{"cves":[{"id":"CVE-2010-1869","published":"2010-05-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the parser function in GhostScript 8.70 and\n8.64 allows context-dependent attackers to execute arbitrary code via a\ncrafted PostScript file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"reproducer doesn't appear to work on dapper's gs-esp\nstack protector makes this a DoS on karmic"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.checkpoint.com/defense/advisories/public/2010/cpai-10-May.html","https://ubuntu.com/security/notices/USN-961-1","https://www.cve.org/CVERecord?id=CVE-2010-1869"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/ghostscript/+bug/546009","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-1869","http://bugs.ghostscript.com/show_bug.cgi?id=690902"],"patches":{"ghostscript":["upstream: http://svn.ghostscript.com/viewvc?view=rev&revision=10312"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.61.dfsg.1-1ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"8.64.dfsg.1-0ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"8.70.dfsg.1-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"8.71.dfsg.1-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.71","component":null,"pocket":"security"}]},{"name":"gs-afpl","source":"https://ubuntu.com/security/cve?package=gs-afpl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gs-afpl","debian":"https://tracker.debian.org/pkg/gs-afpl","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gs-esp","source":"https://ubuntu.com/security/cve?package=gs-esp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gs-esp","debian":"https://tracker.debian.org/pkg/gs-esp","statuses":[{"release_codename":"dapper","status":"not-affected","description":"doesn't reproduce","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gs-gpl","source":"https://ubuntu.com/security/cve?package=gs-gpl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gs-gpl","debian":"https://tracker.debian.org/pkg/gs-gpl","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-961-1"],"notices":[{"id":"USN-961-1","title":"Ghostscript vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-07-13T18:22:58.606419","description":"David Srbecky discovered that Ghostscript incorrectly handled debug\nlogging. If a user or automated system were tricked into opening a crafted\nPDF file, an attacker could cause a denial of service or execute arbitrary\ncode with privileges of the user invoking the program. This issue only\naffected Ubuntu 9.04 and Ubuntu 9.10. The default compiler options for\naffected releases should reduce the vulnerability to a denial of service.\n(CVE-2009-4270)\n\nIt was discovered that Ghostscript incorrectly handled certain malformed\nfiles. If a user or automated system were tricked into opening a crafted\nPostscript or PDF file, an attacker could cause a denial of service or\nexecute arbitrary code with privileges of the user invoking the program.\nThis issue only affected Ubuntu 8.04 LTS and Ubuntu 9.04. (CVE-2009-4897)\n\nDan Rosenberg discovered that Ghostscript incorrectly handled certain\nrecursive Postscript files. If a user or automated system were tricked into\nopening a crafted Postscript file, an attacker could cause a denial of\nservice or execute arbitrary code with privileges of the user invoking the\nprogram. (CVE-2010-1628)\n\nRodrigo Rubira Branco and Dan Rosenberg discovered that Ghostscript\nincorrectly handled certain malformed Postscript files. If a user or\nautomated system were tricked into opening a crafted Postscript file, an\nattacker could cause a denial of service or execute arbitrary code with\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS, 9.04 and 9.10. (CVE-2010-1869)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"ghostscript","version":"8.61.dfsg.1-1ubuntu3.3","description":"","is_source":true},{"name":"libgs8","version":"8.61.dfsg.1-1ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.61.dfsg.1-1ubuntu3.3"}],"lucid":[{"name":"ghostscript","version":"8.71.dfsg.1-0ubuntu5.2","description":"","is_source":true},{"name":"libgs8","version":"8.71.dfsg.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.71.dfsg.1-0ubuntu5.2"}],"jaunty":[{"name":"ghostscript","version":"8.64.dfsg.1-0ubuntu8.1","description":"","is_source":true},{"name":"libgs8","version":"8.64.dfsg.1-0ubuntu8.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.64.dfsg.1-0ubuntu8.1"}],"karmic":[{"name":"ghostscript","version":"8.70.dfsg.1-0ubuntu3.1","description":"","is_source":true},{"name":"libgs8","version":"8.70.dfsg.1-0ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.70.dfsg.1-0ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2010-1628","CVE-2010-1869","CVE-2009-4270","CVE-2009-4897"]}]},{"id":"CVE-2010-1000","published":"2010-05-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3\nallows remote attackers to create arbitrary files via directory traversal\nsequences in the name attribute of a file element in a metalink file.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"overwrite of arbitrary files with permissions of user invoking the\nprogram. When combined with startup programs and sourced files can lead to\narbitrary remote code execution."}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-938-1","http://kde.org/info/security/advisory-20100513-1.txt","https://www.cve.org/CVERecord?id=CVE-2010-1000"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/kdenetwork/+bug/578856"],"patches":{"kdenetwork":[]},"tags":{},"packages":[{"name":"kdenetwork","source":"https://ubuntu.com/security/cve?package=kdenetwork","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdenetwork","debian":"https://tracker.debian.org/pkg/kdenetwork","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4:4.2.2-0ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"4:4.3.2-0ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"4:4.4.2-0ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:4.5.0b","component":null,"pocket":"security"}]}],"notices_ids":["USN-938-1"],"notices":[{"id":"USN-938-1","title":"KDENetwork vulnerabilities","summary":"","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2010-05-13T08:40:38.010139","description":"It was discovered that KGet did not properly perform input validation when\nprocessing metalink files. If a user were tricked into opening a crafted\nmetalink file, a remote attacker could overwrite files via directory\ntraversal, which could eventually lead to arbitrary code execution.\n(CVE-2010-1000)\n\nIt was discovered that KGet would not always wait for user confirmation\nwhen downloading metalink files. If a user selected a file to download\nbut did not confirm or cancel the download, KGet would proceed with the\ndownload, overwriting any file with the same name. This issue only\naffected Ubuntu 10.04 LTS. (CVE-2010-1511) ","is_hidden":false,"release_packages":{"lucid":[{"name":"kdenetwork","version":"4:4.4.2-0ubuntu4.1","description":"","is_source":true},{"name":"kget","version":"4:4.4.2-0ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdenetwork","version_link":"https://launchpad.net/ubuntu/+source/kdenetwork/4:4.4.2-0ubuntu4.1"}],"jaunty":[{"name":"kdenetwork","version":"4:4.2.2-0ubuntu2.3","description":"","is_source":true},{"name":"kget","version":"4:4.2.2-0ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdenetwork","version_link":"https://launchpad.net/ubuntu/+source/kdenetwork/4:4.2.2-0ubuntu2.3"}],"karmic":[{"name":"kdenetwork","version":"4:4.3.2-0ubuntu4.1","description":"","is_source":true},{"name":"kget","version":"4:4.3.2-0ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdenetwork","version_link":"https://launchpad.net/ubuntu/+source/kdenetwork/4:4.3.2-0ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2010-1000","CVE-2010-1511"]}]},{"id":"CVE-2009-4897","published":"2010-05-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption) via a crafted PDF document containing a long name.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"reproducer doesn't seem to affect dapper"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-961-1","https://www.cve.org/CVERecord?id=CVE-2009-4897"],"bugs":["http://bugs.ghostscript.com/show_bug.cgi?id=690523"],"patches":{"ghostscript":["upstream: http://svn.ghostscript.com/viewvc?view=rev&revision=9797"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.61.dfsg.1-1ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"8.64.dfsg.1-0ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"8.70.dfsg.1-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"8.71.dfsg.1-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.70","component":null,"pocket":"security"}]},{"name":"gs-afpl","source":"https://ubuntu.com/security/cve?package=gs-afpl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gs-afpl","debian":"https://tracker.debian.org/pkg/gs-afpl","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gs-esp","source":"https://ubuntu.com/security/cve?package=gs-esp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gs-esp","debian":"https://tracker.debian.org/pkg/gs-esp","statuses":[{"release_codename":"dapper","status":"not-affected","description":"doesn't reproduce","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gs-gpl","source":"https://ubuntu.com/security/cve?package=gs-gpl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gs-gpl","debian":"https://tracker.debian.org/pkg/gs-gpl","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-961-1"],"notices":[{"id":"USN-961-1","title":"Ghostscript vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-07-13T18:22:58.606419","description":"David Srbecky discovered that Ghostscript incorrectly handled debug\nlogging. If a user or automated system were tricked into opening a crafted\nPDF file, an attacker could cause a denial of service or execute arbitrary\ncode with privileges of the user invoking the program. This issue only\naffected Ubuntu 9.04 and Ubuntu 9.10. The default compiler options for\naffected releases should reduce the vulnerability to a denial of service.\n(CVE-2009-4270)\n\nIt was discovered that Ghostscript incorrectly handled certain malformed\nfiles. If a user or automated system were tricked into opening a crafted\nPostscript or PDF file, an attacker could cause a denial of service or\nexecute arbitrary code with privileges of the user invoking the program.\nThis issue only affected Ubuntu 8.04 LTS and Ubuntu 9.04. (CVE-2009-4897)\n\nDan Rosenberg discovered that Ghostscript incorrectly handled certain\nrecursive Postscript files. If a user or automated system were tricked into\nopening a crafted Postscript file, an attacker could cause a denial of\nservice or execute arbitrary code with privileges of the user invoking the\nprogram. (CVE-2010-1628)\n\nRodrigo Rubira Branco and Dan Rosenberg discovered that Ghostscript\nincorrectly handled certain malformed Postscript files. If a user or\nautomated system were tricked into opening a crafted Postscript file, an\nattacker could cause a denial of service or execute arbitrary code with\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS, 9.04 and 9.10. (CVE-2010-1869)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"ghostscript","version":"8.61.dfsg.1-1ubuntu3.3","description":"","is_source":true},{"name":"libgs8","version":"8.61.dfsg.1-1ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.61.dfsg.1-1ubuntu3.3"}],"lucid":[{"name":"ghostscript","version":"8.71.dfsg.1-0ubuntu5.2","description":"","is_source":true},{"name":"libgs8","version":"8.71.dfsg.1-0ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.71.dfsg.1-0ubuntu5.2"}],"jaunty":[{"name":"ghostscript","version":"8.64.dfsg.1-0ubuntu8.1","description":"","is_source":true},{"name":"libgs8","version":"8.64.dfsg.1-0ubuntu8.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.64.dfsg.1-0ubuntu8.1"}],"karmic":[{"name":"ghostscript","version":"8.70.dfsg.1-0ubuntu3.1","description":"","is_source":true},{"name":"libgs8","version":"8.70.dfsg.1-0ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.70.dfsg.1-0ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2010-1628","CVE-2010-1869","CVE-2009-4270","CVE-2009-4897"]}]},{"id":"CVE-2009-4855","published":"2010-05-11T12:02:00","updated_at":"2026-08-06T19:09:55.382340+00:00","description":"\nSQL injection vulnerability in index.php in TYPO3 4.0 allows remote\nattackers to execute arbitrary SQL commands via the showUid parameter.\nNOTE: the TYPO3 Security Team disputes this report, stating that \"there is\nno such vulnerability... The showUid parameter is generally used in\nthird-party TYPO3 extensions - not in TYPO3 Core.","ubuntu_description":"","notes":[{"author":"debian","note":"Bogus issue claimed for typo3"},{"author":"mdeslaur","note":"This issue was disputed by type3 developers."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://secure.t3sec.info/blog/post/2009/08/06/typo3-cms-40-showuid-exploit-not-a-vulnerability/4.2.5-1+lenny3","https://www.cve.org/CVERecord?id=CVE-2009-4855"],"bugs":[""],"patches":{"typo3-src":[]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"dapper","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [disputed]","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1864","published":"2010-05-07T23:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe addcslashes function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2\nallows context-dependent attackers to obtain sensitive information (memory\ncontents) by causing a userspace interruption of an internal function,\nrelated to the call time pass by reference feature.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is MOPS-2010-006\ninterruption issue, safe_mode - open_basedir bypass, ignoring"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/03/mops-2010-006-php-addcslashes-interruption-information-leak-vulnerability/index.html","http://www.php.net/releases/5_3_3.php","https://www.cve.org/CVERecord?id=CVE-2010-1864"],"bugs":[""],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=298945","upstream: http://svn.php.net/viewvc?view=revision&revision=299240"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1862","published":"2010-05-07T23:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe chunk_split function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2\nallows context-dependent attackers to obtain sensitive information (memory\ncontents) by causing a userspace interruption of an internal function,\nrelated to the call time pass by reference feature.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is MOPS-2010-008\ninterruption issue, safe_mode - open_basedir bypass, ignoring\nSee CVE-2010-1864 for patch"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/04/mops-2010-008-php-chunk_split-interruption-information-leak-vulnerability/index.html","http://www.php.net/releases/5_3_3.php","https://www.cve.org/CVERecord?id=CVE-2010-1862"],"bugs":[""],"patches":{"php5":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1861","published":"2010-05-07T23:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2\nallows context-dependent attackers to write to arbitrary memory addresses\nby using an object's __sleep function to interrupt an internal call to the\nshm_put_var function, which triggers access of a freed resource.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is MOPS-2010-009\ninterruption issue, safe_mode - open_basedir bypass, ignoring"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/05/mops-2010-009-php-shm_put_var-already-freed-resource-access-vulnerability/index.html","http://www.php.net/releases/5_3_3.php","https://www.cve.org/CVERecord?id=CVE-2010-1861"],"bugs":[""],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=299328"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1860","published":"2010-05-07T23:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe html_entity_decode function in PHP 5.2 through 5.2.13 and 5.3 through\n5.3.2 allows context-dependent attackers to obtain sensitive information\n(memory contents) or trigger memory corruption by causing a userspace\ninterruption of an internal call, related to the call time pass by\nreference feature.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is MOPS-2010-010\nreproducer in report\ninterruption issue, safe_mode - open_basedir bypass, ignoring\nSee CVE-2010-1864 for patch"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/06/mops-2010-010-php-html_entity_decode-interruption-information-leak-vulnerability/index.html","http://www.php.net/releases/5_3_3.php","https://www.cve.org/CVERecord?id=CVE-2010-1860"],"bugs":[""],"patches":{"php5":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1853","published":"2010-05-07T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in the tr_magnetParse function in\nlibtransmission/magnet.c in Transmission 1.91 allow remote attackers to\ncause a denial of service (crash) or possibly execute arbitrary code via a\ncrafted magnet URL with a large number of (1) tr or (2) ws links.","ubuntu_description":"","notes":[{"author":"kees","note":"stack-protector is in use on all releases"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1853"],"bugs":["https://trac.transmissionbt.com/ticket/2965"],"patches":{"transmission":["upstream: https://trac.transmissionbt.com/changeset/10279"]},"tags":{},"packages":[{"name":"transmission","source":"https://ubuntu.com/security/cve?package=transmission","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=transmission","debian":"https://tracker.debian.org/pkg/transmission","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.93-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.92","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1167","published":"2010-05-07T18:24:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not\nproperly handle invalid characters in a multi-character locale, which\nallows remote attackers to cause a denial of service (memory consumption\nand application crash) via a crafted (1) message header or (2) POP3 UIDL\nlist.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1167"],"bugs":[""],"patches":{"fetchmail":[]},"tags":{},"packages":[{"name":"fetchmail","source":"https://ubuntu.com/security/cve?package=fetchmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fetchmail","debian":"https://tracker.debian.org/pkg/fetchmail","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6.3.17-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"6.3.17-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"6.3.17-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"6.3.17-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"6.3.17-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"6.3.17-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"6.3.17-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.3.17","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"6.3.17-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"6.3.17-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [6.3.17-4ubuntu1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1868","published":"2010-05-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) sqlite_single_query and (2) sqlite_array_query functions in\next/sqlite/sqlite.c in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow\ncontext-dependent attackers to execute arbitrary code by calling these\nfunctions with an empty SQL query, which triggers access of uninitialized\nmemory.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"SQLite version 2\nThis is MOPS-2010-012 and MOPS-2010-013"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://php-security.org/2010/05/07/mops-2010-012-php-sqlite_single_query-uninitialized-memory-usage-vulnerability/index.html","http://php-security.org/2010/05/07/mops-2010-013-php-sqlite_array_query-uninitialized-memory-usage-vulnerability/index.html","http://php-security.org/2010/05/07/mops-submission-03-sqlite_single_query-sqlite_array_query-uninitialized-memory-usage/index.html","http://www.php.net/releases/5_3_3.php","https://ubuntu.com/security/notices/USN-989-1","https://www.cve.org/CVERecord?id=CVE-2010-1868"],"bugs":[""],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=298697"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.19","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.12","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.2.6.dfsg.1-3ubuntu4.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-989-1"],"notices":[{"id":"USN-989-1","title":"PHP vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-20T18:22:04.757285","description":"Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc\nrequests. An attacker could exploit this issue to cause the PHP server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2010-0397)\n\nIt was discovered that the pseudorandom number generator in PHP did not\nprovide the expected entropy. An attacker could exploit this issue to\npredict values that were intended to be random, such as session cookies.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10.\n(CVE-2010-1128)\n\nIt was discovered that PHP did not properly handle directory pathnames that\nlacked a trailing slash character. An attacker could exploit this issue to\nbypass safe_mode restrictions. This issue only affected Ubuntu 6.06 LTS,\n8.04 LTS, 9.04 and 9.10. (CVE-2010-1129)\n\nGrzegorz Stachowiak discovered that the PHP session extension did not\nproperly handle semicolon characters. An attacker could exploit this issue\nto bypass safe_mode restrictions. This issue only affected Ubuntu 8.04 LTS,\n9.04 and 9.10. (CVE-2010-1130)\n\nStefan Esser discovered that PHP incorrectly decoded remote HTTP chunked\nencoding streams. An attacker could exploit this issue to cause the PHP\nserver to crash and possibly execute arbitrary code with application\nprivileges. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-1866)\n\nMateusz Kocielski discovered that certain PHP SQLite functions incorrectly\nhandled empty SQL queries. An attacker could exploit this issue to possibly\nexecute arbitrary code with application privileges. (CVE-2010-1868)\n\nMateusz Kocielski discovered that PHP incorrectly handled certain arguments\nto the fnmatch function. An attacker could exploit this flaw and cause the\nPHP server to consume all available stack memory, resulting in a denial of\nservice. (CVE-2010-1917)\n\nStefan Esser discovered that PHP incorrectly handled certain strings in the\nphar extension. An attacker could exploit this flaw to possibly view\nsensitive information. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2010-2094, CVE-2010-2950)\n\nStefan Esser discovered that PHP incorrectly handled deserialization of\nSPLObjectStorage objects. A remote attacker could exploit this issue to\nview sensitive information and possibly execute arbitrary code with\napplication privileges. This issue only affected Ubuntu 8.04 LTS, 9.04,\n9.10 and 10.04 LTS. (CVE-2010-2225)\n\nIt was discovered that PHP incorrectly filtered error messages when limits\nfor memory, execution time, or recursion were exceeded. A remote attacker\ncould exploit this issue to possibly view sensitive information.\n(CVE-2010-2531)\n\nStefan Esser discovered that the PHP session serializer incorrectly handled\nthe PS_UNDEF_MARKER marker. An attacker could exploit this issue to alter\narbitrary session variables. (CVE-2010-3065)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.12","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.5","description":"","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.19","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"}],"jaunty":[{"name":"php5","version":"5.2.6.dfsg.1-3ubuntu4.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"php5-cgi","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"libapache2-mod-php5","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"}]},"type":"USN","cves_ids":["CVE-2010-0397","CVE-2010-1128","CVE-2010-1129","CVE-2010-1130","CVE-2010-1866","CVE-2010-1868","CVE-2010-1917","CVE-2010-2094","CVE-2010-2225","CVE-2010-2531","CVE-2010-2950","CVE-2010-3065"]}]},{"id":"CVE-2010-1866","published":"2010-05-07T00:00:00","updated_at":"2025-08-25T19:56:55.356806+00:00","description":"\nThe dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked\nencoding stream, allows context-dependent attackers to cause a denial of\nservice (crash) and possibly trigger memory corruption via a negative chunk\nsize, which bypasses a signed comparison, related to an integer overflow in\nthe chunk size decoder.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"5.3 only\nThis is MOPS-2010-003"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://php-security.org/2010/05/02/mops-2010-003-php-dechunk-filter-signed-comparison-vulnerability/index.html","http://www.php.net/releases/5_3_3.php","https://ubuntu.com/security/notices/USN-989-1","https://www.cve.org/CVERecord?id=CVE-2010-1866"],"bugs":[""],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=298700"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"5.1.2-1ubuntu3.18","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu5.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.2.6.dfsg.1-3ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.2.10.dfsg.1-2ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-989-1"],"notices":[{"id":"USN-989-1","title":"PHP vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-20T18:22:04.757285","description":"Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc\nrequests. An attacker could exploit this issue to cause the PHP server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2010-0397)\n\nIt was discovered that the pseudorandom number generator in PHP did not\nprovide the expected entropy. An attacker could exploit this issue to\npredict values that were intended to be random, such as session cookies.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10.\n(CVE-2010-1128)\n\nIt was discovered that PHP did not properly handle directory pathnames that\nlacked a trailing slash character. An attacker could exploit this issue to\nbypass safe_mode restrictions. This issue only affected Ubuntu 6.06 LTS,\n8.04 LTS, 9.04 and 9.10. (CVE-2010-1129)\n\nGrzegorz Stachowiak discovered that the PHP session extension did not\nproperly handle semicolon characters. An attacker could exploit this issue\nto bypass safe_mode restrictions. This issue only affected Ubuntu 8.04 LTS,\n9.04 and 9.10. (CVE-2010-1130)\n\nStefan Esser discovered that PHP incorrectly decoded remote HTTP chunked\nencoding streams. An attacker could exploit this issue to cause the PHP\nserver to crash and possibly execute arbitrary code with application\nprivileges. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-1866)\n\nMateusz Kocielski discovered that certain PHP SQLite functions incorrectly\nhandled empty SQL queries. An attacker could exploit this issue to possibly\nexecute arbitrary code with application privileges. (CVE-2010-1868)\n\nMateusz Kocielski discovered that PHP incorrectly handled certain arguments\nto the fnmatch function. An attacker could exploit this flaw and cause the\nPHP server to consume all available stack memory, resulting in a denial of\nservice. (CVE-2010-1917)\n\nStefan Esser discovered that PHP incorrectly handled certain strings in the\nphar extension. An attacker could exploit this flaw to possibly view\nsensitive information. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2010-2094, CVE-2010-2950)\n\nStefan Esser discovered that PHP incorrectly handled deserialization of\nSPLObjectStorage objects. A remote attacker could exploit this issue to\nview sensitive information and possibly execute arbitrary code with\napplication privileges. This issue only affected Ubuntu 8.04 LTS, 9.04,\n9.10 and 10.04 LTS. (CVE-2010-2225)\n\nIt was discovered that PHP incorrectly filtered error messages when limits\nfor memory, execution time, or recursion were exceeded. A remote attacker\ncould exploit this issue to possibly view sensitive information.\n(CVE-2010-2531)\n\nStefan Esser discovered that the PHP session serializer incorrectly handled\nthe PS_UNDEF_MARKER marker. An attacker could exploit this issue to alter\narbitrary session variables. (CVE-2010-3065)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.12","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.5","description":"","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.19","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"}],"jaunty":[{"name":"php5","version":"5.2.6.dfsg.1-3ubuntu4.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"php5-cgi","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"libapache2-mod-php5","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"}]},"type":"USN","cves_ids":["CVE-2010-0397","CVE-2010-1128","CVE-2010-1129","CVE-2010-1130","CVE-2010-1866","CVE-2010-1868","CVE-2010-1917","CVE-2010-2094","CVE-2010-2225","CVE-2010-2531","CVE-2010-2950","CVE-2010-3065"]}]},{"id":"CVE-2010-1451","published":"2010-05-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux\nkernel before 2.6.33 on the SPARC platform does not properly obtain the\nvalue of a certain _PAGE_EXEC_4U bit and consequently does not properly\nimplement a non-executable stack, which makes it easier for\ncontext-dependent attackers to exploit stack-based buffer overflows via a\ncrafted application.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-966-1","https://www.cve.org/CVERecord?id=CVE-2010-1451"],"bugs":[""],"patches":{"linux-source-2.6.15":["dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1451/patches/dapper/linux/0001-sparc64-Fix-sun4u-execute-bit-check-in-TSB-I-TLB-load.txt"],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=1f474646fdc36b457606bbcd6a3592e6cbd31ac4","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1451/patches/hardy/linux/0001-sparc64-Fix-sun4u-execute-bit-check-in-TSB-I-TLB-load.txt","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1451/patches/jaunty/linux/0001-sparc64-Fix-sun4u-execute-bit-check-in-TSB-I-TLB-load.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1451/patches/karmic/linux/0001-sparc64-Fix-sun4u-execute-bit-check-in-TSB-I-TLB-load.txt"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.73","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.62","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.61","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-17.26","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.86","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33","component":null,"pocket":"security"}]}],"notices_ids":["USN-966-1"],"notices":[{"id":"USN-966-1","title":"Linux kernel vulnerabilities","summary":"Multiple security flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2010-08-04T21:59:24.858998","description":"Junjiro R. Okajima discovered that knfsd did not correctly handle\nstrict overcommit. A local attacker could exploit this to crash knfsd,\nleading to a denial of service. (Only Ubuntu 6.06 LTS and 8.04 LTS were\naffected.) (CVE-2008-7256, CVE-2010-1643)\n\nChris Guo, Jukka Taimisto, and Olli Jarva discovered that SCTP did\nnot correctly handle invalid parameters. A remote attacker could send\nspecially crafted traffic that could crash the system, leading to a\ndenial of service. (CVE-2010-1173)\n\nMario Mikocevic discovered that GFS2 did not correctly handle certain\nquota structures. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (Ubuntu 6.06 LTS was not\naffected.) (CVE-2010-1436)\n\nToshiyuki Okajima discovered that the kernel keyring did not correctly\nhandle dead keyrings. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-1437)\n\nBrad Spengler discovered that Sparc did not correctly implement\nnon-executable stacks. This made userspace applications vulnerable to\nexploits that would have been otherwise blocked due to non-executable\nmemory protections. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1451)\n\nDan Rosenberg discovered that the btrfs clone function did not correctly\nvalidate permissions. A local attacker could exploit this to read\nsensitive information, leading to a loss of privacy. (Only Ubuntu 9.10\nwas affected.) (CVE-2010-1636)\n\nDan Rosenberg discovered that GFS2 set_flags function did not correctly\nvalidate permissions. A local attacker could exploit this to gain\naccess to files, leading to a loss of privacy and potential privilege\nescalation. (Ubuntu 6.06 LTS was not affected.) (CVE-2010-1641)\n\nShi Weihua discovered that btrfs xattr_set_acl function did not\ncorrectly validate permissions. A local attacker could exploit\nthis to gain access to files, leading to a loss of privacy and\npotential privilege escalation. (Only Ubuntu 9.10 and 10.04 LTS were\naffected.) (CVE-2010-2071)\n\nAndre Osterhues discovered that eCryptfs did not correctly calculate\nhash values. A local attacker with certain uids could exploit this to\ncrash the system or potentially gain root privileges. (Ubuntu 6.06 LTS\nwas not affected.) (CVE-2010-2492)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.29","description":"Linux kernel for MVL Dove","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.16","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.61","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.16","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.16"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.29","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.29"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.29","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.29"}],"hardy":[{"name":"linux","version":"2.6.24-28.73","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"}],"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-207.21","description":"Linux kernel for MVL Dove","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-502.9","description":"Linux kernel for TI Omap","is_source":true},{"name":"linux-ec2","version":"2.6.32-308.14","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-24.39","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.33-502-omap","version":"2.6.33-502.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-502.9"},{"name":"linux-image-2.6.32-308-ec2","version":"2.6.32-308.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-308.14"},{"name":"linux-image-2.6.32-207-dove","version":"2.6.32-207.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-207.21"},{"name":"linux-image-2.6.32-24-386","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-powerpc","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-powerpc64-smp","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-generic-pae","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-versatile","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-generic","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-virtual","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-server","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-ia64","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-sparc64-smp","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-preempt","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-powerpc-smp","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-sparc64","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-lpia","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.86","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"}],"jaunty":[{"name":"linux","version":"2.6.28-19.62","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"}]},"type":"USN","cves_ids":["CVE-2008-7256","CVE-2010-1173","CVE-2010-1436","CVE-2010-1437","CVE-2010-1451","CVE-2010-1636","CVE-2010-1641","CVE-2010-1643","CVE-2010-2071","CVE-2010-2492"]}]},{"id":"CVE-2010-1437","published":"2010-05-07T00:00:00","updated_at":"2025-08-25T19:55:58.957700+00:00","description":"\nRace condition in the find_keyring_by_name function in\nsecurity/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows\nlocal users to cause a denial of service (memory corruption and system\ncrash) or possibly have unspecified other impact via keyctl session\ncommands that trigger access to a dead keyring that is undergoing deletion\nby the key_cleanup function.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-966-1","https://www.cve.org/CVERecord?id=CVE-2010-1437"],"bugs":[""],"patches":{"linux-source-2.6.15":["dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1437/patches/dapper/linux/0001-KEYS-find_keyring_by_name-can-gain-access-to-a-freed-k.txt"],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=cea7daa3589d6b550546a8c8963599f7c1a3ae5c","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1437/patches/hardy/linux/0001-KEYS-find_keyring_by_name-can-gain-access-to-a-freed-k.txt","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1437/patches/jaunty/linux/0001-KEYS-find_keyring_by_name-can-gain-access-to-a-freed-k.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1437/patches/karmic/linux/0001-KEYS-find_keyring_by_name-can-gain-access-to-a-freed-k.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1437/patches/lucid/linux/0001-KEYS-find_keyring_by_name-can-gain-access-to-a-freed-k.txt"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.73","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.62","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.61","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-24.39","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc7","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.86","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc7","component":null,"pocket":"security"}]}],"notices_ids":["USN-966-1"],"notices":[{"id":"USN-966-1","title":"Linux kernel vulnerabilities","summary":"Multiple security flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2010-08-04T21:59:24.858998","description":"Junjiro R. Okajima discovered that knfsd did not correctly handle\nstrict overcommit. A local attacker could exploit this to crash knfsd,\nleading to a denial of service. (Only Ubuntu 6.06 LTS and 8.04 LTS were\naffected.) (CVE-2008-7256, CVE-2010-1643)\n\nChris Guo, Jukka Taimisto, and Olli Jarva discovered that SCTP did\nnot correctly handle invalid parameters. A remote attacker could send\nspecially crafted traffic that could crash the system, leading to a\ndenial of service. (CVE-2010-1173)\n\nMario Mikocevic discovered that GFS2 did not correctly handle certain\nquota structures. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (Ubuntu 6.06 LTS was not\naffected.) (CVE-2010-1436)\n\nToshiyuki Okajima discovered that the kernel keyring did not correctly\nhandle dead keyrings. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-1437)\n\nBrad Spengler discovered that Sparc did not correctly implement\nnon-executable stacks. This made userspace applications vulnerable to\nexploits that would have been otherwise blocked due to non-executable\nmemory protections. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1451)\n\nDan Rosenberg discovered that the btrfs clone function did not correctly\nvalidate permissions. A local attacker could exploit this to read\nsensitive information, leading to a loss of privacy. (Only Ubuntu 9.10\nwas affected.) (CVE-2010-1636)\n\nDan Rosenberg discovered that GFS2 set_flags function did not correctly\nvalidate permissions. A local attacker could exploit this to gain\naccess to files, leading to a loss of privacy and potential privilege\nescalation. (Ubuntu 6.06 LTS was not affected.) (CVE-2010-1641)\n\nShi Weihua discovered that btrfs xattr_set_acl function did not\ncorrectly validate permissions. A local attacker could exploit\nthis to gain access to files, leading to a loss of privacy and\npotential privilege escalation. (Only Ubuntu 9.10 and 10.04 LTS were\naffected.) (CVE-2010-2071)\n\nAndre Osterhues discovered that eCryptfs did not correctly calculate\nhash values. A local attacker with certain uids could exploit this to\ncrash the system or potentially gain root privileges. (Ubuntu 6.06 LTS\nwas not affected.) (CVE-2010-2492)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.29","description":"Linux kernel for MVL Dove","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.16","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.61","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.16","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.16"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.29","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.29"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.29","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.29"}],"hardy":[{"name":"linux","version":"2.6.24-28.73","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"}],"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-207.21","description":"Linux kernel for MVL Dove","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-502.9","description":"Linux kernel for TI Omap","is_source":true},{"name":"linux-ec2","version":"2.6.32-308.14","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-24.39","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.33-502-omap","version":"2.6.33-502.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-502.9"},{"name":"linux-image-2.6.32-308-ec2","version":"2.6.32-308.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-308.14"},{"name":"linux-image-2.6.32-207-dove","version":"2.6.32-207.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-207.21"},{"name":"linux-image-2.6.32-24-386","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-powerpc","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-powerpc64-smp","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-generic-pae","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-versatile","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-generic","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-virtual","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-server","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-ia64","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-sparc64-smp","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-preempt","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-powerpc-smp","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-sparc64","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-lpia","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.86","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"}],"jaunty":[{"name":"linux","version":"2.6.28-19.62","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"}]},"type":"USN","cves_ids":["CVE-2008-7256","CVE-2010-1173","CVE-2010-1436","CVE-2010-1437","CVE-2010-1451","CVE-2010-1636","CVE-2010-1641","CVE-2010-1643","CVE-2010-2071","CVE-2010-2492"]}]},{"id":"CVE-2010-1173","published":"2010-05-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the\nLinux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote\nattackers to cause a denial of service (system crash) via an SCTPChunkInit\npacket containing multiple invalid parameters that require a large amount\nof error data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-966-1","https://www.cve.org/CVERecord?id=CVE-2010-1173"],"bugs":[""],"patches":{"linux-source-2.6.15":["dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/dapper/linux/0001-sctp-Fix-skb_over_panic-resulting-from-multiple-invali.txt","dapper: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/dapper/linux/0002-sctp-fix-append-error-cause-to-ERROR-chunk-correctly.txt"],"linux":["hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/hardy/linux/0001-sctp-Fix-skb_over_panic-resulting-from-multiple-invali.txt","hardy: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/hardy/linux/0002-sctp-fix-append-error-cause-to-ERROR-chunk-correctly.txt","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/jaunty/linux/0001-sctp-Fix-skb_over_panic-resulting-from-multiple-invali.txt","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/jaunty/linux/0002-sctp-fix-append-error-cause-to-ERROR-chunk-correctly.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/karmic/linux/0001-sctp-Fix-skb_over_panic-resulting-from-multiple-invali.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/karmic/linux/0002-sctp-fix-append-error-cause-to-ERROR-chunk-correctly.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/lucid/linux/0001-sctp-Fix-skb_over_panic-resulting-from-multiple-invali.txt","lucid: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-1173/patches/lucid/linux/0002-sctp-fix-append-error-cause-to-ERROR-chunk-correctly.txt"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.73","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.62","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.61","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-24.39","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"v2.6.34-rc7","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.86","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-966-1"],"notices":[{"id":"USN-966-1","title":"Linux kernel vulnerabilities","summary":"Multiple security flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2010-08-04T21:59:24.858998","description":"Junjiro R. Okajima discovered that knfsd did not correctly handle\nstrict overcommit. A local attacker could exploit this to crash knfsd,\nleading to a denial of service. (Only Ubuntu 6.06 LTS and 8.04 LTS were\naffected.) (CVE-2008-7256, CVE-2010-1643)\n\nChris Guo, Jukka Taimisto, and Olli Jarva discovered that SCTP did\nnot correctly handle invalid parameters. A remote attacker could send\nspecially crafted traffic that could crash the system, leading to a\ndenial of service. (CVE-2010-1173)\n\nMario Mikocevic discovered that GFS2 did not correctly handle certain\nquota structures. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (Ubuntu 6.06 LTS was not\naffected.) (CVE-2010-1436)\n\nToshiyuki Okajima discovered that the kernel keyring did not correctly\nhandle dead keyrings. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-1437)\n\nBrad Spengler discovered that Sparc did not correctly implement\nnon-executable stacks. This made userspace applications vulnerable to\nexploits that would have been otherwise blocked due to non-executable\nmemory protections. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1451)\n\nDan Rosenberg discovered that the btrfs clone function did not correctly\nvalidate permissions. A local attacker could exploit this to read\nsensitive information, leading to a loss of privacy. (Only Ubuntu 9.10\nwas affected.) (CVE-2010-1636)\n\nDan Rosenberg discovered that GFS2 set_flags function did not correctly\nvalidate permissions. A local attacker could exploit this to gain\naccess to files, leading to a loss of privacy and potential privilege\nescalation. (Ubuntu 6.06 LTS was not affected.) (CVE-2010-1641)\n\nShi Weihua discovered that btrfs xattr_set_acl function did not\ncorrectly validate permissions. A local attacker could exploit\nthis to gain access to files, leading to a loss of privacy and\npotential privilege escalation. (Only Ubuntu 9.10 and 10.04 LTS were\naffected.) (CVE-2010-2071)\n\nAndre Osterhues discovered that eCryptfs did not correctly calculate\nhash values. A local attacker with certain uids could exploit this to\ncrash the system or potentially gain root privileges. (Ubuntu 6.06 LTS\nwas not affected.) (CVE-2010-2492)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.29","description":"Linux kernel for MVL Dove","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.16","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.61","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.16","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.16"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.29","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.29"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.61"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.29","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.29"}],"hardy":[{"name":"linux","version":"2.6.24-28.73","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.73"}],"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-207.21","description":"Linux kernel for MVL Dove","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-502.9","description":"Linux kernel for TI Omap","is_source":true},{"name":"linux-ec2","version":"2.6.32-308.14","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-24.39","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.33-502-omap","version":"2.6.33-502.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-502.9"},{"name":"linux-image-2.6.32-308-ec2","version":"2.6.32-308.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-308.14"},{"name":"linux-image-2.6.32-207-dove","version":"2.6.32-207.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-207.21"},{"name":"linux-image-2.6.32-24-386","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-powerpc","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-powerpc64-smp","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-generic-pae","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-versatile","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-generic","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-virtual","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-server","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-ia64","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-sparc64-smp","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-preempt","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-powerpc-smp","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-sparc64","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"},{"name":"linux-image-2.6.32-24-lpia","version":"2.6.32-24.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-24.39"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.86","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.86"}],"jaunty":[{"name":"linux","version":"2.6.28-19.62","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.62"}]},"type":"USN","cves_ids":["CVE-2008-7256","CVE-2010-1173","CVE-2010-1436","CVE-2010-1437","CVE-2010-1451","CVE-2010-1636","CVE-2010-1641","CVE-2010-1643","CVE-2010-2071","CVE-2010-2492"]}]},{"id":"CVE-2010-1738","published":"2010-05-06T18:30:00","updated_at":"2025-08-04T19:23:46.919224+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2010-1448. Reason: This candidate is a duplicate of CVE-2010-1448.\nNotes: All CVE users should reference CVE-2010-1448 instead of this\ncandidate. All references and descriptions in this candidate have been\nremoved to prevent accidental usage","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1738"],"bugs":[""],"patches":{"lxr-cvs":[],"lxr":[]},"tags":{},"packages":[{"name":"lxr","source":"https://ubuntu.com/security/cve?package=lxr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxr","debian":"https://tracker.debian.org/pkg/lxr","statuses":[{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxr-cvs","source":"https://ubuntu.com/security/cve?package=lxr-cvs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxr-cvs","debian":"https://tracker.debian.org/pkg/lxr-cvs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1731","published":"2010-05-06T14:53:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome on the HTC Hero allows remote attackers to cause a denial of\nservice (application crash) via JavaScript that writes sequences\nin an infinite loop.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian, CVE-2010-1729/1730/1731 are the same issue but with\ndifferent effects. This is the chromium-browser CVE\nper Debian, dos-only"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://h.ackack.net/overflow-in-webkit-dll-safari-and-opera.html","https://www.cve.org/CVERecord?id=CVE-2010-1731"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1730","published":"2010-05-06T14:53:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDolphin Browser 2.5.0 on the HTC Hero allows remote attackers to cause a\ndenial of service (application crash) via JavaScript that writes \nsequences in an infinite loop.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian, CVE-2010-1729/1730/1731 are the same issue but with\ndifferent effects. This is the KDE CVE\nper Debian, dos-only"},{"author":"mdeslaur","note":"this doesn't look like it applies to kdelibs, can be changed\nback if proved otherwise."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://h.ackack.net/overflow-in-webkit-dll-safari-and-opera.html","https://www.cve.org/CVERecord?id=CVE-2010-1730"],"bugs":[""],"patches":{"kdelibs":[],"kde4libs":[],"qt4-x11":[]},"tags":{},"packages":[{"name":"kde4libs","source":"https://ubuntu.com/security/cve?package=kde4libs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kde4libs","debian":"https://tracker.debian.org/pkg/kde4libs","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kdelibs","source":"https://ubuntu.com/security/cve?package=kdelibs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdelibs","debian":"https://tracker.debian.org/pkg/kdelibs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1729","published":"2010-05-06T14:53:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari,\nallows remote attackers to cause a denial of service (application crash)\nvia JavaScript that writes sequences in an infinite loop.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian, CVE-2010-1729/1730/1731 are the same issue but with\ndifferent effects. This is the webkit CVE\nper Debian, dos-only on webkit"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://h.ackack.net/overflow-in-webkit-dll-safari-and-opera.html","https://www.cve.org/CVERecord?id=CVE-2010-1729"],"bugs":[""],"patches":{"webkit":[]},"tags":{},"packages":[{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1733","published":"2010-05-06T12:47:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3\nallow remote attackers to execute arbitrary SQL commands via (1) multiple\ninventory fields to the search form, reachable through index.php; or (2)\nthe \"Software name\" field to the \"All softwares\" search form, reachable\nthrough index.php. NOTE: the provenance of this information is unknown;\nthe details are obtained solely from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1733"],"bugs":[""],"patches":{"ocsinventory-server":[]},"tags":{},"packages":[{"name":"ocsinventory-server","source":"https://ubuntu.com/security/cve?package=ocsinventory-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ocsinventory-server","debian":"https://tracker.debian.org/pkg/ocsinventory-server","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.0-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.0-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2.0-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2.0-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.02.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":72900,"limit":20,"total_results":79316}