{"cves":[{"id":"CVE-2010-2959","published":"2010-08-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in net/can/bcm.c in the Controller Area Network (CAN)\nimplementation in the Linux kernel before 2.6.27.53, 2.6.32.x before\n2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows\nattackers to execute arbitrary code or cause a denial of service (system\ncrash) via crafted CAN traffic.","ubuntu_description":"\nBen Hawkes discovered an integer overflow in the Controller Area Network","notes":[{"author":"smb","note":"File bcm.c does not exist in Hardy and before."}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-974-1","https://ubuntu.com/security/notices/USN-1074-1","https://www.cve.org/CVERecord?id=CVE-2010-2959"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["vendor: http://www.spinics.net/lists/netdev/msg137652.html","upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=5b75c4973ce779520b9d1e392483207d6f842cde","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2959/patches/jaunty/linux/0001-can-add-limit-for-nframes-and-clean-up-signed-unsigned.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2959/patches/karmic/linux/0001-can-add-limit-for-nframes-and-clean-up-signed-unsigned.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2959/patches/lucid/linux/0001-can-add-limit-for-nframes-and-clean-up-signed-unsigned.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-mvl-dove":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.64","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.63","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-24.41","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-18.24","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.17","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-308.15","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.19","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-214.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-208.24","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-974-1","USN-1074-1"],"notices":[{"id":"USN-974-1","title":"Linux kernel vulnerabilities","summary":"The Linux kernel could be made to crash or run programs as root.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2010-08-19T22:12:07.989033","description":"Gael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CAN) subsystem when setting up frame content and filtering certain\nmessages. An attacker could send specially crafted CAN traffic to crash the\nsystem or gain root privileges. (CVE-2010-2959)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.30","description":"The Linux kernel for Marvell Dove","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.17","description":"The Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.63","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.17","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.17"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.30"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.30"}],"hardy":[{"name":"linux","version":"2.6.24-28.75","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"}],"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-208.24","description":"The Linux kernel for Marvell Dove","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-608.19","description":"The Linux kernel for I.MX51-based systems","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-502.10","description":"The Linux kernel for OMAP3-based systems","is_source":true},{"name":"linux-ec2","version":"2.6.32-308.15","description":"The Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-24.41","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.33-502-omap","version":"2.6.33-502.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-502.10"},{"name":"linux-image-2.6.32-308-ec2","version":"2.6.32-308.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-308.15"},{"name":"linux-image-2.6.32-24-386","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-powerpc","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-powerpc64-smp","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-generic-pae","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-versatile","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-generic","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-virtual","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-server","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-ia64","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-sparc64-smp","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-preempt","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-powerpc-smp","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-sparc64","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-lpia","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-208-dove","version":"2.6.32-208.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-208.24"},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.19"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.87","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"}],"jaunty":[{"name":"linux","version":"2.6.28-19.64","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"}]},"type":"USN","cves_ids":["CVE-2010-2240","CVE-2010-2803","CVE-2010-2959"]},{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-2803","published":"2010-08-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering\nManager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x\nbefore 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4\nallows local users to obtain potentially sensitive information from kernel\nmemory by requesting a large memory-allocation amount.","ubuntu_description":"\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.","notes":[{"author":"smb","note":"No DRM for Hardy and Dapper."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-974-1","https://ubuntu.com/security/notices/USN-1074-1","https://www.cve.org/CVERecord?id=CVE-2010-2803"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2803/patches/jaunty/linux/0001-drm-Initialize-ioctl-struct-when-no-user-data-is-prese.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2803/patches/karmic/linux/0001-drm-Initialize-ioctl-struct-when-no-user-data-is-prese.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2803/patches/lucid/linux/0001-drm-Initialize-ioctl-struct-when-no-user-data-is-prese.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-mvl-dove":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.64","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.63","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-24.41","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-18.24","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.35.3","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.17","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-308.15","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.19","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-214.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-208.24","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-974-1","USN-1074-1"],"notices":[{"id":"USN-974-1","title":"Linux kernel vulnerabilities","summary":"The Linux kernel could be made to crash or run programs as root.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2010-08-19T22:12:07.989033","description":"Gael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CAN) subsystem when setting up frame content and filtering certain\nmessages. An attacker could send specially crafted CAN traffic to crash the\nsystem or gain root privileges. (CVE-2010-2959)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.30","description":"The Linux kernel for Marvell Dove","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.17","description":"The Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.63","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.17","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.17"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.30"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.30"}],"hardy":[{"name":"linux","version":"2.6.24-28.75","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"}],"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-208.24","description":"The Linux kernel for Marvell Dove","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-608.19","description":"The Linux kernel for I.MX51-based systems","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-502.10","description":"The Linux kernel for OMAP3-based systems","is_source":true},{"name":"linux-ec2","version":"2.6.32-308.15","description":"The Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-24.41","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.33-502-omap","version":"2.6.33-502.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-502.10"},{"name":"linux-image-2.6.32-308-ec2","version":"2.6.32-308.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-308.15"},{"name":"linux-image-2.6.32-24-386","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-powerpc","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-powerpc64-smp","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-generic-pae","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-versatile","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-generic","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-virtual","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-server","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-ia64","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-sparc64-smp","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-preempt","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-powerpc-smp","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-sparc64","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-lpia","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-208-dove","version":"2.6.32-208.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-208.24"},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.19"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.87","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"}],"jaunty":[{"name":"linux","version":"2.6.28-19.64","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"}]},"type":"USN","cves_ids":["CVE-2010-2240","CVE-2010-2803","CVE-2010-2959"]},{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-2242","published":"2010-08-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRed Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper\nmappings of privileged source ports, which allows guest OS users to bypass\nintended access restrictions by leveraging IP address and source-port\nvalues, as demonstrated by copying and deleting an NFS directory tree.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1008-1","https://www.cve.org/CVERecord?id=CVE-2010-2242"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/591943"],"patches":{"libvirt":[]},"tags":{},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.4.0-2ubuntu8.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.6.1-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.7.0-1ubuntu13.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.7.5-5ubuntu27.5","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.8.3-1ubuntu8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.3-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1008-1"],"notices":[{"id":"USN-1008-1","title":"libvirt vulnerabilities","summary":"Guest VMs could be made to circumvent security protections to access\nresources on the host.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: The previous version of libvirt on Ubuntu 10.04 LTS would probe\na qemu disk to determine its format and did not require that the format be\ndeclared in the XML. This is considered a security problem in most\ndeployments and this version of libvirt will default to the 'raw' format\nwhen the format is not specified in the XML. As a result, non-raw disks\nwithout a specified disk format will no longer be available in existing\nvirtual machines.\n\nThe libvirt-migrate-qemu-disks tool is provided to aid in transitioning\nvirtual machine definitions to the new required format. In essence, it will\ncheck all domains for affected virtual machines, probe the affected disks\nand update the domain definition accordingly. This command will be run\nautomatically on upgrade. For new virtual machines using non-raw images,\nthe disk format must be specified in the domain XML provided to libvirt,\notherwise the disk will not be available to the virtual machine. See man 1\nlibvirt-migrate-qemu-disks for details.\n\nUsers who require the old behavior can adjust the 'allow_disk_format_probing'\noption in /etc/libvirt/qemu.conf.\n","references":[],"published":"2010-10-21T22:20:53.013023","description":"It was discovered that libvirt would probe disk backing stores without\nconsulting the defined format for the disk. A privileged attacker in the\nguest could exploit this to read arbitrary files on the host. This issue\nonly affected Ubuntu 10.04 LTS. By default, guests are confined by an\nAppArmor profile which provided partial protection against this flaw.\n(CVE-2010-2237, CVE-2010-2238)\n\nIt was discovered that libvirt would create new VMs without setting a\nbacking store format. A privileged attacker in the guest could exploit this\nto read arbitrary files on the host. This issue did not affect Ubuntu 8.04\nLTS. In Ubuntu 9.10 and later guests are confined by an AppArmor profile\nwhich provided partial protection against this flaw. (CVE-2010-2239)\n\nJeremy Nickurak discovered that libvirt created iptables rules with too\nlenient mappings of source ports. A privileged attacker in the guest could\nbypass intended restrictions to access privileged resources on the host.\n(CVE-2010-2242)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libvirt","version":"0.4.0-2ubuntu8.3","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.4.0-2ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.4.0-2ubuntu8.3"},{"name":"libvirt-bin","version":"0.4.0-2ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.4.0-2ubuntu8.3"}],"lucid":[{"name":"libvirt","version":"0.7.5-5ubuntu27.5","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.7.5-5ubuntu27.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.5-5ubuntu27.5"},{"name":"libvirt-bin","version":"0.7.5-5ubuntu27.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.5-5ubuntu27.5"}],"jaunty":[{"name":"libvirt","version":"0.6.1-0ubuntu5.2","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.6.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.6.1-0ubuntu5.2"},{"name":"libvirt-bin","version":"0.6.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.6.1-0ubuntu5.2"}],"karmic":[{"name":"libvirt","version":"0.7.0-1ubuntu13.2","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.7.0-1ubuntu13.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.0-1ubuntu13.2"},{"name":"libvirt-bin","version":"0.7.0-1ubuntu13.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.0-1ubuntu13.2"}]},"type":"USN","cves_ids":["CVE-2010-2237","CVE-2010-2238","CVE-2010-2239","CVE-2010-2242"]}]},{"id":"CVE-2010-2239","published":"2010-08-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRed Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without\nsetting the user-defined backing-store format, which allows guest OS users\nto read arbitrary files on the host OS via unspecified vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"AppArmor in Ubuntu 9.10 and 10.04 should protect the host OS, but\nan attacker in a virtual machine may be able to access files of another\nmachine.\nUbuntu 9.10's qemu-img and kvm-img both support '-F backingType', so\nhard code libvirt to use this\nUbuntu 9.04's qemu-img and kvm-img do not support specifiying a\nbacking store disk format, so we must autoprobe backing stores at this time.\nQemu didn't gain this option until 0.11, and 9.04 has 0.10 and kvm 84. The\nchanges to qemu/kvm are too invasive and regression-prone and therefore\nan update will not be provided for this CVE for Ubuntu 9.04."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1008-1","https://www.cve.org/CVERecord?id=CVE-2010-2239"],"bugs":[""],"patches":{"libvirt":[]},"tags":{"libvirt":["apparmor"]},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.7.0-1ubuntu13.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.7.5-5ubuntu27.5","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.8.3-1ubuntu8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.3-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1008-1"],"notices":[{"id":"USN-1008-1","title":"libvirt vulnerabilities","summary":"Guest VMs could be made to circumvent security protections to access\nresources on the host.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: The previous version of libvirt on Ubuntu 10.04 LTS would probe\na qemu disk to determine its format and did not require that the format be\ndeclared in the XML. This is considered a security problem in most\ndeployments and this version of libvirt will default to the 'raw' format\nwhen the format is not specified in the XML. As a result, non-raw disks\nwithout a specified disk format will no longer be available in existing\nvirtual machines.\n\nThe libvirt-migrate-qemu-disks tool is provided to aid in transitioning\nvirtual machine definitions to the new required format. In essence, it will\ncheck all domains for affected virtual machines, probe the affected disks\nand update the domain definition accordingly. This command will be run\nautomatically on upgrade. For new virtual machines using non-raw images,\nthe disk format must be specified in the domain XML provided to libvirt,\notherwise the disk will not be available to the virtual machine. See man 1\nlibvirt-migrate-qemu-disks for details.\n\nUsers who require the old behavior can adjust the 'allow_disk_format_probing'\noption in /etc/libvirt/qemu.conf.\n","references":[],"published":"2010-10-21T22:20:53.013023","description":"It was discovered that libvirt would probe disk backing stores without\nconsulting the defined format for the disk. A privileged attacker in the\nguest could exploit this to read arbitrary files on the host. This issue\nonly affected Ubuntu 10.04 LTS. By default, guests are confined by an\nAppArmor profile which provided partial protection against this flaw.\n(CVE-2010-2237, CVE-2010-2238)\n\nIt was discovered that libvirt would create new VMs without setting a\nbacking store format. A privileged attacker in the guest could exploit this\nto read arbitrary files on the host. This issue did not affect Ubuntu 8.04\nLTS. In Ubuntu 9.10 and later guests are confined by an AppArmor profile\nwhich provided partial protection against this flaw. (CVE-2010-2239)\n\nJeremy Nickurak discovered that libvirt created iptables rules with too\nlenient mappings of source ports. A privileged attacker in the guest could\nbypass intended restrictions to access privileged resources on the host.\n(CVE-2010-2242)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libvirt","version":"0.4.0-2ubuntu8.3","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.4.0-2ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.4.0-2ubuntu8.3"},{"name":"libvirt-bin","version":"0.4.0-2ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.4.0-2ubuntu8.3"}],"lucid":[{"name":"libvirt","version":"0.7.5-5ubuntu27.5","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.7.5-5ubuntu27.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.5-5ubuntu27.5"},{"name":"libvirt-bin","version":"0.7.5-5ubuntu27.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.5-5ubuntu27.5"}],"jaunty":[{"name":"libvirt","version":"0.6.1-0ubuntu5.2","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.6.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.6.1-0ubuntu5.2"},{"name":"libvirt-bin","version":"0.6.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.6.1-0ubuntu5.2"}],"karmic":[{"name":"libvirt","version":"0.7.0-1ubuntu13.2","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.7.0-1ubuntu13.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.0-1ubuntu13.2"},{"name":"libvirt-bin","version":"0.7.0-1ubuntu13.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.0-1ubuntu13.2"}]},"type":"USN","cves_ids":["CVE-2010-2237","CVE-2010-2238","CVE-2010-2239","CVE-2010-2242"]}]},{"id":"CVE-2010-2238","published":"2010-08-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRed Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image\nbacking stores without extracting the defined disk backing-store format,\nwhich might allow guest OS users to read arbitrary files on the host OS,\nand possibly have unspecified other impact, via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"AppArmor in Ubuntu 10.04 should mostly protect the host OS, but\nan attacker in a virtual machine may be able to access files of another\nmachine.\nupstream patch is highly intrusive, needs rewriting for all affected\nreleases, requires a conffile change and a migration helper.\nUbuntu 10.04 LTS is the first release to probe the backing stores\nthe changes for CVE-2010-2238 introduced LP: #665531. Upstream has\nstated that \"\" was only accidentally\nsupported and that they do not intend to fix it. Since this used to work on\n10.04 LTS and a number of people were affected, a fix will be issued for\n10.04 LTS only. Libvirt 0.8.3 (in Ubuntu 10.10) will not support specifying\ntype='host_device'. The discussion can be seen on the libvirt mailing."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1008-1","https://www.redhat.com/archives/libvir-list/2010-November/msg00276.html","https://ubuntu.com/security/notices/USN-1008-4","https://www.cve.org/CVERecord?id=CVE-2010-2238"],"bugs":["https://launchpad.net/bugs/665531"],"patches":{"libvirt":[]},"tags":{"libvirt":["apparmor"]},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.7.5-5ubuntu27.5","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.8.3-1ubuntu8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.3-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1008-1"],"notices":[{"id":"USN-1008-1","title":"libvirt vulnerabilities","summary":"Guest VMs could be made to circumvent security protections to access\nresources on the host.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: The previous version of libvirt on Ubuntu 10.04 LTS would probe\na qemu disk to determine its format and did not require that the format be\ndeclared in the XML. This is considered a security problem in most\ndeployments and this version of libvirt will default to the 'raw' format\nwhen the format is not specified in the XML. As a result, non-raw disks\nwithout a specified disk format will no longer be available in existing\nvirtual machines.\n\nThe libvirt-migrate-qemu-disks tool is provided to aid in transitioning\nvirtual machine definitions to the new required format. In essence, it will\ncheck all domains for affected virtual machines, probe the affected disks\nand update the domain definition accordingly. This command will be run\nautomatically on upgrade. For new virtual machines using non-raw images,\nthe disk format must be specified in the domain XML provided to libvirt,\notherwise the disk will not be available to the virtual machine. See man 1\nlibvirt-migrate-qemu-disks for details.\n\nUsers who require the old behavior can adjust the 'allow_disk_format_probing'\noption in /etc/libvirt/qemu.conf.\n","references":[],"published":"2010-10-21T22:20:53.013023","description":"It was discovered that libvirt would probe disk backing stores without\nconsulting the defined format for the disk. A privileged attacker in the\nguest could exploit this to read arbitrary files on the host. This issue\nonly affected Ubuntu 10.04 LTS. By default, guests are confined by an\nAppArmor profile which provided partial protection against this flaw.\n(CVE-2010-2237, CVE-2010-2238)\n\nIt was discovered that libvirt would create new VMs without setting a\nbacking store format. A privileged attacker in the guest could exploit this\nto read arbitrary files on the host. This issue did not affect Ubuntu 8.04\nLTS. In Ubuntu 9.10 and later guests are confined by an AppArmor profile\nwhich provided partial protection against this flaw. (CVE-2010-2239)\n\nJeremy Nickurak discovered that libvirt created iptables rules with too\nlenient mappings of source ports. A privileged attacker in the guest could\nbypass intended restrictions to access privileged resources on the host.\n(CVE-2010-2242)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libvirt","version":"0.4.0-2ubuntu8.3","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.4.0-2ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.4.0-2ubuntu8.3"},{"name":"libvirt-bin","version":"0.4.0-2ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.4.0-2ubuntu8.3"}],"lucid":[{"name":"libvirt","version":"0.7.5-5ubuntu27.5","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.7.5-5ubuntu27.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.5-5ubuntu27.5"},{"name":"libvirt-bin","version":"0.7.5-5ubuntu27.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.5-5ubuntu27.5"}],"jaunty":[{"name":"libvirt","version":"0.6.1-0ubuntu5.2","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.6.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.6.1-0ubuntu5.2"},{"name":"libvirt-bin","version":"0.6.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.6.1-0ubuntu5.2"}],"karmic":[{"name":"libvirt","version":"0.7.0-1ubuntu13.2","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.7.0-1ubuntu13.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.0-1ubuntu13.2"},{"name":"libvirt-bin","version":"0.7.0-1ubuntu13.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.0-1ubuntu13.2"}]},"type":"USN","cves_ids":["CVE-2010-2237","CVE-2010-2238","CVE-2010-2239","CVE-2010-2242"]}]},{"id":"CVE-2010-2237","published":"2010-08-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRed Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores\nwithout referring to the user-defined main disk format, which might allow\nguest OS users to read arbitrary files on the host OS, and possibly have\nunspecified other impact, via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"AppArmor 10.04 should mostly protect the host OS, but an attacker in\na virtual machine may be able to access files of another machine.\nupstream patch is highly intrusive, needs rewriting for all affected\nreleases, requires a conffile change and a migration helper.\nUbuntu 10.04 LTS is the first release to probe the backing stores"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1008-1","https://www.cve.org/CVERecord?id=CVE-2010-2237"],"bugs":[""],"patches":{"libvirt":[]},"tags":{"libvirt":["apparmor"]},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.7.5-5ubuntu27.5","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.8.3-1ubuntu8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.3-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1008-1"],"notices":[{"id":"USN-1008-1","title":"libvirt vulnerabilities","summary":"Guest VMs could be made to circumvent security protections to access\nresources on the host.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: The previous version of libvirt on Ubuntu 10.04 LTS would probe\na qemu disk to determine its format and did not require that the format be\ndeclared in the XML. This is considered a security problem in most\ndeployments and this version of libvirt will default to the 'raw' format\nwhen the format is not specified in the XML. As a result, non-raw disks\nwithout a specified disk format will no longer be available in existing\nvirtual machines.\n\nThe libvirt-migrate-qemu-disks tool is provided to aid in transitioning\nvirtual machine definitions to the new required format. In essence, it will\ncheck all domains for affected virtual machines, probe the affected disks\nand update the domain definition accordingly. This command will be run\nautomatically on upgrade. For new virtual machines using non-raw images,\nthe disk format must be specified in the domain XML provided to libvirt,\notherwise the disk will not be available to the virtual machine. See man 1\nlibvirt-migrate-qemu-disks for details.\n\nUsers who require the old behavior can adjust the 'allow_disk_format_probing'\noption in /etc/libvirt/qemu.conf.\n","references":[],"published":"2010-10-21T22:20:53.013023","description":"It was discovered that libvirt would probe disk backing stores without\nconsulting the defined format for the disk. A privileged attacker in the\nguest could exploit this to read arbitrary files on the host. This issue\nonly affected Ubuntu 10.04 LTS. By default, guests are confined by an\nAppArmor profile which provided partial protection against this flaw.\n(CVE-2010-2237, CVE-2010-2238)\n\nIt was discovered that libvirt would create new VMs without setting a\nbacking store format. A privileged attacker in the guest could exploit this\nto read arbitrary files on the host. This issue did not affect Ubuntu 8.04\nLTS. In Ubuntu 9.10 and later guests are confined by an AppArmor profile\nwhich provided partial protection against this flaw. (CVE-2010-2239)\n\nJeremy Nickurak discovered that libvirt created iptables rules with too\nlenient mappings of source ports. A privileged attacker in the guest could\nbypass intended restrictions to access privileged resources on the host.\n(CVE-2010-2242)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libvirt","version":"0.4.0-2ubuntu8.3","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.4.0-2ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.4.0-2ubuntu8.3"},{"name":"libvirt-bin","version":"0.4.0-2ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.4.0-2ubuntu8.3"}],"lucid":[{"name":"libvirt","version":"0.7.5-5ubuntu27.5","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.7.5-5ubuntu27.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.5-5ubuntu27.5"},{"name":"libvirt-bin","version":"0.7.5-5ubuntu27.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.5-5ubuntu27.5"}],"jaunty":[{"name":"libvirt","version":"0.6.1-0ubuntu5.2","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.6.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.6.1-0ubuntu5.2"},{"name":"libvirt-bin","version":"0.6.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.6.1-0ubuntu5.2"}],"karmic":[{"name":"libvirt","version":"0.7.0-1ubuntu13.2","description":"library for interfacing with different virtualization systems","is_source":true},{"name":"libvirt0","version":"0.7.0-1ubuntu13.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.0-1ubuntu13.2"},{"name":"libvirt-bin","version":"0.7.0-1ubuntu13.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/0.7.0-1ubuntu13.2"}]},"type":"USN","cves_ids":["CVE-2010-2237","CVE-2010-2238","CVE-2010-2239","CVE-2010-2242"]}]},{"id":"CVE-2010-2934","published":"2010-08-17T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in ZNC 0.092 allow remote attackers to\ncause a denial of service (exception and daemon crash) via unknown vectors\nrelated to \"unsafe substr() calls.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2934"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=599708","https://bugs.launchpad.net/ubuntu/+source/znc/+bug/1090195"],"patches":{"znc":["upstream: http://znc.svn.sourceforge.net/viewvc/znc?view=revision&revision=2095"]},"tags":{},"packages":[{"name":"znc","source":"https://ubuntu.com/security/cve?package=znc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=znc","debian":"https://tracker.debian.org/pkg/znc","statuses":[{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.078-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.098-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.092-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2812","published":"2010-08-17T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nClient.cpp in ZNC 0.092 allows remote attackers to cause a denial of\nservice (exception and daemon crash) via a PING command that lacks an\nargument.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2812"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=599708","https://bugs.launchpad.net/ubuntu/+source/znc/+bug/1090195"],"patches":{"znc":["upstream: http://znc.svn.sourceforge.net/viewvc/znc?view=revision&revision=2093"]},"tags":{},"packages":[{"name":"znc","source":"https://ubuntu.com/security/cve?package=znc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=znc","debian":"https://tracker.debian.org/pkg/znc","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.078-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.098-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.092-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1516","published":"2010-08-17T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in SWFTools 0.9.1 allow remote attackers to\nexecute arbitrary code via (1) a crafted PNG file, related to the getPNG\nfunction in lib/png.c; or (2) a crafted JPEG file, related to the jpeg_load\nfunction in lib/jpeg.c.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"ignoring this, upstream needs to fix in partner."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1516"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1870","published":"2010-08-17T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe OGNL extensive expression evaluation capability in XWork in Struts\n2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly\nother products, uses a permissive whitelist, which allows remote attackers\nto modify server-side context objects and bypass the \"#\" protection\nmechanism in ParameterInterceptors via the (1) #context, (2)\n#_memberAccess, (3) #root, (4) #this, (5) #_typeResolver, (6)\n#_classResolver, (7) #_traceEvaluations, (8) #_lastEvaluation, (9)\n#_keepLastEvaluation, and possibly other OGNL context variables, a\ndifferent vulnerability than CVE-2008-6504.","ubuntu_description":"\n sbeattie> we do not have struts2 in the archive (yet)","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1870"],"bugs":[""],"patches":{"libstruts1.2-java":[]},"tags":{},"packages":[{"name":"libstruts1.2-java","source":"https://ubuntu.com/security/cve?package=libstruts1.2-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libstruts1.2-java","debian":"https://tracker.debian.org/pkg/libstruts1.2-java","statuses":[{"release_codename":"dapper","status":"not-affected","description":"1.2.9-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.2.9-3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.2.9-3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.2.9-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.9-3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2939","published":"2010-08-17T00:00:00","updated_at":"2025-08-04T19:23:52.278537+00:00","description":"\nDouble free vulnerability in the ssl3_get_key_exchange function in the\nOpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and\npossibly other versions, when using ECDH, allows context-dependent\nattackers to cause a denial of service (crash) and possibly execute\narbitrary code via a crafted private key with an invalid prime. NOTE: some\nsources refer to this as a use-after-free issue.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"possibly stopped by glibc's double-free heap protection,\nCVE asserts that it's needed in 0.9.7, though the referenced\nemail from solar designer claims that it's not needed in 0.9.7 as\nECDH hadn't been introduced yet as of openssl 0.9.7m."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1003-1","https://www.cve.org/CVERecord?id=CVE-2010-2939"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=594415"],"patches":{"openssl":["upstream: http://www.mail-archive.com/openssl-dev@openssl.org/msg28049.html"],"openssl097":[]},"tags":{"openssl":["heap-protector"]},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"dapper","status":"released","description":"0.9.8a-7ubuntu0.13","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.9.8g-4ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.9.8g-15ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.9.8g-16ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.9.8k-7ubuntu8.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl097","source":"https://ubuntu.com/security/cve?package=openssl097","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl097","debian":"https://tracker.debian.org/pkg/openssl097","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1003-1"],"notices":[{"id":"USN-1003-1","title":"OpenSSL vulnerabilities","summary":"","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2010-10-07T14:46:34.282164","description":"It was discovered that OpenSSL incorrectly handled return codes from the\nbn_wexpand function calls. A remote attacker could trigger this flaw in\nservices that used SSL to cause a denial of service or possibly execute\narbitrary code with application privileges. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2009-3245)\n\nIt was discovered that OpenSSL incorrectly handled certain private keys\nwith an invalid prime. A remote attacker could trigger this flaw in\nservices that used SSL to cause a denial of service or possibly execute\narbitrary code with application privileges. The default compiler options\nfor affected releases should reduce the vulnerability to a denial of\nservice. (CVE-2010-2939)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"openssl","version":"0.9.8k-7ubuntu8.3","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8k-7ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8k-7ubuntu8.3"}],"karmic":[{"name":"openssl","version":"0.9.8g-16ubuntu3.3","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-16ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-16ubuntu3.3"}],"hardy":[{"name":"openssl","version":"0.9.8g-4ubuntu3.11","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-4ubuntu3.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-4ubuntu3.11"}],"dapper":[{"name":"openssl","version":"0.9.8a-7ubuntu0.13","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8a-7ubuntu0.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8a-7ubuntu0.13"}],"maverick":[{"name":"openssl","version":"0.9.8o-1ubuntu4.1","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8o-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8o-1ubuntu4.1"}],"jaunty":[{"name":"openssl","version":"0.9.8g-15ubuntu3.6","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-15ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-15ubuntu3.6"}]},"type":"USN","cves_ids":["CVE-2009-3245","CVE-2010-2939"]}]},{"id":"CVE-2010-2783","published":"2010-08-17T00:00:00","updated_at":"2025-08-25T19:58:50.871596+00:00","description":"\nIcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary\nfiles, related to Extended JNLP Services.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-971-1","https://www.cve.org/CVERecord?id=CVE-2010-2783"],"bugs":[""],"patches":{"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.1-0ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b18-1.8.1-0ubuntu1~9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6b18-1.8.1-0ubuntu1~9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b18-1.8.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-971-1"],"notices":[{"id":"USN-971-1","title":"OpenJDK vulnerabilities","summary":"Exposed arbitrary file contents to remote systems.\n","instructions":"After a standard system update you need to restart any Java applications\nto make all the necessary changes.\n","references":[],"published":"2010-08-16T15:09:11.504079","description":"It was discovered that the IcedTea plugin did not correctly check certain\naccesses. If a user or automated system were tricked into running a\nspecially crafted Java applet, a remote attacker could read arbitrary\nfiles with user privileges, leading to a loss of privacy. (CVE-2010-2548,\nCVE-2010-2783)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"openjdk-6","version":"6b18-1.8.1-0ubuntu1","description":"Java Virtual Machine","is_source":true},{"name":"icedtea6-plugin","version":"6b18-1.8.1-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b18-1.8.1-0ubuntu1"}],"jaunty":[{"name":"openjdk-6","version":"6b18-1.8.1-0ubuntu1~9.04.1","description":"Java Virtual Machine","is_source":true},{"name":"icedtea6-plugin","version":"6b18-1.8.1-0ubuntu1~9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b18-1.8.1-0ubuntu1~9.04.1"}],"karmic":[{"name":"openjdk-6","version":"6b18-1.8.1-0ubuntu1~9.10.1","description":"Java Virtual Machine","is_source":true},{"name":"icedtea6-plugin","version":"6b18-1.8.1-0ubuntu1~9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b18-1.8.1-0ubuntu1~9.10.1"}]},"type":"USN","cves_ids":["CVE-2010-2548","CVE-2010-2783"]}]},{"id":"CVE-2010-2548","published":"2010-08-17T00:00:00","updated_at":"2025-08-25T19:58:31.312507+00:00","description":"\nIcedTea6 before 1.7.4 does not properly check property access, which allows\nunsigned apps to read and write arbitrary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-971-1","https://www.cve.org/CVERecord?id=CVE-2010-2548"],"bugs":[""],"patches":{"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.1-0ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b18-1.8.1-0ubuntu1~9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6b18-1.8.1-0ubuntu1~9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b18-1.8.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-971-1"],"notices":[{"id":"USN-971-1","title":"OpenJDK vulnerabilities","summary":"Exposed arbitrary file contents to remote systems.\n","instructions":"After a standard system update you need to restart any Java applications\nto make all the necessary changes.\n","references":[],"published":"2010-08-16T15:09:11.504079","description":"It was discovered that the IcedTea plugin did not correctly check certain\naccesses. If a user or automated system were tricked into running a\nspecially crafted Java applet, a remote attacker could read arbitrary\nfiles with user privileges, leading to a loss of privacy. (CVE-2010-2548,\nCVE-2010-2783)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"openjdk-6","version":"6b18-1.8.1-0ubuntu1","description":"Java Virtual Machine","is_source":true},{"name":"icedtea6-plugin","version":"6b18-1.8.1-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b18-1.8.1-0ubuntu1"}],"jaunty":[{"name":"openjdk-6","version":"6b18-1.8.1-0ubuntu1~9.04.1","description":"Java Virtual Machine","is_source":true},{"name":"icedtea6-plugin","version":"6b18-1.8.1-0ubuntu1~9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b18-1.8.1-0ubuntu1~9.04.1"}],"karmic":[{"name":"openjdk-6","version":"6b18-1.8.1-0ubuntu1~9.10.1","description":"Java Virtual Machine","is_source":true},{"name":"icedtea6-plugin","version":"6b18-1.8.1-0ubuntu1~9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b18-1.8.1-0ubuntu1~9.10.1"}]},"type":"USN","cves_ids":["CVE-2010-2548","CVE-2010-2783"]}]},{"id":"CVE-2010-2240","published":"2010-08-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe do_anonymous_page function in mm/memory.c in the Linux kernel before\n2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and\n2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap,\nwhich allows context-dependent attackers to execute arbitrary code by\nwriting to the bottom page of a shared memory segment, as demonstrated by a\nmemory-exhaustion attack against the X.Org X server.","ubuntu_description":"\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server.","notes":[{"author":"smb","note":"There seem to be three follow-up patches upstream (one of them is not\nCCed to stable, but should be (gets fixed up actually))."},{"author":"jdstrand","note":"caused regression in Xen on hardy"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.invisiblethingslab.com/resources/misc-2010/xorg-large-memory-attacks.pdf","https://ubuntu.com/security/notices/USN-974-1","https://ubuntu.com/security/notices/USN-974-2","https://ubuntu.com/security/notices/USN-1074-1","https://www.cve.org/CVERecord?id=CVE-2010-2240"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/linux/+bug/620994"],"patches":{"linux-source-2.6.15":["dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/dapper/linux/0001-mm-keep-a-guard-page-below-a-grow-down-stack-segment.txt","dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/dapper/linux/0002-mm-fix-missing-page-table-unmap-for-stack-guard-page-f.txt","dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/dapper/linux/0003-mm-fix-page-table-unmap-for-stack-guard-page-properly.txt","dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/dapper/linux/0004-mm-fix-up-some-user-visible-effects-of-the-stack-guard.txt","dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/dapper/linux/0005-x86-don-t-send-SIGBUS-for-kernel-page-faults.txt","dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/dapper/linux/0006-mm-pass-correct-mm-when-growing-stack.txt"],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=320b2b8de12698082609ebbc1a17165727f4c893","upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=5528f9132cf65d4d892bcbc5684c61e7822b21e9","upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=11ac552477e32835cb6970bf0a70c210807f5673","upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=d7824370e26325c881b665350ce64fb0a4fde24a","upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=96054569190bdec375fe824e48ca1f4e3b53dd36","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/hardy/linux/0001-mm-keep-a-guard-page-below-a-grow-down-stack-segment.txt","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/hardy/linux/0002-mm-fix-missing-page-table-unmap-for-stack-guard-page-f.txt","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/hardy/linux/0003-mm-fix-page-table-unmap-for-stack-guard-page-properly.txt","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/hardy/linux/0004-mm-fix-up-some-user-visible-effects-of-the-stack-guard.txt","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/hardy/linux/0005-x86-don-t-send-SIGBUS-for-kernel-page-faults.txt","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/hardy/linux/0006-mm-pass-correct-mm-when-growing-stack.txt","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/hardy/linux/0007-OPENVZ-Fixup-patches-to-memory.c-and-mlock.c.txt","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/jaunty/linux/0001-mm-keep-a-guard-page-below-a-grow-down-stack-segment.txt","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/jaunty/linux/0002-mm-fix-missing-page-table-unmap-for-stack-guard-page-f.txt","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/jaunty/linux/0003-mm-fix-page-table-unmap-for-stack-guard-page-properly.txt","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/jaunty/linux/0004-mm-fix-up-some-user-visible-effects-of-the-stack-guard.txt","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/jaunty/linux/0005-x86-don-t-send-SIGBUS-for-kernel-page-faults.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/karmic/linux/0001-mm-keep-a-guard-page-below-a-grow-down-stack-segment.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/karmic/linux/0002-mm-fix-missing-page-table-unmap-for-stack-guard-page-f.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/karmic/linux/0003-mm-fix-page-table-unmap-for-stack-guard-page-properly.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/karmic/linux/0004-mm-fix-up-some-user-visible-effects-of-the-stack-guard.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/karmic/linux/0005-x86-don-t-send-SIGBUS-for-kernel-page-faults.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/lucid/linux/0001-mm-keep-a-guard-page-below-a-grow-down-stack-segment.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/lucid/linux/0002-mm-fix-missing-page-table-unmap-for-stack-guard-page-f.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/lucid/linux/0003-mm-fix-page-table-unmap-for-stack-guard-page-properly.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/lucid/linux/0004-mm-fix-up-some-user-visible-effects-of-the-stack-guard.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2240/patches/lucid/linux/0005-x86-don-t-send-SIGBUS-for-kernel-page-faults.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-mvl-dove":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.75","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.64","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.63","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-24.41","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-16.22","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.17","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-308.15","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.19","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-214.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-208.24","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.87","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-974-1","USN-1074-1"],"notices":[{"id":"USN-974-1","title":"Linux kernel vulnerabilities","summary":"The Linux kernel could be made to crash or run programs as root.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2010-08-19T22:12:07.989033","description":"Gael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CAN) subsystem when setting up frame content and filtering certain\nmessages. An attacker could send specially crafted CAN traffic to crash the\nsystem or gain root privileges. (CVE-2010-2959)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.30","description":"The Linux kernel for Marvell Dove","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.17","description":"The Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.63","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.17","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.17"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.30"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.63"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.30"}],"hardy":[{"name":"linux","version":"2.6.24-28.75","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.75"}],"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-208.24","description":"The Linux kernel for Marvell Dove","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-608.19","description":"The Linux kernel for I.MX51-based systems","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-502.10","description":"The Linux kernel for OMAP3-based systems","is_source":true},{"name":"linux-ec2","version":"2.6.32-308.15","description":"The Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-24.41","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.33-502-omap","version":"2.6.33-502.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-502.10"},{"name":"linux-image-2.6.32-308-ec2","version":"2.6.32-308.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-308.15"},{"name":"linux-image-2.6.32-24-386","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-powerpc","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-powerpc64-smp","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-generic-pae","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-versatile","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-generic","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-virtual","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-server","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-ia64","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-sparc64-smp","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-preempt","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-powerpc-smp","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-sparc64","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-24-lpia","version":"2.6.32-24.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.41"},{"name":"linux-image-2.6.32-208-dove","version":"2.6.32-208.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-208.24"},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.19"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.87","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.87"}],"jaunty":[{"name":"linux","version":"2.6.28-19.64","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.64"}]},"type":"USN","cves_ids":["CVE-2010-2240","CVE-2010-2803","CVE-2010-2959"]},{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2009-4269","published":"2010-08-16T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe password hash generation algorithm in the BUILTIN authentication\nfunctionality for Apache Derby before 10.6.1.0 performs a transformation\nthat reduces the size of the set of inputs to SHA-1, which produces a small\nsearch space that makes it easier for local and possibly remote attackers\nto crack passwords by generating hash collisions, related to password\nsubstitution.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"ignoring this CVE for esm-apps/xenial because we don't have\nplans to fix this."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blogs.sun.com/kah/entry/derby_10_6_1_has","https://www.cve.org/CVERecord?id=CVE-2009-4269"],"bugs":[""],"patches":{"sun-javadb":[]},"tags":{},"packages":[{"name":"sun-javadb","source":"https://ubuntu.com/security/cve?package=sun-javadb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-javadb","debian":"https://tracker.debian.org/pkg/sun-javadb","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.6.1.0","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2759","published":"2010-08-16T15:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1,\nand 3.7 through 3.7.2, when PostgreSQL is used, does not properly handle\nlarge integers in (1) bug and (2) attachment phrases, which allows remote\nauthenticated users to cause a denial of service (bug invisibility) via a\ncrafted comment.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2759"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.7.3, 3.6.2, 3.4.8, 3.2.8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2758","published":"2010-08-16T15:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1,\nand 3.7 through 3.7.2 generates different error messages depending on\nwhether a product exists, which makes it easier for remote attackers to\nguess product names via unspecified use of the (1) Reports or (2)\nDuplicates page.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2758"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.7.3, 3.6.2, 3.4.8, 3.2.8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2757","published":"2010-08-16T15:14:00","updated_at":"2025-07-17T16:42:31.366623+00:00","description":"\nThe sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7,\n3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send\nimpersonation notifications, which makes it easier for remote authenticated\nusers to impersonate other users without discovery.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2757"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.7.3, 3.6.2, 3.4.8, 3.2.8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2756","published":"2010-08-16T15:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSearch.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1\nthrough 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine\nthe group memberships of arbitrary users via vectors involving the Search\ninterface, boolean charts, and group-based pronouns.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2756"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.6.2.0-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.7.3, 3.6.1, 3.4.7, 3.2.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1519","published":"2010-08-16T15:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in glpng.c in glpng 1.45 allow context-dependent\nattackers to execute arbitrary code via a crafted PNG image, related to (1)\nthe pngLoadRawF function and (2) the pngLoadF function, leading to\nheap-based buffer overflows.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1519"],"bugs":[""],"patches":{"libglpng":[]},"tags":{},"packages":[{"name":"libglpng","source":"https://ubuntu.com/security/cve?package=libglpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libglpng","debian":"https://tracker.debian.org/pkg/libglpng","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":72480,"limit":20,"total_results":79316}