{"cves":[{"id":"CVE-2010-0161","published":"2010-03-23T00:53:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in\nMozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows\nVista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and\nPOP servers to cause a denial of service (heap memory corruption and\napplication crash) or possibly execute arbitrary code via crafted data in a\nsession that uses SSPI.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"windows-only"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0161"],"bugs":[""],"patches":{"thunderbird":[]},"tags":{},"packages":[{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3385","published":"2010-03-23T00:53:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe mail component in Mozilla SeaMonkey before 1.1.19 does not properly\nrestrict execution of scriptable plugin content, which allows user-assisted\nremote attackers to obtain sensitive information via crafted content in an\nIFRAME element in an HTML e-mail message, as demonstrated by a Flash object\nthat sends arbitrary local files during a reply or forward operation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2010/mfsa2010-06.html","https://www.cve.org/CVERecord?id=CVE-2009-3385"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=371976"],"patches":{"seamonkey":[]},"tags":{},"packages":[{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.19","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1029","published":"2010-03-19T21:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack consumption vulnerability in the WebCore::CSSSelector function in\nWebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone\nOS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to\ncause a denial of service (application crash) or possibly execute arbitrary\ncode via a STYLE element composed of a large number of *> sequences.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit.\nlooks like it was safari only"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1029"],"bugs":[""],"patches":{"webkit":[],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1028","published":"2010-03-19T21:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the decompression functionality in the Web Open Fonts\nFormat (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before\n3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted\nWOFF file that triggers a buffer overflow, as demonstrated by the vd_ff\nmodule in VulnDisco 9.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1028"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0736","published":"2010-03-19T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the view_queryform function in\nlib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, allows\nremote attackers to inject arbitrary web script or HTML via \"user-provided\ninput.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0736"],"bugs":[""],"patches":{"viewvc":[]},"tags":{},"packages":[{"name":"viewvc","source":"https://ubuntu.com/security/cve?package=viewvc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=viewvc","debian":"https://tracker.debian.org/pkg/viewvc","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.5-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.5-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.5-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.1.5-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.1.5-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.1.5-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.1.5-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.10","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0733","published":"2010-03-19T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and\nearlier, and 8.5 through 8.5alpha2, allows remote authenticated users to\ncause a denial of service (daemon crash) via a SELECT statement with many\nLEFT JOIN clauses, related to certain hashtable size calculations.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.postgresql.org/pgsql-bugs/2009-10/msg00277.php","https://www.cve.org/CVERecord?id=CVE-2010-0733"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=546621","http://archives.postgresql.org/pgsql-bugs/2009-10/msg00277.php"],"patches":{"postgresql-7.4":[],"postgresql-8.0":[],"postgresql-8.1":[],"postgresql-8.2":[],"postgresql-8.3":[],"postgresql-8.4":["upstream: http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=64b057e6823655fb6c5d1f24a28f236b94dd6c54"]},"tags":{},"packages":[{"name":"postgresql-7.4","source":"https://ubuntu.com/security/cve?package=postgresql-7.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-7.4","debian":"https://tracker.debian.org/pkg/postgresql-7.4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.0","source":"https://ubuntu.com/security/cve?package=postgresql-8.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-8.0","debian":"https://tracker.debian.org/pkg/postgresql-8.0","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.1","source":"https://ubuntu.com/security/cve?package=postgresql-8.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-8.1","debian":"https://tracker.debian.org/pkg/postgresql-8.1","statuses":[{"release_codename":"dapper","status":"released","description":"8.1.19-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.1.19","component":null,"pocket":"security"}]},{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.2.15","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.3.9-0ubuntu8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"8.3.9-0ubuntu8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"8.3.9-0ubuntu9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.3.9","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"8.4.2-0ubuntu9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.4.3-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.4.3-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"8.4.3-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"8.4.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0732","published":"2010-03-19T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ngdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before\n2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN,\nwhich triggers an X error in certain circumstances and consequently allows\nphysically proximate attackers to bypass screen locking and access an\nunattended workstation by pressing the Enter key many times.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0732"],"bugs":[""],"patches":{"gtk+2.0":[]},"tags":{},"packages":[{"name":"gtk+2.0","source":"https://ubuntu.com/security/cve?package=gtk+2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gtk+2.0","debian":"https://tracker.debian.org/pkg/gtk+2.0","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"fixed in gnome-screensaver 2.28.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.18.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0734","published":"2010-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncontent_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled,\ndoes not properly restrict the amount of callback data sent to an\napplication that requests automatic decompression, which might allow remote\nattackers to cause a denial of service (application crash) or have\nunspecified other impact by sending crafted compressed data to an\napplication that relies on the intended data-length limit.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://curl.haxx.se/docs/adv_20100209.html","https://ubuntu.com/security/notices/USN-1158-1","https://www.cve.org/CVERecord?id=CVE-2010-0734"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=563220"],"patches":{"curl":["upstream: http://curl.haxx.se/libcurl-contentencoding.patch"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"7.18.0-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"7.19.7-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"7.21.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"7.21.3-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.20.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-1158-1"],"notices":[{"id":"USN-1158-1","title":"curl vulnerabilities","summary":"Multiple vulnerabilities in curl.\n","instructions":"After a standard system update you need to restart any applications\nthat make use of libcurl to make all the necessary changes.\n","references":[],"published":"2011-06-24T03:27:25.101099","description":"Richard Silverman discovered that when doing GSSAPI authentication,\nlibcurl unconditionally performs credential delegation, handing the\nserver a copy of the client's security credential. (CVE-2011-2192)\n\nWesley Miaw discovered that when zlib is enabled, libcurl does not\nproperly restrict the amount of callback data sent to an application\nthat requests automatic decompression. This might allow an attacker to\ncause a denial of service via an application crash or possibly execute\narbitrary code with the privilege of the application. This issue only\naffected Ubuntu 8.04 LTS and Ubuntu 10.04 LTS. (CVE-2010-0734)\n\nUSN 818-1 fixed an issue with curl's handling of SSL certificates with\nzero bytes in the Common Name. Due to a packaging error, the fix for\nthis issue was not being applied during the build. This issue only\naffected Ubuntu 8.04 LTS. We apologize for the error. (CVE-2009-2417)\n\nOriginal advisory details:\n\n Scott Cantor discovered that curl did not correctly handle SSL\n certificates with zero bytes in the Common Name. A remote attacker\n could exploit this to perform a machine-in-the-middle attack to view\n sensitive information or alter encrypted communications.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"curl","version":"7.18.0-1ubuntu2.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"libcurl3","version":"7.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.18.0-1ubuntu2.3"},{"name":"libcurl3-gnutls","version":"7.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.18.0-1ubuntu2.3"}],"lucid":[{"name":"curl","version":"7.19.7-1ubuntu1.1","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"libcurl3","version":"7.19.7-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.19.7-1ubuntu1.1"},{"name":"libcurl3-gnutls","version":"7.19.7-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.19.7-1ubuntu1.1"}],"maverick":[{"name":"curl","version":"7.21.0-1ubuntu1.1","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"libcurl3","version":"7.21.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.21.0-1ubuntu1.1"},{"name":"libcurl3-gnutls","version":"7.21.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.21.0-1ubuntu1.1"}],"natty":[{"name":"curl","version":"7.21.3-1ubuntu1.2","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"libcurl3","version":"7.21.3-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.21.3-1ubuntu1.2"},{"name":"libcurl3-gnutls","version":"7.21.3-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.21.3-1ubuntu1.2"},{"name":"libcurl3-nss","version":"7.21.3-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.21.3-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2009-2417","CVE-2010-0734","CVE-2011-2192"]}]},{"id":"CVE-2010-0008","published":"2010-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe sctp_rcv_ootb function in the SCTP implementation in the Linux kernel\nbefore 2.6.23 allows remote attackers to cause a denial of service\n(infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of\nzero length.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-947-1","https://www.cve.org/CVERecord?id=CVE-2010-0008"],"bugs":[""],"patches":{"linux-source-2.6.15":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=aecedeab6fcf914929cd8ff6fa0b8ae9bfdf3d30"],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"2.6.15-55.84","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-947-1"],"notices":[{"id":"USN-947-1","title":"Linux kernel vulnerabilities","summary":"Multiple flaws in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2010-06-03T06:23:23.617205","description":"It was discovered that the Linux kernel did not correctly handle memory\nprotection of the Virtual Dynamic Shared Object page when running\na 32-bit application on a 64-bit kernel.  A local attacker could\nexploit this to cause a denial of service. (Only affected Ubuntu 6.06\nLTS.) (CVE-2009-4271)\n\nIt was discovered that the r8169 network driver did not correctly check\nthe size of Ethernet frames.  A remote attacker could send specially\ncrafted traffic to crash the system, leading to a denial of service.\n(CVE-2009-4537)\n\nWei Yongjun discovered that SCTP did not correctly validate certain\nchunks.  A remote attacker could send specially crafted traffic to\nmonopolize CPU resources, leading to a denial of service. (Only affected\nUbuntu 6.06 LTS.) (CVE-2010-0008)\n\nIt was discovered that KVM did not correctly limit certain privileged\nIO accesses on x86.  Processes in the guest OS with access to IO regions\ncould gain further privileges within the guest OS. (Did not affect Ubuntu\n6.06 LTS.) (CVE-2010-0298, CVE-2010-0306, CVE-2010-0419)\n\nEvgeniy Polyakov discovered that IPv6 did not correctly handle\ncertain TUN packets.  A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (Only affected Ubuntu 8.04\nLTS.) (CVE-2010-0437)\n\nSachin Prabhu discovered that GFS2 did not correctly handle certain locks.\nA local attacker with write access to a GFS2 filesystem could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-0727)\n\nJamie Strandboge discovered that network virtio in KVM did not correctly\nhandle certain high-traffic conditions.  A remote attacker could exploit\nthis by sending specially crafted traffic to a guest OS, causing the\nguest to crash, leading to a denial of service. (Only affected Ubuntu\n8.04 LTS.) (CVE-2010-0741)\n\nMarcus Meissner discovered that the USB subsystem did not correctly handle\ncertain error conditions.  A local attacker with access to a USB device\ncould exploit this to read recently used kernel memory, leading to a\nloss of privacy and potentially root privilege escalation. (CVE-2010-1083)\n\nNeil Brown discovered that the Bluetooth subsystem did not correctly\nhandle large amounts of traffic.  A physically proximate remote attacker\ncould exploit this by sending specially crafted traffic that would consume\nall available system memory, leading to a denial of service. (Ubuntu\n6.06 LTS and 10.04 LTS were not affected.) (CVE-2010-1084)\n\nJody Bruchon discovered that the sound driver for the AMD780V did not\ncorrectly handle certain conditions.  A local attacker with access to\nthis hardward could exploit the flaw to cause a system crash, leading\nto a denial of service. (CVE-2010-1085)\n\nAng Way Chuang discovered that the DVB driver did not correctly handle\ncertain MPEG2-TS frames.  An attacker could exploit this by delivering\nspecially crafted frames to monopolize CPU resources, leading to a denial\nof service. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1086)\n\nTrond Myklebust discovered that NFS did not correctly handle truncation\nunder certain conditions.  A local attacker with write access to an NFS\nshare could exploit this to crash the system, leading to a denial of\nservice. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1087)\n\nAl Viro discovered that automount of NFS did not correctly handle symlinks\nunder certain conditions.  A local attacker could exploit this to crash\nthe system, leading to a denial of service. (Ubuntu 6.06 LTS and Ubuntu\n10.04 LTS were not affected.) (CVE-2010-1088)\n\nMatt McCutchen discovered that ReiserFS did not correctly protect xattr\nfiles in the .reiserfs_priv directory.  A local attacker could exploit\nthis to gain root privileges or crash the system, leading to a denial\nof service. (CVE-2010-1146)\n\nEugene Teo discovered that CIFS did not correctly validate arguments when\ncreating new files.  A local attacker could exploit this to crash the\nsystem, leading to a denial of service, or possibly gain root privileges\nif mmap_min_addr was not set. (CVE-2010-1148)\n\nCatalin Marinas and Tetsuo Handa discovered that the TTY layer did not\ncorrectly release process IDs.  A local attacker could exploit this to\nconsume kernel resources, leading to a denial of service. (CVE-2010-1162)\n\nNeil Horman discovered that TIPC did not correctly check its internal\nstate.  A local attacker could send specially crafted packets via AF_TIPC\nthat would cause the system to crash, leading to a denial of service.\n(Ubuntu 6.06 LTS was not affected.) (CVE-2010-1187)\n\nMasayuki Nakagawa discovered that IPv6 did not correctly handle\ncertain settings when listening.  If a socket were listening with the\nIPV6_RECVPKTINFO flag, a remote attacker could send specially crafted\ntraffic that would cause the system to crash, leading to a denial of\nservice. (Only Ubuntu 6.06 LTS was affected.) (CVE-2010-1188)\n\nOleg Nesterov discovered that the Out-Of-Memory handler did not correctly\nhandle certain arrangements of processes.  A local attacker could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-1488)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.28","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-112.28","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.15","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.60","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.15"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.28"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"}],"hardy":[{"name":"linux","version":"2.6.24-28.70","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"}],"lucid":[{"name":"linux-ec2","version":"2.6.32-306.11","description":"Linux kernel for EC2","is_source":true},{"name":"linux-qcm-msm","version":"2.6.31-802.4","description":"Linux kernel for qcm-msm ARM","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-501.7","description":"Linux kernel for ti-omap ARM","is_source":true},{"name":"linux-mvl-dove","version":"2.6.32-205.18","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux","version":"2.6.32-22.35","description":"Linux kernel","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-608.14","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-image-2.6.32-22-powerpc","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-802-st1-5","version":"2.6.31-802.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm","version_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm/2.6.31-802.4"},{"name":"linux-image-2.6.32-22-powerpc-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-virtual","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.14"},{"name":"linux-image-2.6.32-22-powerpc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.33-501-omap","version":"2.6.33-501.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-501.7"},{"name":"linux-image-2.6.32-22-generic-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-205-dove","version":"2.6.32-205.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-205.18"},{"name":"linux-image-2.6.32-22-ia64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-306-ec2","version":"2.6.32-306.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-306.11"},{"name":"linux-image-2.6.32-22-preempt","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-preempt-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-ia64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.84","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"}],"jaunty":[{"name":"linux","version":"2.6.28-19.61","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"}]},"type":"USN","cves_ids":["CVE-2009-4271","CVE-2009-4537","CVE-2010-0008","CVE-2010-0298","CVE-2010-0306","CVE-2010-0419","CVE-2010-0437","CVE-2010-0727","CVE-2010-0741","CVE-2010-1083","CVE-2010-1084","CVE-2010-1085","CVE-2010-1086","CVE-2010-1087","CVE-2010-1088","CVE-2010-1146","CVE-2010-1148","CVE-2010-1162","CVE-2010-1187","CVE-2010-1188","CVE-2010-1488"]}]},{"id":"CVE-2009-4271","published":"2010-03-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Linux kernel 2.6.9 through 2.6.17 on the x86_64 and amd64 platforms\nallows local users to cause a denial of service (panic) via a 32-bit\napplication that calls mprotect on its Virtual Dynamic Shared Object (VDSO)\npage and then triggers a segmentation fault.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-947-1","https://www.cve.org/CVERecord?id=CVE-2009-4271"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.84","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-947-1"],"notices":[{"id":"USN-947-1","title":"Linux kernel vulnerabilities","summary":"Multiple flaws in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2010-06-03T06:23:23.617205","description":"It was discovered that the Linux kernel did not correctly handle memory\nprotection of the Virtual Dynamic Shared Object page when running\na 32-bit application on a 64-bit kernel.  A local attacker could\nexploit this to cause a denial of service. (Only affected Ubuntu 6.06\nLTS.) (CVE-2009-4271)\n\nIt was discovered that the r8169 network driver did not correctly check\nthe size of Ethernet frames.  A remote attacker could send specially\ncrafted traffic to crash the system, leading to a denial of service.\n(CVE-2009-4537)\n\nWei Yongjun discovered that SCTP did not correctly validate certain\nchunks.  A remote attacker could send specially crafted traffic to\nmonopolize CPU resources, leading to a denial of service. (Only affected\nUbuntu 6.06 LTS.) (CVE-2010-0008)\n\nIt was discovered that KVM did not correctly limit certain privileged\nIO accesses on x86.  Processes in the guest OS with access to IO regions\ncould gain further privileges within the guest OS. (Did not affect Ubuntu\n6.06 LTS.) (CVE-2010-0298, CVE-2010-0306, CVE-2010-0419)\n\nEvgeniy Polyakov discovered that IPv6 did not correctly handle\ncertain TUN packets.  A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (Only affected Ubuntu 8.04\nLTS.) (CVE-2010-0437)\n\nSachin Prabhu discovered that GFS2 did not correctly handle certain locks.\nA local attacker with write access to a GFS2 filesystem could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-0727)\n\nJamie Strandboge discovered that network virtio in KVM did not correctly\nhandle certain high-traffic conditions.  A remote attacker could exploit\nthis by sending specially crafted traffic to a guest OS, causing the\nguest to crash, leading to a denial of service. (Only affected Ubuntu\n8.04 LTS.) (CVE-2010-0741)\n\nMarcus Meissner discovered that the USB subsystem did not correctly handle\ncertain error conditions.  A local attacker with access to a USB device\ncould exploit this to read recently used kernel memory, leading to a\nloss of privacy and potentially root privilege escalation. (CVE-2010-1083)\n\nNeil Brown discovered that the Bluetooth subsystem did not correctly\nhandle large amounts of traffic.  A physically proximate remote attacker\ncould exploit this by sending specially crafted traffic that would consume\nall available system memory, leading to a denial of service. (Ubuntu\n6.06 LTS and 10.04 LTS were not affected.) (CVE-2010-1084)\n\nJody Bruchon discovered that the sound driver for the AMD780V did not\ncorrectly handle certain conditions.  A local attacker with access to\nthis hardward could exploit the flaw to cause a system crash, leading\nto a denial of service. (CVE-2010-1085)\n\nAng Way Chuang discovered that the DVB driver did not correctly handle\ncertain MPEG2-TS frames.  An attacker could exploit this by delivering\nspecially crafted frames to monopolize CPU resources, leading to a denial\nof service. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1086)\n\nTrond Myklebust discovered that NFS did not correctly handle truncation\nunder certain conditions.  A local attacker with write access to an NFS\nshare could exploit this to crash the system, leading to a denial of\nservice. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1087)\n\nAl Viro discovered that automount of NFS did not correctly handle symlinks\nunder certain conditions.  A local attacker could exploit this to crash\nthe system, leading to a denial of service. (Ubuntu 6.06 LTS and Ubuntu\n10.04 LTS were not affected.) (CVE-2010-1088)\n\nMatt McCutchen discovered that ReiserFS did not correctly protect xattr\nfiles in the .reiserfs_priv directory.  A local attacker could exploit\nthis to gain root privileges or crash the system, leading to a denial\nof service. (CVE-2010-1146)\n\nEugene Teo discovered that CIFS did not correctly validate arguments when\ncreating new files.  A local attacker could exploit this to crash the\nsystem, leading to a denial of service, or possibly gain root privileges\nif mmap_min_addr was not set. (CVE-2010-1148)\n\nCatalin Marinas and Tetsuo Handa discovered that the TTY layer did not\ncorrectly release process IDs.  A local attacker could exploit this to\nconsume kernel resources, leading to a denial of service. (CVE-2010-1162)\n\nNeil Horman discovered that TIPC did not correctly check its internal\nstate.  A local attacker could send specially crafted packets via AF_TIPC\nthat would cause the system to crash, leading to a denial of service.\n(Ubuntu 6.06 LTS was not affected.) (CVE-2010-1187)\n\nMasayuki Nakagawa discovered that IPv6 did not correctly handle\ncertain settings when listening.  If a socket were listening with the\nIPV6_RECVPKTINFO flag, a remote attacker could send specially crafted\ntraffic that would cause the system to crash, leading to a denial of\nservice. (Only Ubuntu 6.06 LTS was affected.) (CVE-2010-1188)\n\nOleg Nesterov discovered that the Out-Of-Memory handler did not correctly\nhandle certain arrangements of processes.  A local attacker could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-1488)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.28","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-112.28","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.15","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.60","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.15"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.28"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"}],"hardy":[{"name":"linux","version":"2.6.24-28.70","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"}],"lucid":[{"name":"linux-ec2","version":"2.6.32-306.11","description":"Linux kernel for EC2","is_source":true},{"name":"linux-qcm-msm","version":"2.6.31-802.4","description":"Linux kernel for qcm-msm ARM","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-501.7","description":"Linux kernel for ti-omap ARM","is_source":true},{"name":"linux-mvl-dove","version":"2.6.32-205.18","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux","version":"2.6.32-22.35","description":"Linux kernel","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-608.14","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-image-2.6.32-22-powerpc","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-802-st1-5","version":"2.6.31-802.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm","version_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm/2.6.31-802.4"},{"name":"linux-image-2.6.32-22-powerpc-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-virtual","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.14"},{"name":"linux-image-2.6.32-22-powerpc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.33-501-omap","version":"2.6.33-501.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-501.7"},{"name":"linux-image-2.6.32-22-generic-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-205-dove","version":"2.6.32-205.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-205.18"},{"name":"linux-image-2.6.32-22-ia64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-306-ec2","version":"2.6.32-306.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-306.11"},{"name":"linux-image-2.6.32-22-preempt","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-preempt-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-ia64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.84","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"}],"jaunty":[{"name":"linux","version":"2.6.28-19.61","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"}]},"type":"USN","cves_ids":["CVE-2009-4271","CVE-2009-4537","CVE-2010-0008","CVE-2010-0298","CVE-2010-0306","CVE-2010-0419","CVE-2010-0437","CVE-2010-0727","CVE-2010-0741","CVE-2010-1083","CVE-2010-1084","CVE-2010-1085","CVE-2010-1086","CVE-2010-1087","CVE-2010-1088","CVE-2010-1146","CVE-2010-1148","CVE-2010-1162","CVE-2010-1187","CVE-2010-1188","CVE-2010-1488"]}]},{"id":"CVE-2009-4720","published":"2010-03-18T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in cgi-bin/gnudip.cgi in GnuDIP 2.1.1 allows\nremote attackers to execute arbitrary SQL commands via the username\nparameter.  NOTE: some of these details are obtained from third party\ninformation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4720"],"bugs":[""],"patches":{"gnudip":[]},"tags":{},"packages":[{"name":"gnudip","source":"https://ubuntu.com/security/cve?package=gnudip","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnudip","debian":"https://tracker.debian.org/pkg/gnudip","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1299","published":"2010-03-18T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and\n0.9.19 allows local users to change the ownership and permissions of\narbitrary files via a symlink attack on a /tmp/.esd-##### temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1299"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/pulseaudio/+bug/509008","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=573615"],"patches":{"pulseaudio":["upstream: http://git.0pointer.de/?p=pulseaudio.git;a=patch;h=d3efa43d85ac132c6a5a416a2b6f2115f5d577ee"]},"tags":{},"packages":[{"name":"pulseaudio","source":"https://ubuntu.com/security/cve?package=pulseaudio","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pulseaudio","debian":"https://tracker.debian.org/pkg/pulseaudio","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1:0.9.22~0.9.21+stable-queue-32-g8478-0ubuntu12","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.22","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0421","published":"2010-03-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nArray index error in the hb_ot_layout_build_glyph_classes function in\npango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows\ncontext-dependent attackers to cause a denial of service (application\ncrash) via a crafted font file, related to building a synthetic Glyph\nDefinition (aka GDEF) table by using this font's charmap and the Unicode\nproperty database.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"debian patch is different, backport?"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1082-1","https://www.cve.org/CVERecord?id=CVE-2010-0421"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-0421","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=574021"],"patches":{"pango1.0":["upstream: http://git.gnome.org/browse/pango/commit/?id=797d46714d27f147277fdd5346648d838c68fb8c","vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=10;filename=pango1.0_1.20.5-5%2Blenny1.debdiff;att=1;bug=574021"]},"tags":{},"packages":[{"name":"pango1.0","source":"https://ubuntu.com/security/cve?package=pango1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pango1.0","debian":"https://tracker.debian.org/pkg/pango1.0","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.20.5-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.26.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.28.0-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.28.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.27.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1082-1"],"notices":[{"id":"USN-1082-1","title":"Pango vulnerabilities","summary":"","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2011-03-02T15:48:48.518865","description":"Marc Schoenefeld discovered that Pango incorrectly handled certain Glyph\nDefinition (GDEF) tables. If a user were tricked into displaying text with\na specially-crafted font, an attacker could cause Pango to crash, resulting\nin a denial of service. This issue only affected Ubuntu 8.04 LTS and 9.10.\n(CVE-2010-0421)\n\nDan Rosenberg discovered that Pango incorrectly handled certain FT_Bitmap\nobjects. If a user were tricked into displaying text with a specially-\ncrafted font, an attacker could cause a denial of service or execute\narbitrary code with privileges of the user invoking the program. The\ndefault compiler options for affected releases should reduce the\nvulnerability to a denial of service. (CVE-2011-0020)\n\nIt was discovered that Pango incorrectly handled certain memory\nreallocation failures. If a user were tricked into displaying text in a way\nthat would cause a reallocation failure, an attacker could cause a denial\nof service or execute arbitrary code with privileges of the user invoking\nthe program. This issue only affected Ubuntu 9.10, 10.04 LTS and 10.10.\n(CVE-2011-0064)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"pango1.0","version":"1.20.5-0ubuntu1.2","description":"","is_source":true},{"name":"libpango1.0-0","version":"1.20.5-0ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pango1.0","version_link":"https://launchpad.net/ubuntu/+source/pango1.0/1.20.5-0ubuntu1.2"}],"lucid":[{"name":"pango1.0","version":"1.28.0-0ubuntu2.2","description":"","is_source":true},{"name":"gir1.0-pango-1.0","version":"1.28.0-0ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pango1.0","version_link":"https://launchpad.net/ubuntu/+source/pango1.0/1.28.0-0ubuntu2.2"}],"maverick":[{"name":"pango1.0","version":"1.28.2-0ubuntu1.1","description":"","is_source":true},{"name":"gir1.0-pango-1.0","version":"1.28.2-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pango1.0","version_link":"https://launchpad.net/ubuntu/+source/pango1.0/1.28.2-0ubuntu1.1"}],"karmic":[{"name":"pango1.0","version":"1.26.0-1ubuntu0.1","description":"","is_source":true},{"name":"libpango1.0-0","version":"1.26.0-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pango1.0","version_link":"https://launchpad.net/ubuntu/+source/pango1.0/1.26.0-1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2010-0421","CVE-2011-0064","CVE-2011-0020"]}]},{"id":"CVE-2010-0163","published":"2010-03-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process\ne-mail attachments with a parser that performs casts and line termination\nincorrectly, which allows remote attackers to cause a denial of service\n(application crash) or possibly execute arbitrary code via a crafted\nmessage, related to message indexing.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-915-1","https://www.cve.org/CVERecord?id=CVE-2010-0163"],"bugs":[""],"patches":{"thunderbird":[]},"tags":{},"packages":[{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.24","component":null,"pocket":"security"}]}],"notices_ids":["USN-915-1"],"notices":[{"id":"USN-915-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2010-03-18T14:08:21.930607","description":"Several flaws were discovered in the JavaScript engine of Thunderbird. If a\nuser had JavaScript enabled and were tricked into viewing malicious web\ncontent, a remote attacker could cause a denial of service or possibly\nexecute arbitrary code with the privileges of the user invoking the\nprogram. (CVE-2009-0689, CVE-2009-2463, CVE-2009-3075)\n\nJosh Soref discovered that the BinHex decoder used in Thunderbird contained\na flaw. If a user were tricked into viewing malicious content, a remote\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2009-3072)\n\nIt was discovered that Thunderbird did not properly manage memory when\nusing XUL tree elements. If a user were tricked into viewing malicious\ncontent, a remote attacker could cause a denial of service or possibly\nexecute arbitrary code with the privileges of the user invoking the\nprogram. (CVE-2009-3077)\n\nJesse Ruderman and Sid Stamm discovered that Thunderbird did not properly\ndisplay filenames containing right-to-left (RTL) override characters. If a\nuser were tricked into opening a malicious file with a crafted filename, an\nattacker could exploit this to trick the user into opening a different file\nthan the user expected. (CVE-2009-3376)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in\nThunderbird. If an NTLM authenticated user opened content containing links\nto a malicious website, a remote attacker could send requests to other\napplications, authenticated as the user. (CVE-2009-3983)\n\nLudovic Hirlimann discovered a flaw in the way Thunderbird indexed certain\nmessages with attachments. A remote attacker could send specially crafted\ncontent and cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-0163)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1"}],"jaunty":[{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1"}],"karmic":[{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-0689","CVE-2009-2463","CVE-2009-3072","CVE-2009-3075","CVE-2009-3077","CVE-2009-3376","CVE-2009-3983","CVE-2010-0163"]}]},{"id":"CVE-2010-0793","published":"2010-03-16T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in BarnOwl before 1.5.1 allows remote attackers to cause a\ndenial of service (crash) and possibly execute arbitrary code via a crafted\nCC: header.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0793"],"bugs":[""],"patches":{"barnowl":[]},"tags":{},"packages":[{"name":"barnowl","source":"https://ubuntu.com/security/cve?package=barnowl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=barnowl","debian":"https://tracker.debian.org/pkg/barnowl","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.5.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.5.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.5.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.5.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.5.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0729","published":"2010-03-16T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nA certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux\n(RHEL) 4 on the ia64 platform allows local users to use ptrace on an\narbitrary process, and consequently gain privileges, via vectors related to\na missing ptrace_check_attach call.","ubuntu_description":"","notes":[{"author":"kees","note":"RedHat-specific patch."}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0729"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-6733","published":"2010-03-16T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe nfs_lock function in fs/nfs/file.c in the Linux kernel 2.6.9 does not\nproperly remove POSIX locks on files that are setgid without group-execute\npermission, which allows local users to cause a denial of service (BUG and\nsystem crash) by locking a file on an NFS filesystem and then changing this\nfile's permissions, a related issue to CVE-2010-0727.","ubuntu_description":"","notes":[{"author":"kees","note":"predates Dapper"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-6733"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0969","published":"2010-03-16T19:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnbound before 1.4.3 does not properly align structures on 64-bit\nplatforms, which allows remote attackers to cause a denial of service\n(daemon crash) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0969"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.4.1-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.4.4-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.4.4-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.4.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0727","published":"2010-03-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312,\nand the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux\n(RHEL) 5 and 6, does not properly remove POSIX locks on files that are\nsetgid without group-execute permission, which allows local users to cause\na denial of service (BUG and system crash) by locking a file on a (1) GFS\nor (2) GFS2 filesystem, and then changing this file's permissions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-947-1","https://www.cve.org/CVERecord?id=CVE-2010-0727"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=720e7749279bde0d08684b1bb4e7a2eedeec6394"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.70","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.61","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.60","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-22.35","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.84","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-947-1"],"notices":[{"id":"USN-947-1","title":"Linux kernel vulnerabilities","summary":"Multiple flaws in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2010-06-03T06:23:23.617205","description":"It was discovered that the Linux kernel did not correctly handle memory\nprotection of the Virtual Dynamic Shared Object page when running\na 32-bit application on a 64-bit kernel.  A local attacker could\nexploit this to cause a denial of service. (Only affected Ubuntu 6.06\nLTS.) (CVE-2009-4271)\n\nIt was discovered that the r8169 network driver did not correctly check\nthe size of Ethernet frames.  A remote attacker could send specially\ncrafted traffic to crash the system, leading to a denial of service.\n(CVE-2009-4537)\n\nWei Yongjun discovered that SCTP did not correctly validate certain\nchunks.  A remote attacker could send specially crafted traffic to\nmonopolize CPU resources, leading to a denial of service. (Only affected\nUbuntu 6.06 LTS.) (CVE-2010-0008)\n\nIt was discovered that KVM did not correctly limit certain privileged\nIO accesses on x86.  Processes in the guest OS with access to IO regions\ncould gain further privileges within the guest OS. (Did not affect Ubuntu\n6.06 LTS.) (CVE-2010-0298, CVE-2010-0306, CVE-2010-0419)\n\nEvgeniy Polyakov discovered that IPv6 did not correctly handle\ncertain TUN packets.  A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (Only affected Ubuntu 8.04\nLTS.) (CVE-2010-0437)\n\nSachin Prabhu discovered that GFS2 did not correctly handle certain locks.\nA local attacker with write access to a GFS2 filesystem could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-0727)\n\nJamie Strandboge discovered that network virtio in KVM did not correctly\nhandle certain high-traffic conditions.  A remote attacker could exploit\nthis by sending specially crafted traffic to a guest OS, causing the\nguest to crash, leading to a denial of service. (Only affected Ubuntu\n8.04 LTS.) (CVE-2010-0741)\n\nMarcus Meissner discovered that the USB subsystem did not correctly handle\ncertain error conditions.  A local attacker with access to a USB device\ncould exploit this to read recently used kernel memory, leading to a\nloss of privacy and potentially root privilege escalation. (CVE-2010-1083)\n\nNeil Brown discovered that the Bluetooth subsystem did not correctly\nhandle large amounts of traffic.  A physically proximate remote attacker\ncould exploit this by sending specially crafted traffic that would consume\nall available system memory, leading to a denial of service. (Ubuntu\n6.06 LTS and 10.04 LTS were not affected.) (CVE-2010-1084)\n\nJody Bruchon discovered that the sound driver for the AMD780V did not\ncorrectly handle certain conditions.  A local attacker with access to\nthis hardward could exploit the flaw to cause a system crash, leading\nto a denial of service. (CVE-2010-1085)\n\nAng Way Chuang discovered that the DVB driver did not correctly handle\ncertain MPEG2-TS frames.  An attacker could exploit this by delivering\nspecially crafted frames to monopolize CPU resources, leading to a denial\nof service. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1086)\n\nTrond Myklebust discovered that NFS did not correctly handle truncation\nunder certain conditions.  A local attacker with write access to an NFS\nshare could exploit this to crash the system, leading to a denial of\nservice. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1087)\n\nAl Viro discovered that automount of NFS did not correctly handle symlinks\nunder certain conditions.  A local attacker could exploit this to crash\nthe system, leading to a denial of service. (Ubuntu 6.06 LTS and Ubuntu\n10.04 LTS were not affected.) (CVE-2010-1088)\n\nMatt McCutchen discovered that ReiserFS did not correctly protect xattr\nfiles in the .reiserfs_priv directory.  A local attacker could exploit\nthis to gain root privileges or crash the system, leading to a denial\nof service. (CVE-2010-1146)\n\nEugene Teo discovered that CIFS did not correctly validate arguments when\ncreating new files.  A local attacker could exploit this to crash the\nsystem, leading to a denial of service, or possibly gain root privileges\nif mmap_min_addr was not set. (CVE-2010-1148)\n\nCatalin Marinas and Tetsuo Handa discovered that the TTY layer did not\ncorrectly release process IDs.  A local attacker could exploit this to\nconsume kernel resources, leading to a denial of service. (CVE-2010-1162)\n\nNeil Horman discovered that TIPC did not correctly check its internal\nstate.  A local attacker could send specially crafted packets via AF_TIPC\nthat would cause the system to crash, leading to a denial of service.\n(Ubuntu 6.06 LTS was not affected.) (CVE-2010-1187)\n\nMasayuki Nakagawa discovered that IPv6 did not correctly handle\ncertain settings when listening.  If a socket were listening with the\nIPV6_RECVPKTINFO flag, a remote attacker could send specially crafted\ntraffic that would cause the system to crash, leading to a denial of\nservice. (Only Ubuntu 6.06 LTS was affected.) (CVE-2010-1188)\n\nOleg Nesterov discovered that the Out-Of-Memory handler did not correctly\nhandle certain arrangements of processes.  A local attacker could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-1488)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.28","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-112.28","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.15","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.60","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.15"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.28"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"}],"hardy":[{"name":"linux","version":"2.6.24-28.70","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"}],"lucid":[{"name":"linux-ec2","version":"2.6.32-306.11","description":"Linux kernel for EC2","is_source":true},{"name":"linux-qcm-msm","version":"2.6.31-802.4","description":"Linux kernel for qcm-msm ARM","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-501.7","description":"Linux kernel for ti-omap ARM","is_source":true},{"name":"linux-mvl-dove","version":"2.6.32-205.18","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux","version":"2.6.32-22.35","description":"Linux kernel","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-608.14","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-image-2.6.32-22-powerpc","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-802-st1-5","version":"2.6.31-802.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm","version_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm/2.6.31-802.4"},{"name":"linux-image-2.6.32-22-powerpc-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-virtual","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.14"},{"name":"linux-image-2.6.32-22-powerpc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.33-501-omap","version":"2.6.33-501.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-501.7"},{"name":"linux-image-2.6.32-22-generic-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-205-dove","version":"2.6.32-205.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-205.18"},{"name":"linux-image-2.6.32-22-ia64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-306-ec2","version":"2.6.32-306.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-306.11"},{"name":"linux-image-2.6.32-22-preempt","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-preempt-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-ia64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.84","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"}],"jaunty":[{"name":"linux","version":"2.6.28-19.61","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"}]},"type":"USN","cves_ids":["CVE-2009-4271","CVE-2009-4537","CVE-2010-0008","CVE-2010-0298","CVE-2010-0306","CVE-2010-0419","CVE-2010-0437","CVE-2010-0727","CVE-2010-0741","CVE-2010-1083","CVE-2010-1084","CVE-2010-1085","CVE-2010-1086","CVE-2010-1087","CVE-2010-1088","CVE-2010-1146","CVE-2010-1148","CVE-2010-1162","CVE-2010-1187","CVE-2010-1188","CVE-2010-1488"]}]},{"id":"CVE-2010-0397","published":"2010-03-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe xmlrpc extension in PHP 5.3.1 does not properly handle a missing\nmethodName element in the first argument to the xmlrpc_decode_request\nfunction, which allows context-dependent attackers to cause a denial of\nservice (NULL pointer dereference and application crash) and possibly have\nunspecified other impact via a crafted argument.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"reproducer in debian bug"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.php.net/releases/5_3_3.php","https://ubuntu.com/security/notices/USN-989-1","https://www.cve.org/CVERecord?id=CVE-2010-0397"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=573573","http://bugs.php.net/bug.php?id=51288"],"patches":{"php5":["vendor: http://git.debian.org/?p=pkg-php/php.git;a=commitdiff;h=414208016e869fd218f047792ba5912fed83c08c","upstream: http://svn.php.net/viewvc?view=revision&revision=296152","upstream: http://svn.php.net/viewvc?view=revision&revision=296153"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.19","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.12","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.2.6.dfsg.1-3ubuntu4.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"5.3.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-989-1"],"notices":[{"id":"USN-989-1","title":"PHP vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-20T18:22:04.757285","description":"Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc\nrequests. An attacker could exploit this issue to cause the PHP server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2010-0397)\n\nIt was discovered that the pseudorandom number generator in PHP did not\nprovide the expected entropy. An attacker could exploit this issue to\npredict values that were intended to be random, such as session cookies.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10.\n(CVE-2010-1128)\n\nIt was discovered that PHP did not properly handle directory pathnames that\nlacked a trailing slash character. An attacker could exploit this issue to\nbypass safe_mode restrictions. This issue only affected Ubuntu 6.06 LTS,\n8.04 LTS, 9.04 and 9.10. (CVE-2010-1129)\n\nGrzegorz Stachowiak discovered that the PHP session extension did not\nproperly handle semicolon characters. An attacker could exploit this issue\nto bypass safe_mode restrictions. This issue only affected Ubuntu 8.04 LTS,\n9.04 and 9.10. (CVE-2010-1130)\n\nStefan Esser discovered that PHP incorrectly decoded remote HTTP chunked\nencoding streams. An attacker could exploit this issue to cause the PHP\nserver to crash and possibly execute arbitrary code with application\nprivileges. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-1866)\n\nMateusz Kocielski discovered that certain PHP SQLite functions incorrectly\nhandled empty SQL queries. An attacker could exploit this issue to possibly\nexecute arbitrary code with application privileges. (CVE-2010-1868)\n\nMateusz Kocielski discovered that PHP incorrectly handled certain arguments\nto the fnmatch function. An attacker could exploit this flaw and cause the\nPHP server to consume all available stack memory, resulting in a denial of\nservice. (CVE-2010-1917)\n\nStefan Esser discovered that PHP incorrectly handled certain strings in the\nphar extension. An attacker could exploit this flaw to possibly view\nsensitive information. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2010-2094, CVE-2010-2950)\n\nStefan Esser discovered that PHP incorrectly handled deserialization of\nSPLObjectStorage objects. A remote attacker could exploit this issue to\nview sensitive information and possibly execute arbitrary code with\napplication privileges. This issue only affected Ubuntu 8.04 LTS, 9.04,\n9.10 and 10.04 LTS. (CVE-2010-2225)\n\nIt was discovered that PHP incorrectly filtered error messages when limits\nfor memory, execution time, or recursion were exceeded. A remote attacker\ncould exploit this issue to possibly view sensitive information.\n(CVE-2010-2531)\n\nStefan Esser discovered that the PHP session serializer incorrectly handled\nthe PS_UNDEF_MARKER marker. An attacker could exploit this issue to alter\narbitrary session variables. (CVE-2010-3065)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.12","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.5","description":"","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.19","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"}],"jaunty":[{"name":"php5","version":"5.2.6.dfsg.1-3ubuntu4.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"php5-cgi","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"libapache2-mod-php5","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"}]},"type":"USN","cves_ids":["CVE-2010-0397","CVE-2010-1128","CVE-2010-1129","CVE-2010-1130","CVE-2010-1866","CVE-2010-1868","CVE-2010-1917","CVE-2010-2094","CVE-2010-2225","CVE-2010-2531","CVE-2010-2950","CVE-2010-3065"]}]}],"offset":73100,"limit":20,"total_results":79316}