"name":"php5-common","version":"5.3.3-1ubuntu9.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.3-1ubuntu9.6"}],"natty":[{"name":"php5","version":"5.3.5-1ubuntu7.3","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.5-1ubuntu7.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.3"},{"name":"php5-cgi","version":"5.3.5-1ubuntu7.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.3"},{"name":"libapache2-mod-php5","version":"5.3.5-1ubuntu7.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.3"},{"name":"php5-common","version":"5.3.5-1ubuntu7.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.5-1ubuntu7.3"}],"oneiric":[{"name":"php5","version":"5.3.6-13ubuntu3.2","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"php5-cli","version":"5.3.6-13ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.2"},{"name":"php5-cgi","version":"5.3.6-13ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.2"},{"name":"libapache2-mod-php5","version":"5.3.6-13ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.2"},{"name":"php5-common","version":"5.3.6-13ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.6-13ubuntu3.2"}]},"type":"USN","cves_ids":["CVE-2010-1914","CVE-2010-2484","CVE-2011-1657","CVE-2011-1938","CVE-2011-2202","CVE-2011-2483","CVE-2011-3182","CVE-2011-3267"]}]},{"id":"CVE-2010-1172","published":"2010-08-20T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDBus-GLib 0.73 disregards the access flag of exported GObject properties,\nwhich allows local users to bypass intended access restrictions and\npossibly cause a denial of service by modifying properties, as demonstrated\nby properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3)\nModemManager services.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"network-manager and modemmanager require a no change rebuild to\nincorporate the changes"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1138-1","https://ubuntu.com/security/notices/USN-1138-2","https://www.cve.org/CVERecord?id=CVE-2010-1172"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/dbus-glib/+bug/616517"],"patches":{"dbus-glib":["other: http://cgit.freedesktop.org/dbus/dbus-glib/commit/?h=rhel5&id=9a6bce9b615abca6068348c1606ba8eaf13d9ae0","vendor: https://bugzilla.redhat.com/show_bug.cgi?id=585394"]},"tags":{},"packages":[{"name":"dbus-glib","source":"https://ubuntu.com/security/cve?package=dbus-glib","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dbus-glib","debian":"https://tracker.debian.org/pkg/dbus-glib","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.74-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.84-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.88-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1138-1"],"notices":[{"id":"USN-1138-1","title":"DBus-GLib vulnerability","summary":"An attacker could send crafted input to applications using DBus-GLib and\ncause them to crash.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-05-26T21:55:42.553217","description":"It was discovered that DBus-GLib did not properly verify the access flag of\nexported GObject properties under certain circumstances. A local attacker\ncould exploit this to bypass intended access restrictions or possibly\ncause a denial of service.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"dbus-glib","version":"0.74-2ubuntu0.1","description":"GLib bindings for DBus","is_source":true},{"name":"libdbus-glib-1-2","version":"0.74-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus-glib","version_link":"https://launchpad.net/ubuntu/+source/dbus-glib/0.74-2ubuntu0.1"}],"lucid":[{"name":"dbus-glib","version":"0.84-1ubuntu0.2","description":"GLib bindings for DBus","is_source":true},{"name":"libdbus-glib-1-2","version":"0.84-1ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus-glib","version_link":"https://launchpad.net/ubuntu/+source/dbus-glib/0.84-1ubuntu0.2"}]},"type":"USN","cves_ids":["CVE-2010-1172"]}]},{"id":"CVE-2010-2809","published":"2010-08-19T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of the binding in Uzbl before\n2010.08.05 does not properly use the @SELECTED_URI feature, which allows\nuser-assisted remote attackers to execute arbitrary commands via a crafted\nHREF attribute of an A element in an HTML document.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.uzbl.org/news.php?id=29","https://www.cve.org/CVERecord?id=CVE-2010-2809"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=621965","https://bugzilla.redhat.com/show_bug.cgi?id=621964","http://www.uzbl.org/bugs/index.php?do=details&task_id=240"],"patches":{"uzbl":["upstream: http://github.com/pawelz/uzbl/commit/342f292c27973c9df5f631a38bd12f14a9c5cdc2","upstream: http://github.com/Dieterbe/uzbl/commit/9cc39cb5c9396be013b5dc2ba7e4b3eaa647e975"]},"tags":{},"packages":[{"name":"uzbl","source":"https://ubuntu.com/security/cve?package=uzbl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=uzbl","debian":"https://tracker.debian.org/pkg/uzbl","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"0.0.0git.20100403-3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2010.08.05","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [0.0.0git.20100403-3]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2234","published":"2010-08-19T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0\nthrough 0.11.0 allows remote attackers to hijack the authentication of\nadministrators for direct requests to an installation URL.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"backport is regression prone"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2234"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=624764","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=570013"],"patches":{"couchdb":["upstream: http://svn.apache.org/viewvc?view=revision&revision=957969"]},"tags":{},"packages":[{"name":"couchdb","source":"https://ubuntu.com/security/cve?package=couchdb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=couchdb","debian":"https://tracker.debian.org/pkg/couchdb","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.0.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.0.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.0.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.0.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.0.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.11.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1760","published":"2010-08-19T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nloader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in\nWebCore in WebKit before r58409 does not properly handle credentials during\na cross-origin synchronous request, which has unspecified impact and remote\nattack vectors, aka rdar problem 7905150.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)\nwebkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-1760"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=37781"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/58409"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.5-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1386","published":"2010-08-19T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npage/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5\ndoes not properly restrict access to the lastPosition function, which has\nunspecified impact and remote attack vectors, aka rdar problem 7746357.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)\nwebkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-1386"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=36255"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/56188"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.5-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3054","published":"2010-08-19T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in FreeType 2.3.9, and other versions before\n2.4.2, allows remote attackers to cause a denial of service via vectors\ninvolving nested Standard Encoding Accented Character (aka seac) calls,\nrelated to psaux.h, cffgload.c, cffgload.h, and t1decode.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3054"],"bugs":[""],"patches":{"freetype":[]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"not-affected","description":"doesn't reproduce","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"doesn't reproduce","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.3.9-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.3.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.3.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3053","published":"2010-08-19T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nbdf/bdflib.c in FreeType before 2.4.2 allows remote attackers to cause a\ndenial of service (application crash) via a crafted BDF font file, related\nto an attempted modification of a value in a static string.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3053"],"bugs":[""],"patches":{"freetype":[]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.10-1ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.3.5-1ubuntu4.8.04.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.3.9-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.3.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.3.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2813","published":"2010-08-19T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfunctions/imap_general.php in SquirrelMail before 1.4.21 does not properly\nhandle 8-bit characters in passwords, which allows remote attackers to\ncause a denial of service (disk consumption) by making many IMAP login\nattempts with different usernames, leading to the creation of many\npreferences files.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Note that Red Hat Security Advisory RHSA-2012:010 was incomplete (see\nCVE-2012-2124)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2813"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=618096"],"patches":{"squirrelmail":["upstream: http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/imap_general.php?view=patch&r1=13972&r2=13971&pathrev=13972"]},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2:1.4.21-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2:1.4.21-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2:1.4.21-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2:1.4.21-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2:1.4.21-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2:1.4.21-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2:1.4.21-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.21","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2497","published":"2010-08-19T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger underflow in glyph handling in FreeType before 2.4.0 allows remote\nattackers to cause a denial of service (application crash) or possibly\nexecute arbitrary code via a crafted font file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"code not present in lucid and earlier"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2497"],"bugs":["http://savannah.nongnu.org/bugs/index.php?30082","http://savannah.nongnu.org/bugs/index.php?30083"],"patches":{"freetype":["upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=7d3d2cc4fef72c6be9c454b3809c387e12b44cfc","upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=7d3d2cc4fef72c6be9c454b3809c387e12b44cfc"]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":72460,"limit":20,"total_results":79316}