{"cves":[{"id":"CVE-2010-2109","published":"2010-05-28T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 5.0.375.55 allows\nuser-assisted remote attackers to cause a denial of service (memory error)\nor possibly have unspecified other impact via vectors related to the \"drag\n+ drop\" functionality.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2109"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.70~r48679-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.55","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2108","published":"2010-05-28T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 5.0.375.55 allows remote\nattackers to bypass the whitelist-mode plugin blocker via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2108"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.70~r48679-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.55","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2107","published":"2010-05-28T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 5.0.375.55 allows\nattackers to cause a denial of service (memory error) or possibly have\nunspecified other impact via vectors related to the Safe Browsing\nfunctionality.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2107"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.70~r48679-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.55","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2106","published":"2010-05-28T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 5.0.375.55 might allow\nremote attackers to spoof the URL bar via vectors involving unload event\nhandlers.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2106"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.70~r48679-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.55","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2105","published":"2010-05-28T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 5.0.375.55 does not properly follow the Safe Browsing\nspecification's requirements for canonicalization of URLs, which has\nunspecified impact and remote attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2105"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.70~r48679-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.55","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1938","published":"2010-05-28T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the __opiereadrec function in readrec.c in libopie in\nOPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE\nand other platforms, allows remote attackers to cause a denial of service\n(daemon crash) or possibly execute arbitrary code via a long username, as\ndemonstrated by a long USER command to the FreeBSD 8.0 ftpd.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in dapper and hardy, the off-by-one overflows into *c, which\nisn't used after in the function, so it's harmless.\non jaunty+, fortify source makes opie abort, so it is a\ndenial of service."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://security.freebsd.org/advisories/FreeBSD-SA-10:05.opie.asc","http://securityreason.com/achievement_securityalert/87","https://ubuntu.com/security/notices/USN-955-1","https://ubuntu.com/security/notices/USN-955-2","https://www.cve.org/CVERecord?id=CVE-2010-1938"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584932"],"patches":{"opie":["vendor: http://security.freebsd.org/patches/SA-10:05/opie.patch"]},"tags":{},"packages":[{"name":"opie","source":"https://ubuntu.com/security/cve?package=opie","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=opie","debian":"https://tracker.debian.org/pkg/opie","statuses":[{"release_codename":"dapper","status":"not-affected","description":"2.32-10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.32-10.2build1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.40~dfsg-0ubuntu1.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.40~dfsg-0ubuntu1.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.40~dfsg-0ubuntu1.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-955-1","USN-955-2"],"notices":[{"id":"USN-955-1","title":"OPIE vulnerability","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-06-21T18:12:22.155591","description":"Maksymilian Arciemowicz and Adam Zabrocki discovered that OPIE incorrectly\nhandled long usernames. A remote attacker could exploit this with a crafted\nusername and make applications linked against libopie crash, leading to a\ndenial of service.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"opie","version":"2.40~dfsg-0ubuntu1.10.04.1","description":"","is_source":true},{"name":"libopie-dev","version":"2.40~dfsg-0ubuntu1.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/opie","version_link":"https://launchpad.net/ubuntu/+source/opie/2.40~dfsg-0ubuntu1.10.04.1"}],"jaunty":[{"name":"opie","version":"2.40~dfsg-0ubuntu1.9.04.1","description":"","is_source":true},{"name":"libopie-dev","version":"2.40~dfsg-0ubuntu1.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/opie","version_link":"https://launchpad.net/ubuntu/+source/opie/2.40~dfsg-0ubuntu1.9.04.1"}],"karmic":[{"name":"opie","version":"2.40~dfsg-0ubuntu1.9.10.1","description":"","is_source":true},{"name":"libopie-dev","version":"2.40~dfsg-0ubuntu1.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/opie","version_link":"https://launchpad.net/ubuntu/+source/opie/2.40~dfsg-0ubuntu1.9.10.1"}]},"type":"USN","cves_ids":["CVE-2010-1938"]},{"id":"USN-955-2","title":"libpam-opie vulnerability","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-06-21T18:20:29.466360","description":"USN-955-1 fixed vulnerabilities in OPIE. This update provides rebuilt\nlibpam-opie packages against the updated libopie library.\n\nOriginal advisory details:\n\n Maksymilian Arciemowicz and Adam Zabrocki discovered that OPIE incorrectly\n handled long usernames. A remote attacker could exploit this with a crafted\n username and make applications linked against libopie crash, leading to a\n denial of service.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"libpam-opie","version":"0.21-8build3.1","description":"","is_source":true},{"name":"libpam-opie","version":"0.21-8build3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpam-opie","version_link":"https://launchpad.net/ubuntu/+source/libpam-opie/0.21-8build3.1"}],"jaunty":[{"name":"libpam-opie","version":"0.21-8build1.9.04.1","description":"","is_source":true},{"name":"libpam-opie","version":"0.21-8build1.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpam-opie","version_link":"https://launchpad.net/ubuntu/+source/libpam-opie/0.21-8build1.9.04.1"}],"karmic":[{"name":"libpam-opie","version":"0.21-8build2.1","description":"","is_source":true},{"name":"libpam-opie","version":"0.21-8build2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpam-opie","version_link":"https://launchpad.net/ubuntu/+source/libpam-opie/0.21-8build2.1"}]},"type":"USN","cves_ids":["CVE-2010-1938"]}]},{"id":"CVE-2010-2103","published":"2010-05-27T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in\naxis2-admin/axis2-admin/engagingglobally in the administration console in\nApache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP\nBusiness Objects 12, 3com IMC, and possibly other products, allows remote\nattackers to inject arbitrary web script or HTML via the modules parameter.\n NOTE: some of these details are obtained from third party information.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this is axis2, not the axis source package in Debian/ubuntu"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2103"],"bugs":[""],"patches":{"axis":[]},"tags":{},"packages":[{"name":"axis","source":"https://ubuntu.com/security/cve?package=axis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=axis","debian":"https://tracker.debian.org/pkg/axis","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2101","published":"2010-05-27T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap, (5)\nstr_word_count, and (6) str_pad functions in PHP 5.2 through 5.2.13 and 5.3\nthrough 5.3.2 allow context-dependent attackers to obtain sensitive\ninformation (memory contents) by causing a userspace interruption of an\ninternal function, related to the call time pass by reference feature.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"see CVE-2010-1864 for patch\ninterruption issue, safe_mode - open_basedir bypass, ignoring\nThis is MOPS-2010-041 to MOPS-2010-046"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/26/mops-2010-041-php-strip_tags-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/26/mops-2010-042-php-setcookie-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/26/mops-2010-043-php-strtok-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/26/mops-2010-044-php-wordwrap-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/26/mops-2010-045-php-str_word_count-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/26/mops-2010-046-php-str_pad-interruption-information-leak-vulnerability/index.html","https://www.cve.org/CVERecord?id=CVE-2010-2101"],"bugs":[""],"patches":{"php5":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2100","published":"2010-05-27T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) htmlentities, (2) htmlspecialchars, (3) str_getcsv, (4)\nhttp_build_query, (5) strpbrk, and (6) strtr functions in PHP 5.2 through\n5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain\nsensitive information (memory contents) by causing a userspace interruption\nof an internal function, related to the call time pass by reference\nfeature.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"see CVE-2010-1864 for patch\ninterruption issue, safe_mode - open_basedir bypass, ignoring\nThis is MOPS-2010-036 to MOPS-2010-040"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/21/mops-2010-036-php-htmlentities-and-htmlspecialchars-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/21/mops-2010-037-php-str_getcsv-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/21/mops-2010-038-php-http_build_query-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/21/mops-2010-039-php-strpbrk-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/21/mops-2010-040-php-strtr-interruption-information-leak-vulnerability/index.html","https://www.cve.org/CVERecord?id=CVE-2010-2100"],"bugs":[""],"patches":{"php5":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2097","published":"2010-05-27T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) iconv_mime_decode, (2) iconv_substr, and (3) iconv_mime_encode\nfunctions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow\ncontext-dependent attackers to obtain sensitive information (memory\ncontents) by causing a userspace interruption of an internal function,\nrelated to the call time pass by reference feature.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"see CVE-2010-1864 for patch\ninterruption issue, safe_mode - open_basedir bypass, ignoring\nThis is MOPS-2010-032, MOPS-2010-033, MOPS-2010-034"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/18/mops-2010-032-php-iconv_mime_decode-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/18/mops-2010-033-php-iconv_substr-interruption-information-leak-vulnerability/index.html","http://php-security.org/2010/05/18/mops-2010-034-php-iconv_mime_encode-interruption-information-leak-vulnerability/index.html","https://www.cve.org/CVERecord?id=CVE-2010-2097"],"bugs":[""],"patches":{"php5":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2093","published":"2010-05-27T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the request shutdown functionality in PHP\n5.2 before 5.2.13 and 5.3 before 5.3.2 allows context-dependent attackers\nto cause a denial of service (crash) via a stream context structure that is\nfreed before destruction occurs.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"PoC: http://php-security.org/2010/05/12/mops-2010-022-php-stream-context-use-after-free-on-request-shutdown-vulnerability/index.html"},{"author":"mdeslaur","note":"unfixed in 5.3.3\nThis is MOPS-2010-022"},{"author":"sbeattie","note":"upstream considers a fix invasive, according to referenced\noss-security post"},{"author":"mdeslaur","note":"upstream is ignoring this, so are we."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/12/mops-2010-022-php-stream-context-use-after-free-on-request-shutdown-vulnerability/index.html","http://openwall.com/lists/oss-security/2010/08/20/4","https://www.cve.org/CVERecord?id=CVE-2010-2093"],"bugs":[""],"patches":{"php5":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2092","published":"2010-05-27T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows\nremote attackers to execute arbitrary SQL commands via a crafted rra_id\nparameter in a GET request in conjunction with a valid rra_id value in a\nPOST request or a cookie, which causes the POST or cookie value to bypass\nthe validation routine, but inserts the $_GET value into the resulting\nquery.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2092"],"bugs":[""],"patches":{"cacti":[]},"tags":{},"packages":[{"name":"cacti","source":"https://ubuntu.com/security/cve?package=cacti","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cacti","debian":"https://tracker.debian.org/pkg/cacti","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.8.7e-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.8.7e-4","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.8.7e-4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.8.7e-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.7e-4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1450","published":"2010-05-27T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple buffer overflows in the RLE decoder in the rgbimg module in Python\n2.5 allow remote attackers to have an unspecified impact via an image file\ncontaining crafted data that triggers improper processing within the (1)\nlongimagedata or (2) expandrow function.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per upstream, python2.6 not affected\nfix for CVE-2007-4965 also fixed the rgbimg module. This CVE was\nassigned after the fact."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.python.org/issue8678","https://www.cve.org/CVERecord?id=CVE-2010-1450"],"bugs":[""],"patches":{"python2.4":[],"python2.5":["upstream: http://hg.python.org/cpython/rev/f49d9314d439/"]},"tags":{},"packages":[{"name":"python2.4","source":"https://ubuntu.com/security/cve?package=python2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.4","debian":"https://tracker.debian.org/pkg/python2.4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.4.5-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.4-7","component":null,"pocket":"security"}]},{"name":"python2.5","source":"https://ubuntu.com/security/cve?package=python2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.5","debian":"https://tracker.debian.org/pkg/python2.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.5.2-2ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.1-6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1449","published":"2010-05-27T19:30:00","updated_at":"2025-08-04T19:23:44.558874+00:00","description":"\nInteger overflow in rgbimgmodule.c in the rgbimg module in Python 2.5\nallows remote attackers to have an unspecified impact via a large image\nthat triggers a buffer overflow. NOTE: this vulnerability exists because\nof an incomplete fix for CVE-2008-3143.12.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per upstream, python2.6 not affected\nfix for CVE-2007-4965 also fixed the rgbimg module. This CVE was\nassigned after the fact."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.python.org/issue8678","https://www.cve.org/CVERecord?id=CVE-2010-1449"],"bugs":[""],"patches":{"python2.4":[],"python2.5":["upstream: http://hg.python.org/cpython/rev/f49d9314d439/"]},"tags":{},"packages":[{"name":"python2.4","source":"https://ubuntu.com/security/cve?package=python2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.4","debian":"https://tracker.debian.org/pkg/python2.4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.4.5-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.4-7","component":null,"pocket":"security"}]},{"name":"python2.5","source":"https://ubuntu.com/security/cve?package=python2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.5","debian":"https://tracker.debian.org/pkg/python2.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.5.2-2ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.1-6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4134","published":"2010-05-27T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer underflow in the rgbimg module in Python 2.5 allows remote attackers\nto cause a denial of service (application crash) via a large ZSIZE value in\na black-and-white (aka B/W) RGB image that triggers an invalid pointer\ndereference.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per upstream, python2.6 not affected\nfix for CVE-2007-4965 also fixed the rgbimg module. This CVE was\nassigned after the fact."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.python.org/issue8678","https://www.cve.org/CVERecord?id=CVE-2009-4134"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=541698"],"patches":{"python2.4":[],"python2.5":["upstream: http://hg.python.org/cpython/rev/f49d9314d439/"]},"tags":{},"packages":[{"name":"python2.4","source":"https://ubuntu.com/security/cve?package=python2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.4","debian":"https://tracker.debian.org/pkg/python2.4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.4.5-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.4-7","component":null,"pocket":"security"}]},{"name":"python2.5","source":"https://ubuntu.com/security/cve?package=python2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.5","debian":"https://tracker.debian.org/pkg/python2.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.5.2-2ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.1-6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2950","published":"2010-05-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nFormat string vulnerability in stream.c in the phar extension in PHP 5.3.x\nthrough 5.3.3 allows context-dependent attackers to obtain sensitive\ninformation (memory contents) and possibly execute arbitrary code via a\ncrafted phar:// URI that is not properly handled by the phar_stream_flush\nfunction, leading to errors in the php_stream_wrapper_log_error function.\nNOTE: this vulnerability exists because of an incomplete fix for\nCVE-2010-2094.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"See second patch in CVE-2010-2094\nThis is MOPS-2010-024\n5.3 only, not fixed in 5.3.3"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/14/mops-2010-024-php-phar_stream_flush-format-string-vulnerability/index.html","https://ubuntu.com/security/notices/USN-989-1","https://www.cve.org/CVERecord?id=CVE-2010-2950"],"bugs":[""],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=302565"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"5.1.2-1ubuntu3.18","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu5.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.2.6.dfsg.1-3ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.2.10.dfsg.1-2ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-989-1"],"notices":[{"id":"USN-989-1","title":"PHP vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-20T18:22:04.757285","description":"Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc\nrequests. An attacker could exploit this issue to cause the PHP server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2010-0397)\n\nIt was discovered that the pseudorandom number generator in PHP did not\nprovide the expected entropy. An attacker could exploit this issue to\npredict values that were intended to be random, such as session cookies.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10.\n(CVE-2010-1128)\n\nIt was discovered that PHP did not properly handle directory pathnames that\nlacked a trailing slash character. An attacker could exploit this issue to\nbypass safe_mode restrictions. This issue only affected Ubuntu 6.06 LTS,\n8.04 LTS, 9.04 and 9.10. (CVE-2010-1129)\n\nGrzegorz Stachowiak discovered that the PHP session extension did not\nproperly handle semicolon characters. An attacker could exploit this issue\nto bypass safe_mode restrictions. This issue only affected Ubuntu 8.04 LTS,\n9.04 and 9.10. (CVE-2010-1130)\n\nStefan Esser discovered that PHP incorrectly decoded remote HTTP chunked\nencoding streams. An attacker could exploit this issue to cause the PHP\nserver to crash and possibly execute arbitrary code with application\nprivileges. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-1866)\n\nMateusz Kocielski discovered that certain PHP SQLite functions incorrectly\nhandled empty SQL queries. An attacker could exploit this issue to possibly\nexecute arbitrary code with application privileges. (CVE-2010-1868)\n\nMateusz Kocielski discovered that PHP incorrectly handled certain arguments\nto the fnmatch function. An attacker could exploit this flaw and cause the\nPHP server to consume all available stack memory, resulting in a denial of\nservice. (CVE-2010-1917)\n\nStefan Esser discovered that PHP incorrectly handled certain strings in the\nphar extension. An attacker could exploit this flaw to possibly view\nsensitive information. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2010-2094, CVE-2010-2950)\n\nStefan Esser discovered that PHP incorrectly handled deserialization of\nSPLObjectStorage objects. A remote attacker could exploit this issue to\nview sensitive information and possibly execute arbitrary code with\napplication privileges. This issue only affected Ubuntu 8.04 LTS, 9.04,\n9.10 and 10.04 LTS. (CVE-2010-2225)\n\nIt was discovered that PHP incorrectly filtered error messages when limits\nfor memory, execution time, or recursion were exceeded. A remote attacker\ncould exploit this issue to possibly view sensitive information.\n(CVE-2010-2531)\n\nStefan Esser discovered that the PHP session serializer incorrectly handled\nthe PS_UNDEF_MARKER marker. An attacker could exploit this issue to alter\narbitrary session variables. (CVE-2010-3065)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.12","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.5","description":"","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.19","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"}],"jaunty":[{"name":"php5","version":"5.2.6.dfsg.1-3ubuntu4.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"php5-cgi","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"libapache2-mod-php5","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"}]},"type":"USN","cves_ids":["CVE-2010-0397","CVE-2010-1128","CVE-2010-1129","CVE-2010-1130","CVE-2010-1866","CVE-2010-1868","CVE-2010-1917","CVE-2010-2094","CVE-2010-2225","CVE-2010-2531","CVE-2010-2950","CVE-2010-3065"]}]},{"id":"CVE-2010-2094","published":"2010-05-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple format string vulnerabilities in the phar extension in PHP 5.3\nbefore 5.3.2 allow context-dependent attackers to obtain sensitive\ninformation (memory contents) and possibly execute arbitrary code via a\ncrafted phar:// URI that is not properly handled by the (1)\nphar_stream_flush, (2) phar_wrapper_unlink, (3) phar_parse_url, or (4)\nphar_wrapper_open_url functions in ext/phar/stream.c; and the (5)\nphar_wrapper_open_dir function in ext/phar/dirstream.c, which triggers\nerrors in the php_stream_wrapper_log_error function.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"5.3 only, not fixed in 5.3.3\nThis is MOPS-2010-024 to MOPS-2010-028"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/14/mops-2010-024-php-phar_stream_flush-format-string-vulnerability/index.html","http://php-security.org/2010/05/14/mops-2010-025-php-phar_wrapper_open_dir-format-string-vulnerability/index.html","http://php-security.org/2010/05/14/mops-2010-026-php-phar_wrapper_unlink-format-string-vulnerability/index.html","http://php-security.org/2010/05/14/mops-2010-027-php-phar_parse_url-format-string-vulnerabilities/index.html","http://php-security.org/2010/05/14/mops-2010-028-php-phar_wrapper_open_url-format-string-vulnerabilities/index.html","https://ubuntu.com/security/notices/USN-989-1","https://www.cve.org/CVERecord?id=CVE-2010-2094"],"bugs":[""],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=298667","upstream: http://svn.php.net/viewvc?view=revision&revision=302565"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"5.1.2-1ubuntu3.18","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu5.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.2.6.dfsg.1-3ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.2.10.dfsg.1-2ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-989-1"],"notices":[{"id":"USN-989-1","title":"PHP vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-20T18:22:04.757285","description":"Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc\nrequests. An attacker could exploit this issue to cause the PHP server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2010-0397)\n\nIt was discovered that the pseudorandom number generator in PHP did not\nprovide the expected entropy. An attacker could exploit this issue to\npredict values that were intended to be random, such as session cookies.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10.\n(CVE-2010-1128)\n\nIt was discovered that PHP did not properly handle directory pathnames that\nlacked a trailing slash character. An attacker could exploit this issue to\nbypass safe_mode restrictions. This issue only affected Ubuntu 6.06 LTS,\n8.04 LTS, 9.04 and 9.10. (CVE-2010-1129)\n\nGrzegorz Stachowiak discovered that the PHP session extension did not\nproperly handle semicolon characters. An attacker could exploit this issue\nto bypass safe_mode restrictions. This issue only affected Ubuntu 8.04 LTS,\n9.04 and 9.10. (CVE-2010-1130)\n\nStefan Esser discovered that PHP incorrectly decoded remote HTTP chunked\nencoding streams. An attacker could exploit this issue to cause the PHP\nserver to crash and possibly execute arbitrary code with application\nprivileges. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-1866)\n\nMateusz Kocielski discovered that certain PHP SQLite functions incorrectly\nhandled empty SQL queries. An attacker could exploit this issue to possibly\nexecute arbitrary code with application privileges. (CVE-2010-1868)\n\nMateusz Kocielski discovered that PHP incorrectly handled certain arguments\nto the fnmatch function. An attacker could exploit this flaw and cause the\nPHP server to consume all available stack memory, resulting in a denial of\nservice. (CVE-2010-1917)\n\nStefan Esser discovered that PHP incorrectly handled certain strings in the\nphar extension. An attacker could exploit this flaw to possibly view\nsensitive information. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2010-2094, CVE-2010-2950)\n\nStefan Esser discovered that PHP incorrectly handled deserialization of\nSPLObjectStorage objects. A remote attacker could exploit this issue to\nview sensitive information and possibly execute arbitrary code with\napplication privileges. This issue only affected Ubuntu 8.04 LTS, 9.04,\n9.10 and 10.04 LTS. (CVE-2010-2225)\n\nIt was discovered that PHP incorrectly filtered error messages when limits\nfor memory, execution time, or recursion were exceeded. A remote attacker\ncould exploit this issue to possibly view sensitive information.\n(CVE-2010-2531)\n\nStefan Esser discovered that the PHP session serializer incorrectly handled\nthe PS_UNDEF_MARKER marker. An attacker could exploit this issue to alter\narbitrary session variables. (CVE-2010-3065)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.12","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.5","description":"","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.19","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"}],"jaunty":[{"name":"php5","version":"5.2.6.dfsg.1-3ubuntu4.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"php5-cgi","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"libapache2-mod-php5","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"}]},"type":"USN","cves_ids":["CVE-2010-0397","CVE-2010-1128","CVE-2010-1129","CVE-2010-1130","CVE-2010-1866","CVE-2010-1868","CVE-2010-1917","CVE-2010-2094","CVE-2010-2225","CVE-2010-2531","CVE-2010-2950","CVE-2010-3065"]}]},{"id":"CVE-2010-2089","published":"2010-05-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe audioop module in Python 2.7 and 3.2 does not verify the relationships\nbetween size arguments and byte string lengths, which allows\ncontext-dependent attackers to cause a denial of service (memory corruption\nand application crash) via crafted arguments, as demonstrated by a call to\naudioop.reverse with a one-byte string, a different vulnerability than\nCVE-2010-1634.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream bug report says 2.6 is affected also\nDoS only, setting to low"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.python.org/issue7673","https://ubuntu.com/security/notices/USN-1596-1","https://ubuntu.com/security/notices/USN-1613-1","https://ubuntu.com/security/notices/USN-1613-2","https://ubuntu.com/security/notices/USN-1616-1","https://www.cve.org/CVERecord?id=CVE-2010-2089"],"bugs":["http://bugs.python.org/issue7673"],"patches":{"python2.4":[],"python2.5":[],"python2.6":["upstream: http://svn.python.org/view?view=rev&revision=82494","upstream: http://hg.python.org/cpython/rev/29116b2fcffe"],"python2.7":[],"python3.1":["upstream: http://hg.python.org/cpython/rev/7184421f83b5","upstream: http://hg.python.org/cpython/rev/b67f720998a8"],"python3.2":[]},"tags":{},"packages":[{"name":"python2.4","source":"https://ubuntu.com/security/cve?package=python2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.4","debian":"https://tracker.debian.org/pkg/python2.4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.4.5-1ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"python2.5","source":"https://ubuntu.com/security/cve?package=python2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.5","debian":"https://tracker.debian.org/pkg/python2.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.5.2-2ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"python2.6","source":"https://ubuntu.com/security/cve?package=python2.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.6","debian":"https://tracker.debian.org/pkg/python2.6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.5-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.6.6-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.6-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.6-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.5+20100706-1","component":null,"pocket":"security"}]},{"name":"python2.7","source":"https://ubuntu.com/security/cve?package=python2.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.7","debian":"https://tracker.debian.org/pkg/python2.7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7-1","component":null,"pocket":"security"}]},{"name":"python3.1","source":"https://ubuntu.com/security/cve?package=python3.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.1","debian":"https://tracker.debian.org/pkg/python3.1","statuses":[{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.1.2-0ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.1.3-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.3-1","component":null,"pocket":"security"}]},{"name":"python3.2","source":"https://ubuntu.com/security/cve?package=python3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.2","debian":"https://tracker.debian.org/pkg/python3.2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1613-1","USN-1613-2","USN-1616-1","USN-1596-1"],"notices":[{"id":"USN-1613-1","title":"Python 2.5 vulnerabilities","summary":"Several security issues were fixed in Python 2.5.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-10-17T13:09:19.200949","description":"It was discovered that Python would prepend an empty string to sys.path\nunder certain circumstances. A local attacker with write access to the\ncurrent working directory could exploit this to execute arbitrary code.\n(CVE-2008-5983)\n\nIt was discovered that the audioop module did not correctly perform input\nvalidation. If a user or automatated system were tricked into opening a\ncrafted audio file, an attacker could cause a denial of service via\napplication crash. (CVE-2010-1634, CVE-2010-2089)\n\nGiampaolo Rodola discovered several race conditions in the smtpd module.\nA remote attacker could exploit this to cause a denial of service via\ndaemon outage. (CVE-2010-3493)\n\nIt was discovered that the CGIHTTPServer module did not properly perform\ninput validation on certain HTTP GET requests. A remote attacker could\npotentially obtain access to CGI script source files. (CVE-2011-1015)\n\nNiels Heinen discovered that the urllib and urllib2 modules would process\nLocation headers that specify a redirection to file: URLs. A remote\nattacker could exploit this to obtain sensitive information or cause a\ndenial of service. (CVE-2011-1521)\n\nIt was discovered that SimpleHTTPServer did not use a charset parameter in\nthe Content-Type HTTP header. An attacker could potentially exploit this\nto conduct cross-site scripting (XSS) attacks against Internet Explorer 7\nusers. (CVE-2011-4940)\n\nIt was discovered that Python distutils contained a race condition when\ncreating the ~/.pypirc file. A local attacker could exploit this to obtain\nsensitive information. (CVE-2011-4944)\n\nIt was discovered that SimpleXMLRPCServer did not properly validate its\ninput when handling HTTP POST requests. A remote attacker could exploit\nthis to cause a denial of service via excessive CPU utilization.\n(CVE-2012-0845)\n\nIt was discovered that the Expat module in Python 2.5 computed hash values\nwithout restricting the ability to trigger hash collisions predictably. If\na user or application using pyexpat were tricked into opening a crafted XML\nfile, an attacker could cause a denial of service by consuming excessive\nCPU resources. (CVE-2012-0876)\n\nTim Boddy discovered that the Expat module in Python 2.5 did not properly\nhandle memory reallocation when processing XML files. If a user or\napplication using pyexpat were tricked into opening a crafted XML file, an\nattacker could cause a denial of service by consuming excessive memory\nresources. (CVE-2012-1148)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"python2.5","version":"2.5.2-2ubuntu6.2","description":"An interactive high-level object-oriented language (version 2.5)","is_source":true},{"name":"python2.5-minimal","version":"2.5.2-2ubuntu6.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.5","version_link":"https://launchpad.net/ubuntu/+source/python2.5/2.5.2-2ubuntu6.2"},{"name":"python2.5","version":"2.5.2-2ubuntu6.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.5","version_link":"https://launchpad.net/ubuntu/+source/python2.5/2.5.2-2ubuntu6.2"}]},"type":"USN","cves_ids":["CVE-2008-5983","CVE-2010-1634","CVE-2010-2089","CVE-2010-3493","CVE-2011-1015","CVE-2011-1521","CVE-2011-4940","CVE-2011-4944","CVE-2012-0845","CVE-2012-0876","CVE-2012-1148"]},{"id":"USN-1613-2","title":"Python 2.4 vulnerabilities","summary":"Several security issues were fixed in Python 2.4.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-10-17T20:04:18.574469","description":"USN-1613-1 fixed vulnerabilities in Python 2.5. This update provides the\ncorresponding updates for Python 2.4.\n\nOriginal advisory details:\n\n It was discovered that Python would prepend an empty string to sys.path\n under certain circumstances. A local attacker with write access to the\n current working directory could exploit this to execute arbitrary code.\n (CVE-2008-5983)\n \n It was discovered that the audioop module did not correctly perform input\n validation. If a user or automatated system were tricked into opening a\n crafted audio file, an attacker could cause a denial of service via\n application crash. (CVE-2010-1634, CVE-2010-2089)\n \n Giampaolo Rodola discovered several race conditions in the smtpd module.\n A remote attacker could exploit this to cause a denial of service via\n daemon outage. (CVE-2010-3493)\n \n It was discovered that the CGIHTTPServer module did not properly perform\n input validation on certain HTTP GET requests. A remote attacker could\n potentially obtain access to CGI script source files. (CVE-2011-1015)\n \n Niels Heinen discovered that the urllib and urllib2 modules would process\n Location headers that specify a redirection to file: URLs. A remote\n attacker could exploit this to obtain sensitive information or cause a\n denial of service. (CVE-2011-1521)\n \n It was discovered that SimpleHTTPServer did not use a charset parameter in\n the Content-Type HTTP header. An attacker could potentially exploit this\n to conduct cross-site scripting (XSS) attacks against Internet Explorer 7\n users. (CVE-2011-4940)\n \n It was discovered that Python distutils contained a race condition when\n creating the ~/.pypirc file. A local attacker could exploit this to obtain\n sensitive information. (CVE-2011-4944)\n \n It was discovered that SimpleXMLRPCServer did not properly validate its\n input when handling HTTP POST requests. A remote attacker could exploit\n this to cause a denial of service via excessive CPU utilization.\n (CVE-2012-0845)\n \n It was discovered that the Expat module in Python 2.5 computed hash values\n without restricting the ability to trigger hash collisions predictably. If\n a user or application using pyexpat were tricked into opening a crafted XML\n file, an attacker could cause a denial of service by consuming excessive\n CPU resources. (CVE-2012-0876)\n \n Tim Boddy discovered that the Expat module in Python 2.5 did not properly\n handle memory reallocation when processing XML files. If a user or\n application using pyexpat were tricked into opening a crafted XML file, an\n attacker could cause a denial of service by consuming excessive memory\n resources. (CVE-2012-1148)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"python2.4","version":"2.4.5-1ubuntu4.4","description":"An interactive high-level object-oriented language (version 2.4)","is_source":true},{"name":"python2.4-minimal","version":"2.4.5-1ubuntu4.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.4","version_link":"https://launchpad.net/ubuntu/+source/python2.4/2.4.5-1ubuntu4.4"},{"name":"python2.4","version":"2.4.5-1ubuntu4.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.4","version_link":"https://launchpad.net/ubuntu/+source/python2.4/2.4.5-1ubuntu4.4"}]},"type":"USN","cves_ids":["CVE-2010-2089","CVE-2011-1015","CVE-2008-5983","CVE-2010-1634","CVE-2010-3493","CVE-2011-1521","CVE-2011-4940","CVE-2011-4944","CVE-2012-0845","CVE-2012-0876","CVE-2012-1148"]},{"id":"USN-1616-1","title":"Python 3.1 vulnerabilities","summary":"Several security issues were fixed in Python 3.1.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-10-24T15:51:47.087706","description":"It was discovered that Python would prepend an empty string to sys.path\nunder certain circumstances. A local attacker with write access to the\ncurrent working directory could exploit this to execute arbitrary code.\nThis issue only affected Ubuntu 10.04 LTS. (CVE-2008-5983)\n\nIt was discovered that the audioop module did not correctly perform input\nvalidation. If a user or automatated system were tricked into opening a\ncrafted audio file, an attacker could cause a denial of service via\napplication crash. These issues only affected Ubuntu 10.04 LTS.\n(CVE-2010-1634, CVE-2010-2089)\n\nIt was discovered that Python distutils contained a race condition when\ncreating the ~/.pypirc file. A local attacker could exploit this to obtain\nsensitive information. (CVE-2011-4944)\n\nIt was discovered that SimpleXMLRPCServer did not properly validate its\ninput when handling HTTP POST requests. A remote attacker could exploit\nthis to cause a denial of service via excessive CPU utilization.\n(CVE-2012-0845)\n\nIt was discovered that Python was susceptible to hash algorithm attacks.\nAn attacker could cause a denial of service under certian circumstances.\nThis update adds the '-R' command line option and honors setting the\nPYTHONHASHSEED environment variable to 'random' to salt str and datetime\nobjects with an unpredictable value. (CVE-2012-1150)\n\nSerhiy Storchaka discovered that the UTF16 decoder in Python did not\nproperly reset internal variables after error handling. An attacker could\nexploit this to cause a denial of service via memory corruption.\n(CVE-2012-2135)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"python3.1","version":"3.1.2-0ubuntu3.2","description":"An interactive high-level object-oriented language (version 3.1)","is_source":true},{"name":"python3.1-minimal","version":"3.1.2-0ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.1","version_link":"https://launchpad.net/ubuntu/+source/python3.1/3.1.2-0ubuntu3.2"},{"name":"python3.1","version":"3.1.2-0ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.1","version_link":"https://launchpad.net/ubuntu/+source/python3.1/3.1.2-0ubuntu3.2"}],"natty":[{"name":"python3.1","version":"3.1.3-1ubuntu1.2","description":"An interactive high-level object-oriented language (version 3.1)","is_source":true},{"name":"python3.1-minimal","version":"3.1.3-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.1","version_link":"https://launchpad.net/ubuntu/+source/python3.1/3.1.3-1ubuntu1.2"},{"name":"python3.1","version":"3.1.3-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.1","version_link":"https://launchpad.net/ubuntu/+source/python3.1/3.1.3-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2008-5983","CVE-2010-1634","CVE-2010-2089","CVE-2011-4944","CVE-2012-0845","CVE-2012-1150","CVE-2012-2135"]},{"id":"USN-1596-1","title":"Python 2.6 vulnerabilities","summary":"Several security issues were fixed in Python 2.6.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-10-04T21:40:32.857994","description":"It was discovered that Python would prepend an empty string to sys.path\nunder certain circumstances. A local attacker with write access to the\ncurrent working directory could exploit this to execute arbitrary code.\n(CVE-2008-5983)\n\nIt was discovered that the audioop module did not correctly perform input\nvalidation. If a user or automatated system were tricked into opening a\ncrafted audio file, an attacker could cause a denial of service via\napplication crash. (CVE-2010-1634, CVE-2010-2089)\n\nGiampaolo Rodola discovered several race conditions in the smtpd module.\nA remote attacker could exploit this to cause a denial of service via\ndaemon outage. (CVE-2010-3493)\n\nIt was discovered that the CGIHTTPServer module did not properly perform\ninput validation on certain HTTP GET requests. A remote attacker could\npotentially obtain access to CGI script source files. (CVE-2011-1015)\n\nNiels Heinen discovered that the urllib and urllib2 modules would process\nLocation headers that specify a redirection to file: URLs. A remote\nattacker could exploit this to obtain sensitive information or cause a\ndenial of service. This issue only affected Ubuntu 11.04. (CVE-2011-1521)\n\nIt was discovered that SimpleHTTPServer did not use a charset parameter in\nthe Content-Type HTTP header. An attacker could potentially exploit this\nto conduct cross-site scripting (XSS) attacks against Internet Explorer 7\nusers. This issue only affected Ubuntu 11.04. (CVE-2011-4940)\n\nIt was discovered that Python distutils contained a race condition when\ncreating the ~/.pypirc file. A local attacker could exploit this to obtain\nsensitive information. (CVE-2011-4944)\n\nIt was discovered that SimpleXMLRPCServer did not properly validate its\ninput when handling HTTP POST requests. A remote attacker could exploit\nthis to cause a denial of service via excessive CPU utilization.\n(CVE-2012-0845)\n\nIt was discovered that Python was susceptible to hash algorithm attacks.\nAn attacker could cause a denial of service under certian circumstances.\nThis update adds the '-R' command line option and honors setting the\nPYTHONHASHSEED environment variable to 'random' to salt str and datetime\nobjects with an unpredictable value. (CVE-2012-1150)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"python2.6","version":"2.6.5-1ubuntu6.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.6-minimal","version":"2.6.5-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.5-1ubuntu6.1"},{"name":"python2.6","version":"2.6.5-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.5-1ubuntu6.1"}],"natty":[{"name":"python2.6","version":"2.6.6-6ubuntu7.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.6-minimal","version":"2.6.6-6ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.6-6ubuntu7.1"},{"name":"python2.6","version":"2.6.6-6ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.6-6ubuntu7.1"}],"oneiric":[{"name":"python2.6","version":"2.6.7-4ubuntu1.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.6-minimal","version":"2.6.7-4ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.7-4ubuntu1.1"},{"name":"python2.6","version":"2.6.7-4ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.7-4ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2008-5983","CVE-2010-1634","CVE-2010-2089","CVE-2010-3493","CVE-2011-1015","CVE-2011-1521","CVE-2011-4940","CVE-2011-4944","CVE-2012-0845","CVE-2012-1150"]}]},{"id":"CVE-2010-2077","published":"2010-05-27T00:00:00","updated_at":"2025-08-04T19:23:46.919224+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2010-1640. Reason: This candidate is a duplicate of CVE-2010-1640.\nNotes: All CVE users should reference CVE-2010-1640 instead of this\ncandidate. All references and descriptions in this candidate have been\nremoved to prevent accidental usage","ubuntu_description":"","notes":[{"author":"jdstrand","note":"does not affect 0.95.3 and lower"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-945-1","https://www.cve.org/CVERecord?id=CVE-2010-2077"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.96.1+dfsg-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.96.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-945-1"],"notices":[{"id":"USN-945-1","title":"ClamAV vulnerabilities","summary":"An attacker could send crafted input to ClamAV and cause it to crash.\n","instructions":"In general, a standard system update will make all the necessary\nchanges. For Ubuntu 10.04 LTS, this update uses a new upstream release,\nwhich includes additional bug fixes.\n","references":[],"published":"2010-05-27T21:06:47.012581","description":"It was discovered that ClamAV did not properly reallocate memory when\nprocessing certain PDF files. A remote attacker could send a specially\ncrafted PDF and crash ClamAV. (CVE-2010-1639)\n\nAn out of bounds memory access flaw was discovered in ClamAV. A remote\nattacker could send a specially crafted Portable Executable (PE) file\nand crash ClamAV. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2010-2077)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"clamav","version":"0.96.1+dfsg-0ubuntu0.10.04.1","description":"anti-virus utility for Unix","is_source":true},{"name":"libclamav6","version":"0.96.1+dfsg-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.96.1+dfsg-0ubuntu0.10.04.1"}],"jaunty":[{"name":"clamav","version":"0.95.3+dfsg-1ubuntu0.09.04.2","description":"anti-virus utility for Unix","is_source":true},{"name":"libclamav6","version":"0.95.3+dfsg-1ubuntu0.09.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.95.3+dfsg-1ubuntu0.09.04.2"}],"karmic":[{"name":"clamav","version":"0.95.3+dfsg-1ubuntu0.09.10.2","description":"anti-virus utility for Unix","is_source":true},{"name":"libclamav6","version":"0.95.3+dfsg-1ubuntu0.09.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.95.3+dfsg-1ubuntu0.09.10.2"}]},"type":"USN","cves_ids":["CVE-2010-1639","CVE-2010-2077"]}]},{"id":"CVE-2010-1640","published":"2010-05-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the parseicon function in libclamav/pe_icons.c in\nClamAV 0.96 allows remote attackers to cause a denial of service (crash)\nvia a crafted PE icon that triggers an out-of-bounds read, related to\nimproper rounding during scaling.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"patched as CVE-2010-2077 in USN-945-1\ndoes not affect 0.95.3 and lower"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1640"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.96.1+dfsg-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.96.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":72840,"limit":20,"total_results":79316}