{"cves":[{"id":"CVE-2010-1669","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in Mahara 1.1.x before 1.1.9 and 1.2.x before\n1.2.5 allows remote attackers to execute arbitrary SQL commands via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://wiki.mahara.org/Release_Notes/1.1.9","http://wiki.mahara.org/Release_Notes/1.2.5","https://www.cve.org/CVERecord?id=CVE-2010-1669"],"bugs":[""],"patches":{"mahara":["debdiff: https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/602772"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.5-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.9,1.2.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1668","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site request forgery (CSRF) vulnerabilities in Mahara before\n1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers\nto hijack the authentication of unspecified victims via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://wiki.mahara.org/Release_Notes/1.0.15","http://wiki.mahara.org/Release_Notes/1.1.9","http://wiki.mahara.org/Release_Notes/1.2.5","https://www.cve.org/CVERecord?id=CVE-2010-1668"],"bugs":[""],"patches":{"mahara":["debdiff: https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/602772"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.9-2ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.5-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.15,1.1.9,1.2.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1667","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Mahara before\n1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers\nto inject arbitrary web script or HTML via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://wiki.mahara.org/Release_Notes/1.2.5","http://wiki.mahara.org/Release_Notes/1.1.9","http://wiki.mahara.org/Release_Notes/1.0.15","https://www.cve.org/CVERecord?id=CVE-2010-1667"],"bugs":[""],"patches":{"mahara":["debdiff: https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/602772"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.9-2ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.5-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.15,1.1.9,1.2.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2651","published":"2010-07-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Cascading Style Sheets (CSS) implementation in Google Chrome before\n5.0.375.99 does not properly perform style rendering, which allows remote\nattackers to cause a denial of service (memory corruption) or possibly have\nunspecified other impact via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html","https://ubuntu.com/security/notices/USN-1195-1","https://www.cve.org/CVERecord?id=CVE-2010-2651"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=46360"],"patches":{"chromium-browser":[],"webkit":[],"webkitgtk":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.1271.97-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"5.0.375.99~r51029-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.1271.97-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.1271.97-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.0.1271.97-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.99","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.7-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.7-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":["USN-1195-1"],"notices":[{"id":"USN-1195-1","title":"WebKit vulnerabilities","summary":"Multiple security vulnerabilities were fixed in WebKit.\n","instructions":"After a standard system update you need to restart any applications that\nuse WebKit, such as Epiphany and Midori, to make all the necessary changes.\n","references":[],"published":"2011-08-23T07:30:12.299135","description":"A large number of security issues were discovered in the WebKit browser and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of\nservice attacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"webkit","version":"1.2.7-0ubuntu0.10.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libwebkit-1.0-2","version":"1.2.7-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit","version_link":"https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.04.1"}],"maverick":[{"name":"webkit","version":"1.2.7-0ubuntu0.10.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libwebkit-1.0-2","version":"1.2.7-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit","version_link":"https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.10.1"}]},"type":"USN","cves_ids":["CVE-2010-1824","CVE-2010-2646","CVE-2010-2651","CVE-2010-2900","CVE-2010-2901","CVE-2010-3120","CVE-2010-3254","CVE-2010-3812","CVE-2010-3813","CVE-2010-4040","CVE-2010-4042","CVE-2010-4197","CVE-2010-4198","CVE-2010-4199","CVE-2010-4204","CVE-2010-4206","CVE-2010-4492","CVE-2010-4493","CVE-2010-4577","CVE-2010-4578","CVE-2011-0482","CVE-2011-0778"]}]},{"id":"CVE-2010-2646","published":"2010-07-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME\nelements, which has unspecified impact and remote attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html","https://ubuntu.com/security/notices/USN-1195-1","https://www.cve.org/CVERecord?id=CVE-2010-2646"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=42980","http://code.google.com/p/chromium/issues/detail?id=42575"],"patches":{"chromium-browser":[],"webkit":[],"webkitgtk":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.1271.97-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"5.0.375.99~r51029-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.1271.97-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.1271.97-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.0.1271.97-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.99","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.7-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.7-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":["USN-1195-1"],"notices":[{"id":"USN-1195-1","title":"WebKit vulnerabilities","summary":"Multiple security vulnerabilities were fixed in WebKit.\n","instructions":"After a standard system update you need to restart any applications that\nuse WebKit, such as Epiphany and Midori, to make all the necessary changes.\n","references":[],"published":"2011-08-23T07:30:12.299135","description":"A large number of security issues were discovered in the WebKit browser and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of\nservice attacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"webkit","version":"1.2.7-0ubuntu0.10.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libwebkit-1.0-2","version":"1.2.7-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit","version_link":"https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.04.1"}],"maverick":[{"name":"webkit","version":"1.2.7-0ubuntu0.10.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libwebkit-1.0-2","version":"1.2.7-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit","version_link":"https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.10.1"}]},"type":"USN","cves_ids":["CVE-2010-1824","CVE-2010-2646","CVE-2010-2651","CVE-2010-2900","CVE-2010-2901","CVE-2010-3120","CVE-2010-3254","CVE-2010-3812","CVE-2010-3813","CVE-2010-4040","CVE-2010-4042","CVE-2010-4197","CVE-2010-4198","CVE-2010-4199","CVE-2010-4204","CVE-2010-4206","CVE-2010-4492","CVE-2010-4493","CVE-2010-4577","CVE-2010-4578","CVE-2011-0482","CVE-2011-0778"]}]},{"id":"CVE-2010-2630","published":"2010-07-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate\nthe data types of codec-specific tags that have an out-of-order position in\na TIFF file, which allows remote attackers to cause a denial of service\n(application crash) via a crafted file, a different vulnerability than\nCVE-2010-2481.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same reproducer as CVE-2010-2481\nfixes regression in CVE-2010-2481 patch"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1085-1","https://www.cve.org/CVERecord?id=CVE-2010-2630"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=554371","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2630","http://bugzilla.maptools.org/show_bug.cgi?id=2210"],"patches":{"tiff":["upstream: r1.92.2.13"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"released","description":"3.7.4-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.8.2-7ubuntu3.7","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.8.2-13ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.9.4-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1085-1"],"notices":[{"id":"USN-1085-1","title":"tiff vulnerabilities","summary":"Certain applications could be made to run programs as your login if they\nopened a specially crafted TIFF file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2011-03-07T15:26:24.073766","description":"Sauli Pahlman discovered that the TIFF library incorrectly handled invalid\ntd_stripbytecount fields. If a user or automated system were tricked into\nopening a specially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. This issue only affected\nUbuntu 10.04 LTS and 10.10. (CVE-2010-2482)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled TIFF\nfiles with an invalid combination of SamplesPerPixel and Photometric\nvalues. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could crash the application, leading\nto a denial of service. This issue only affected Ubuntu 10.10.\n(CVE-2010-2482)\n\nNicolae Ghimbovschi discovered that the TIFF library incorrectly handled\ninvalid ReferenceBlackWhite values. If a user or automated system were\ntricked into opening a specially crafted TIFF image, a remote attacker\ncould crash the application, leading to a denial of service.\n(CVE-2010-2595)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled certain\ndefault fields. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2597, CVE-2010-2598)\n\nIt was discovered that the TIFF library incorrectly validated certain\ndata types. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2630)\n\nIt was discovered that the TIFF library incorrectly handled downsampled\nJPEG data. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. This issue only affected Ubuntu 10.04 LTS and 10.10.\n(CVE-2010-3087)\n\nIt was discovered that the TIFF library incorrectly handled certain JPEG\ndata. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could execute arbitrary code with\nuser privileges, or crash the application, leading to a denial of service.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS and 9.10.\n(CVE-2011-0191)\n\nIt was discovered that the TIFF library incorrectly handled certain TIFF\nFAX images. If a user or automated system were tricked into opening a\nspecially crafted TIFF FAX image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. (CVE-2011-0191)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"tiff","version":"3.8.2-7ubuntu3.7","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-7ubuntu3.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-7ubuntu3.7"}],"lucid":[{"name":"tiff","version":"3.9.2-2ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.2-2ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.4"}],"maverick":[{"name":"tiff","version":"3.9.4-2ubuntu0.1","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.4-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.1"}],"dapper":[{"name":"tiff","version":"3.7.4-1ubuntu3.9","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.7.4-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.7.4-1ubuntu3.9"}],"karmic":[{"name":"tiff","version":"3.8.2-13ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-13ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-13ubuntu0.4"}]},"type":"USN","cves_ids":["CVE-2010-3087","CVE-2011-0192","CVE-2010-2630","CVE-2010-2598","CVE-2010-2483","CVE-2010-2482","CVE-2010-2595","CVE-2010-2597","CVE-2011-0191"]}]},{"id":"CVE-2010-2483","published":"2010-07-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers to\ncause a denial of service (out-of-bounds read and application crash) via a\nTIFF file with an invalid combination of SamplesPerPixel and Photometric\nvalues.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"code not present in karmic and earlier\nthis is patch fix-ycbcr-oob-read.patch in natty"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1085-1","https://www.cve.org/CVERecord?id=CVE-2010-2483"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2216","https://bugzilla.redhat.com/show_bug.cgi?id=603081","https://bugs.launchpad.net/ubuntu/+source/tiff/+bug/591605"],"patches":{"tiff":["upstream: r1.63.2.5"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"not-affected","description":"3.7.4-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"3.8.2-7ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.8.2-13ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.9.4-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1085-1"],"notices":[{"id":"USN-1085-1","title":"tiff vulnerabilities","summary":"Certain applications could be made to run programs as your login if they\nopened a specially crafted TIFF file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2011-03-07T15:26:24.073766","description":"Sauli Pahlman discovered that the TIFF library incorrectly handled invalid\ntd_stripbytecount fields. If a user or automated system were tricked into\nopening a specially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. This issue only affected\nUbuntu 10.04 LTS and 10.10. (CVE-2010-2482)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled TIFF\nfiles with an invalid combination of SamplesPerPixel and Photometric\nvalues. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could crash the application, leading\nto a denial of service. This issue only affected Ubuntu 10.10.\n(CVE-2010-2482)\n\nNicolae Ghimbovschi discovered that the TIFF library incorrectly handled\ninvalid ReferenceBlackWhite values. If a user or automated system were\ntricked into opening a specially crafted TIFF image, a remote attacker\ncould crash the application, leading to a denial of service.\n(CVE-2010-2595)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled certain\ndefault fields. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2597, CVE-2010-2598)\n\nIt was discovered that the TIFF library incorrectly validated certain\ndata types. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2630)\n\nIt was discovered that the TIFF library incorrectly handled downsampled\nJPEG data. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. This issue only affected Ubuntu 10.04 LTS and 10.10.\n(CVE-2010-3087)\n\nIt was discovered that the TIFF library incorrectly handled certain JPEG\ndata. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could execute arbitrary code with\nuser privileges, or crash the application, leading to a denial of service.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS and 9.10.\n(CVE-2011-0191)\n\nIt was discovered that the TIFF library incorrectly handled certain TIFF\nFAX images. If a user or automated system were tricked into opening a\nspecially crafted TIFF FAX image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. (CVE-2011-0191)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"tiff","version":"3.8.2-7ubuntu3.7","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-7ubuntu3.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-7ubuntu3.7"}],"lucid":[{"name":"tiff","version":"3.9.2-2ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.2-2ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.4"}],"maverick":[{"name":"tiff","version":"3.9.4-2ubuntu0.1","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.4-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.1"}],"dapper":[{"name":"tiff","version":"3.7.4-1ubuntu3.9","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.7.4-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.7.4-1ubuntu3.9"}],"karmic":[{"name":"tiff","version":"3.8.2-13ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-13ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-13ubuntu0.4"}]},"type":"USN","cves_ids":["CVE-2010-3087","CVE-2011-0192","CVE-2010-2630","CVE-2010-2598","CVE-2010-2483","CVE-2010-2482","CVE-2010-2595","CVE-2010-2597","CVE-2011-0191"]}]},{"id":"CVE-2010-2482","published":"2010-07-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nLibTIFF 3.9.4 and earlier does not properly handle an invalid\ntd_stripbytecount field, which allows remote attackers to cause a denial of\nservice (NULL pointer dereference and application crash) via a crafted TIFF\nfile, a different vulnerability than CVE-2010-2443.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"does not reproduce on karmic and older, and code is different"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1085-1","https://www.cve.org/CVERecord?id=CVE-2010-2482"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=1996","https://bugzilla.redhat.com/show_bug.cgi?id=608010","https://bugzilla.redhat.com/show_bug.cgi?id=603024","https://bugs.launchpad.net/bugs/597246"],"patches":{"tiff":["upstream: r1.24.2.7, r1.14.2.5"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"not-affected","description":"3.7.4-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"3.8.2-7ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.8.2-13ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.9.4-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1085-1"],"notices":[{"id":"USN-1085-1","title":"tiff vulnerabilities","summary":"Certain applications could be made to run programs as your login if they\nopened a specially crafted TIFF file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2011-03-07T15:26:24.073766","description":"Sauli Pahlman discovered that the TIFF library incorrectly handled invalid\ntd_stripbytecount fields. If a user or automated system were tricked into\nopening a specially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. This issue only affected\nUbuntu 10.04 LTS and 10.10. (CVE-2010-2482)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled TIFF\nfiles with an invalid combination of SamplesPerPixel and Photometric\nvalues. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could crash the application, leading\nto a denial of service. This issue only affected Ubuntu 10.10.\n(CVE-2010-2482)\n\nNicolae Ghimbovschi discovered that the TIFF library incorrectly handled\ninvalid ReferenceBlackWhite values. If a user or automated system were\ntricked into opening a specially crafted TIFF image, a remote attacker\ncould crash the application, leading to a denial of service.\n(CVE-2010-2595)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled certain\ndefault fields. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2597, CVE-2010-2598)\n\nIt was discovered that the TIFF library incorrectly validated certain\ndata types. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2630)\n\nIt was discovered that the TIFF library incorrectly handled downsampled\nJPEG data. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. This issue only affected Ubuntu 10.04 LTS and 10.10.\n(CVE-2010-3087)\n\nIt was discovered that the TIFF library incorrectly handled certain JPEG\ndata. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could execute arbitrary code with\nuser privileges, or crash the application, leading to a denial of service.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS and 9.10.\n(CVE-2011-0191)\n\nIt was discovered that the TIFF library incorrectly handled certain TIFF\nFAX images. If a user or automated system were tricked into opening a\nspecially crafted TIFF FAX image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. (CVE-2011-0191)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"tiff","version":"3.8.2-7ubuntu3.7","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-7ubuntu3.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-7ubuntu3.7"}],"lucid":[{"name":"tiff","version":"3.9.2-2ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.2-2ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.4"}],"maverick":[{"name":"tiff","version":"3.9.4-2ubuntu0.1","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.4-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.1"}],"dapper":[{"name":"tiff","version":"3.7.4-1ubuntu3.9","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.7.4-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.7.4-1ubuntu3.9"}],"karmic":[{"name":"tiff","version":"3.8.2-13ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-13ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-13ubuntu0.4"}]},"type":"USN","cves_ids":["CVE-2010-3087","CVE-2011-0192","CVE-2010-2630","CVE-2010-2598","CVE-2010-2483","CVE-2010-2482","CVE-2010-2595","CVE-2010-2597","CVE-2011-0191"]}]},{"id":"CVE-2010-2253","published":"2010-07-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlwp-download in libwww-perl before 5.835 does not reject downloads to\nfilenames that begin with a . (dot) character, which allows remote servers\nto create or overwrite files via (1) a 3xx redirect to a URL with a crafted\nfilename or (2) a Content-Disposition header that suggests a crafted\nfilename, and possibly execute arbitrary code as a consequence of writing\nto a dotfile in a home directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.ocert.org/advisories/ocert-2010-001.html","https://ubuntu.com/security/notices/USN-981-1","https://www.cve.org/CVERecord?id=CVE-2010-2253"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=602800","https://bugzilla.redhat.com/show_bug.cgi?id=591580"],"patches":{"libwww-perl":["upstream: http://github.com/gisle/libwww-perl/commit/f97f339f552666ef79cdd2cf2a44032cf206bb6e"]},"tags":{},"packages":[{"name":"libwww-perl","source":"https://ubuntu.com/security/cve?package=libwww-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libwww-perl","debian":"https://tracker.debian.org/pkg/libwww-perl","statuses":[{"release_codename":"dapper","status":"released","description":"5.803-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.808-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.820-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.831-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.834-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.835","component":null,"pocket":"security"}]}],"notices_ids":["USN-981-1"],"notices":[{"id":"USN-981-1","title":"libwww-perl vulnerability","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-08-31T13:05:39.817282","description":"It was discovered that libwww-perl incorrectly filtered filenames suggested\nby Content-Disposition headers. If a user were tricked into downloading a\nfile from a malicious site, a remote attacker could overwrite hidden files\nin the user's directory.\n","is_hidden":false,"release_packages":{"karmic":[{"name":"libwww-perl","version":"5.831-1ubuntu0.1","description":"","is_source":true},{"name":"libwww-perl","version":"5.831-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libwww-perl","version_link":"https://launchpad.net/ubuntu/+source/libwww-perl/5.831-1ubuntu0.1"}],"hardy":[{"name":"libwww-perl","version":"5.808-1ubuntu0.1","description":"","is_source":true},{"name":"libwww-perl","version":"5.808-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libwww-perl","version_link":"https://launchpad.net/ubuntu/+source/libwww-perl/5.808-1ubuntu0.1"}],"lucid":[{"name":"libwww-perl","version":"5.834-1ubuntu0.1","description":"","is_source":true},{"name":"libwww-perl","version":"5.834-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libwww-perl","version_link":"https://launchpad.net/ubuntu/+source/libwww-perl/5.834-1ubuntu0.1"}],"dapper":[{"name":"libwww-perl","version":"5.803-4ubuntu0.1","description":"","is_source":true},{"name":"libwww-perl","version":"5.803-4ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libwww-perl","version_link":"https://launchpad.net/ubuntu/+source/libwww-perl/5.803-4ubuntu0.1"}],"jaunty":[{"name":"libwww-perl","version":"5.820-1ubuntu0.1","description":"","is_source":true},{"name":"libwww-perl","version":"5.820-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libwww-perl","version_link":"https://launchpad.net/ubuntu/+source/libwww-perl/5.820-1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2010-2253"]}]},{"id":"CVE-2010-2252","published":"2010-07-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGNU Wget 1.12 and earlier uses a server-provided filename instead of the\noriginal URL to determine the destination filename of a download, which\nallows remote servers to create or overwrite arbitrary files via a 3xx\nredirect to a URL with a .wgetrc filename followed by a 3xx redirect to a\nURL with a crafted filename, and possibly execute arbitrary code as a\nconsequence of writing to a dotfile in a home directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.ocert.org/advisories/ocert-2010-001.html","http://www.debian.org/security/2010/dsa-2088","https://ubuntu.com/security/notices/USN-982-1","https://www.cve.org/CVERecord?id=CVE-2010-2252"],"bugs":["https://savannah.gnu.org/bugs/?29958","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590296","https://bugzilla.redhat.com/show_bug.cgi?id=602797","https://bugzilla.redhat.com/show_bug.cgi?id=591580"],"patches":{"wget":["upstream: http://lists.gnu.org/archive/html/bug-wget/2010-07/msg00076.html","upstream: r2409"]},"tags":{},"packages":[{"name":"wget","source":"https://ubuntu.com/security/cve?package=wget","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wget","debian":"https://tracker.debian.org/pkg/wget","statuses":[{"release_codename":"dapper","status":"released","description":"1.10.2-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.10.2-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.11.4-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.11.4-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.12-1.1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-982-1"],"notices":[{"id":"USN-982-1","title":"Wget vulnerability","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n\nATTENTION: This update changes previous behaviour by ignoring the filename\nsupplied by the server during redirects. To re-enable previous behaviour,\nuse the new --trust-server-names option.\n","references":[],"published":"2010-09-02T13:07:32.781864","description":"It was discovered that Wget would use filenames provided by the server when\nfollowing 3xx redirects. If a user or automated system were tricked into\ndownloading a file from a malicious site, a remote attacker could create\nthe file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrary\ncode.\n","is_hidden":false,"release_packages":{"karmic":[{"name":"wget","version":"1.11.4-2ubuntu2.1","description":"","is_source":true},{"name":"wget","version":"1.11.4-2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.11.4-2ubuntu2.1"}],"hardy":[{"name":"wget","version":"1.10.2-3ubuntu1.2","description":"","is_source":true},{"name":"wget","version":"1.10.2-3ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.10.2-3ubuntu1.2"}],"lucid":[{"name":"wget","version":"1.12-1.1ubuntu2.1","description":"","is_source":true},{"name":"wget","version":"1.12-1.1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.12-1.1ubuntu2.1"}],"dapper":[{"name":"wget","version":"1.10.2-1ubuntu1.2","description":"","is_source":true},{"name":"wget","version":"1.10.2-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.10.2-1ubuntu1.2"}],"jaunty":[{"name":"wget","version":"1.11.4-2ubuntu1.2","description":"","is_source":true},{"name":"wget","version":"1.11.4-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.11.4-2ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2010-2252"]}]},{"id":"CVE-2010-2251","published":"2010-07-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe get1 command, as used by lftpget, in LFTP before 4.0.6 does not\nproperly validate a server-provided filename before determining the\ndestination filename of a download, which allows remote servers to create\nor overwrite arbitrary files via a Content-Disposition header that suggests\na crafted filename, and possibly execute arbitrary code as a consequence of\nwriting to a dotfile in a home directory.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"dapper's lftp is too old to support server-suggested filenames"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.ocert.org/advisories/ocert-2010-001.html","http://www.debian.org/security/2010/dsa-2085","https://ubuntu.com/security/notices/USN-984-1","https://www.cve.org/CVERecord?id=CVE-2010-2251"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=602836","https://bugzilla.redhat.com/show_bug.cgi?id=591580"],"patches":{"lftp":[]},"tags":{},"packages":[{"name":"lftp","source":"https://ubuntu.com/security/cve?package=lftp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lftp","debian":"https://tracker.debian.org/pkg/lftp","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.6.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.7.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.7.15-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"4.0.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-984-1"],"notices":[{"id":"USN-984-1","title":"LFTP vulnerability","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n\nATTENTION: This update changes previous behaviour by ignoring the filename\nsupplied by servers in Content-Disposition headers. To re-enable previous\nbehaviour, use the new xfer:auto-rename setting.\n","references":[],"published":"2010-09-07T17:33:13.575508","description":"It was discovered that LFTP incorrectly filtered filenames suggested\nby Content-Disposition headers. If a user or automated system were tricked\ninto downloading a file from a malicious site, a remote attacker could\ncreate the file with an arbitrary name, such as a dotfile, and possibly run\narbitrary code.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"lftp","version":"3.6.1-1ubuntu0.1","description":"","is_source":true},{"name":"lftp","version":"3.6.1-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/lftp","version_link":"https://launchpad.net/ubuntu/+source/lftp/3.6.1-1ubuntu0.1"}],"lucid":[{"name":"lftp","version":"4.0.2-1ubuntu0.1","description":"","is_source":true},{"name":"lftp","version":"4.0.2-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/lftp","version_link":"https://launchpad.net/ubuntu/+source/lftp/4.0.2-1ubuntu0.1"}],"jaunty":[{"name":"lftp","version":"3.7.8-1ubuntu0.1","description":"","is_source":true},{"name":"lftp","version":"3.7.8-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/lftp","version_link":"https://launchpad.net/ubuntu/+source/lftp/3.7.8-1ubuntu0.1"}],"karmic":[{"name":"lftp","version":"3.7.15-1ubuntu2.1","description":"","is_source":true},{"name":"lftp","version":"3.7.15-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/lftp","version_link":"https://launchpad.net/ubuntu/+source/lftp/3.7.15-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2010-2251"]}]},{"id":"CVE-2010-2621","published":"2010-07-02T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe QSslSocketBackendPrivate::transmit function in\nsrc_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows\nremote attackers to cause a denial of service (infinite loop) via a\nmalformed request.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://aluigi.altervista.org/adv/qtsslame-adv.txt","https://www.cve.org/CVERecord?id=CVE-2010-2621"],"bugs":[""],"patches":{"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4924","published":"2010-07-02T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to\ncjson.encode, which makes it easier for remote attackers to conduct certain\ncross-site scripting (XSS) attacks involving Firefox and the end tag of a\nSCRIPT element.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4924"],"bugs":[""],"patches":{"python-cjson":[]},"tags":{},"packages":[{"name":"python-cjson","source":"https://ubuntu.com/security/cve?package=python-cjson","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python-cjson","debian":"https://tracker.debian.org/pkg/python-cjson","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.0.5-4build1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.0.5-4build1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1666","published":"2010-07-02T19:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in Dan Pascu python-cjson 1.0.5, when UCS-4 encoding is\nenabled, allows context-dependent attackers to cause a denial of service\n(application crash) or possibly have unspecified other impact via vectors\ninvolving crafted Unicode input to the cjson.encode function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1666"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/python-cjson/+bug/585274","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=587700"],"patches":{"python-cjson":[]},"tags":{},"packages":[{"name":"python-cjson","source":"https://ubuntu.com/security/cve?package=python-cjson","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python-cjson","debian":"https://tracker.debian.org/pkg/python-cjson","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.0.5-1ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.5-1ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.0.5-2ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.0.5-2ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2596","published":"2010-07-02T12:43:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe OJPEGPostDecode function in tif_ojpeg.c in LibTIFF 3.9.0 and 3.9.2, as\nused in tiff2ps, allows remote attackers to cause a denial of service\n(assertion failure and application exit) via a crafted TIFF image, related\nto \"downsampled OJPEG input.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"RedHat claims this is fixed by RHSA-2014-0222, no specific\npatch though, so one of the patches for other CVEs must have\nfixed it at the same time.\ncannot reproduce on quantal+\nalso check for missing parts of CVE-2014-8127 and CVE-2014-8128\nthis will not be fixed in precise/esm"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0222.html","https://www.cve.org/CVERecord?id=CVE-2010-2596"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=583081","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2596","http://bugzilla.maptools.org/show_bug.cgi?id=2209"],"patches":{"tiff":[]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2233","published":"2010-07-02T12:43:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ntif_getimage.c in LibTIFF 3.9.0 and 3.9.2 on 64-bit platforms, as used in\nImageMagick, does not properly perform vertical flips, which allows remote\nattackers to cause a denial of service (application crash) or possibly\nexecute arbitrary code via a crafted TIFF image, related to \"downsampled\nOJPEG input.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-954-1","https://www.cve.org/CVERecord?id=CVE-2010-2233"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2207"],"patches":{"tiff":[]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.9.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2598","published":"2010-07-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nLibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as used\nin tiff2rgba, attempts to process image data even when the required\ncompression functionality is not configured, which allows remote attackers\nto cause a denial of service via a crafted TIFF image, related to\n\"downsampled OJPEG input.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Same patch as CVE-2010-2597"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1085-1","https://www.cve.org/CVERecord?id=CVE-2010-2598"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=583081","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2598"],"patches":{"tiff":[]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"released","description":"3.7.4-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.8.2-7ubuntu3.7","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.8.2-13ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.9.4-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1085-1"],"notices":[{"id":"USN-1085-1","title":"tiff vulnerabilities","summary":"Certain applications could be made to run programs as your login if they\nopened a specially crafted TIFF file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2011-03-07T15:26:24.073766","description":"Sauli Pahlman discovered that the TIFF library incorrectly handled invalid\ntd_stripbytecount fields. If a user or automated system were tricked into\nopening a specially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. This issue only affected\nUbuntu 10.04 LTS and 10.10. (CVE-2010-2482)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled TIFF\nfiles with an invalid combination of SamplesPerPixel and Photometric\nvalues. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could crash the application, leading\nto a denial of service. This issue only affected Ubuntu 10.10.\n(CVE-2010-2482)\n\nNicolae Ghimbovschi discovered that the TIFF library incorrectly handled\ninvalid ReferenceBlackWhite values. If a user or automated system were\ntricked into opening a specially crafted TIFF image, a remote attacker\ncould crash the application, leading to a denial of service.\n(CVE-2010-2595)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled certain\ndefault fields. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2597, CVE-2010-2598)\n\nIt was discovered that the TIFF library incorrectly validated certain\ndata types. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2630)\n\nIt was discovered that the TIFF library incorrectly handled downsampled\nJPEG data. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. This issue only affected Ubuntu 10.04 LTS and 10.10.\n(CVE-2010-3087)\n\nIt was discovered that the TIFF library incorrectly handled certain JPEG\ndata. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could execute arbitrary code with\nuser privileges, or crash the application, leading to a denial of service.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS and 9.10.\n(CVE-2011-0191)\n\nIt was discovered that the TIFF library incorrectly handled certain TIFF\nFAX images. If a user or automated system were tricked into opening a\nspecially crafted TIFF FAX image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. (CVE-2011-0191)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"tiff","version":"3.8.2-7ubuntu3.7","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-7ubuntu3.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-7ubuntu3.7"}],"lucid":[{"name":"tiff","version":"3.9.2-2ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.2-2ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.4"}],"maverick":[{"name":"tiff","version":"3.9.4-2ubuntu0.1","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.4-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.1"}],"dapper":[{"name":"tiff","version":"3.7.4-1ubuntu3.9","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.7.4-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.7.4-1ubuntu3.9"}],"karmic":[{"name":"tiff","version":"3.8.2-13ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-13ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-13ubuntu0.4"}]},"type":"USN","cves_ids":["CVE-2010-3087","CVE-2011-0192","CVE-2010-2630","CVE-2010-2598","CVE-2010-2483","CVE-2010-2482","CVE-2010-2595","CVE-2010-2597","CVE-2011-0191"]}]},{"id":"CVE-2010-2597","published":"2010-07-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes\nincorrect calls to the TIFFGetField function, which allows remote attackers\nto cause a denial of service (application crash) via a crafted TIFF image,\nrelated to \"downsampled OJPEG input\" and possibly related to a compiler\noptimization that triggers a divide-by-zero error.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1085-1","https://www.cve.org/CVERecord?id=CVE-2010-2597"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2597","https://bugzilla.redhat.com/show_bug.cgi?id=603703","https://bugs.launchpad.net/bugs/593067","http://bugzilla.maptools.org/show_bug.cgi?id=2215"],"patches":{"tiff":["upstream: r1.19.2.3"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"3.7.4-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.8.2-7ubuntu3.7","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.8.2-13ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.9.4-2ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1085-1"],"notices":[{"id":"USN-1085-1","title":"tiff vulnerabilities","summary":"Certain applications could be made to run programs as your login if they\nopened a specially crafted TIFF file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2011-03-07T15:26:24.073766","description":"Sauli Pahlman discovered that the TIFF library incorrectly handled invalid\ntd_stripbytecount fields. If a user or automated system were tricked into\nopening a specially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. This issue only affected\nUbuntu 10.04 LTS and 10.10. (CVE-2010-2482)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled TIFF\nfiles with an invalid combination of SamplesPerPixel and Photometric\nvalues. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could crash the application, leading\nto a denial of service. This issue only affected Ubuntu 10.10.\n(CVE-2010-2482)\n\nNicolae Ghimbovschi discovered that the TIFF library incorrectly handled\ninvalid ReferenceBlackWhite values. If a user or automated system were\ntricked into opening a specially crafted TIFF image, a remote attacker\ncould crash the application, leading to a denial of service.\n(CVE-2010-2595)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled certain\ndefault fields. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2597, CVE-2010-2598)\n\nIt was discovered that the TIFF library incorrectly validated certain\ndata types. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2630)\n\nIt was discovered that the TIFF library incorrectly handled downsampled\nJPEG data. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. This issue only affected Ubuntu 10.04 LTS and 10.10.\n(CVE-2010-3087)\n\nIt was discovered that the TIFF library incorrectly handled certain JPEG\ndata. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could execute arbitrary code with\nuser privileges, or crash the application, leading to a denial of service.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS and 9.10.\n(CVE-2011-0191)\n\nIt was discovered that the TIFF library incorrectly handled certain TIFF\nFAX images. If a user or automated system were tricked into opening a\nspecially crafted TIFF FAX image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. (CVE-2011-0191)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"tiff","version":"3.8.2-7ubuntu3.7","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-7ubuntu3.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-7ubuntu3.7"}],"lucid":[{"name":"tiff","version":"3.9.2-2ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.2-2ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.4"}],"maverick":[{"name":"tiff","version":"3.9.4-2ubuntu0.1","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.4-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.1"}],"dapper":[{"name":"tiff","version":"3.7.4-1ubuntu3.9","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.7.4-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.7.4-1ubuntu3.9"}],"karmic":[{"name":"tiff","version":"3.8.2-13ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-13ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-13ubuntu0.4"}]},"type":"USN","cves_ids":["CVE-2010-3087","CVE-2011-0192","CVE-2010-2630","CVE-2010-2598","CVE-2010-2483","CVE-2010-2482","CVE-2010-2595","CVE-2010-2597","CVE-2011-0191"]}]},{"id":"CVE-2010-2595","published":"2010-07-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in\nImageMagick, does not properly handle invalid ReferenceBlackWhite values,\nwhich allows remote attackers to cause a denial of service (application\ncrash) via a crafted TIFF image that triggers an array index error, related\nto \"downsampled OJPEG input.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1085-1","https://www.cve.org/CVERecord?id=CVE-2010-2595"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=583081","http://bugzilla.maptools.org/show_bug.cgi?id=2208"],"patches":{"tiff":["upstream: libtiff/tif_color.c r1.12.2.2"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"3.7.4-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.8.2-7ubuntu3.7","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.8.2-13ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.9.4-2ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1085-1"],"notices":[{"id":"USN-1085-1","title":"tiff vulnerabilities","summary":"Certain applications could be made to run programs as your login if they\nopened a specially crafted TIFF file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2011-03-07T15:26:24.073766","description":"Sauli Pahlman discovered that the TIFF library incorrectly handled invalid\ntd_stripbytecount fields. If a user or automated system were tricked into\nopening a specially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. This issue only affected\nUbuntu 10.04 LTS and 10.10. (CVE-2010-2482)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled TIFF\nfiles with an invalid combination of SamplesPerPixel and Photometric\nvalues. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could crash the application, leading\nto a denial of service. This issue only affected Ubuntu 10.10.\n(CVE-2010-2482)\n\nNicolae Ghimbovschi discovered that the TIFF library incorrectly handled\ninvalid ReferenceBlackWhite values. If a user or automated system were\ntricked into opening a specially crafted TIFF image, a remote attacker\ncould crash the application, leading to a denial of service.\n(CVE-2010-2595)\n\nSauli Pahlman discovered that the TIFF library incorrectly handled certain\ndefault fields. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2597, CVE-2010-2598)\n\nIt was discovered that the TIFF library incorrectly validated certain\ndata types. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could crash the\napplication, leading to a denial of service. (CVE-2010-2630)\n\nIt was discovered that the TIFF library incorrectly handled downsampled\nJPEG data. If a user or automated system were tricked into opening a\nspecially crafted TIFF image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. This issue only affected Ubuntu 10.04 LTS and 10.10.\n(CVE-2010-3087)\n\nIt was discovered that the TIFF library incorrectly handled certain JPEG\ndata. If a user or automated system were tricked into opening a specially\ncrafted TIFF image, a remote attacker could execute arbitrary code with\nuser privileges, or crash the application, leading to a denial of service.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS and 9.10.\n(CVE-2011-0191)\n\nIt was discovered that the TIFF library incorrectly handled certain TIFF\nFAX images. If a user or automated system were tricked into opening a\nspecially crafted TIFF FAX image, a remote attacker could execute arbitrary\ncode with user privileges, or crash the application, leading to a denial of\nservice. (CVE-2011-0191)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"tiff","version":"3.8.2-7ubuntu3.7","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-7ubuntu3.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-7ubuntu3.7"}],"lucid":[{"name":"tiff","version":"3.9.2-2ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.2-2ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.4"}],"maverick":[{"name":"tiff","version":"3.9.4-2ubuntu0.1","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.9.4-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.1"}],"dapper":[{"name":"tiff","version":"3.7.4-1ubuntu3.9","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.7.4-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.7.4-1ubuntu3.9"}],"karmic":[{"name":"tiff","version":"3.8.2-13ubuntu0.4","description":"TIFF manipulation and conversion tools","is_source":true},{"name":"libtiff4","version":"3.8.2-13ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.8.2-13ubuntu0.4"}]},"type":"USN","cves_ids":["CVE-2010-3087","CVE-2011-0192","CVE-2010-2630","CVE-2010-2598","CVE-2010-2483","CVE-2010-2482","CVE-2010-2595","CVE-2010-2597","CVE-2011-0191"]}]},{"id":"CVE-2010-2480","published":"2010-07-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMako before 0.3.4 relies on the cgi.escape function in the Python standard\nlibrary for cross-site scripting (XSS) protection, which makes it easier\nfor remote attackers to conduct XSS attacks via vectors involving\nsingle-quote characters and a JavaScript onLoad event handler for a BODY\nelement.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-996-1","https://www.cve.org/CVERecord?id=CVE-2010-2480"],"bugs":["http://bugs.python.org/issue9061"],"patches":{"mako":[]},"tags":{},"packages":[{"name":"mako","source":"https://ubuntu.com/security/cve?package=mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mako","debian":"https://tracker.debian.org/pkg/mako","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.2.5-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.3.4-2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.3.4-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.3.4-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-996-1"],"notices":[{"id":"USN-996-1","title":"Mako vulnerability","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-29T15:37:01.019159","description":"It was discovered that Mako incorrectly filtered single-quote characters\nwhen performing html filtering. An attacker could utilize this to perform\ncross-site scripting attacks.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"mako","version":"0.2.5-2ubuntu1.3","description":"","is_source":true},{"name":"python-mako","version":"0.2.5-2ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mako","version_link":"https://launchpad.net/ubuntu/+source/mako/0.2.5-2ubuntu1.3"}]},"type":"USN","cves_ids":["CVE-2010-2480"]}]}],"offset":72620,"limit":20,"total_results":79316}