{"cves":[{"id":"CVE-2010-0054","published":"2010-03-15T14:15:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows\nremote attackers to execute arbitrary code or cause a denial of service\n(application crash) via vectors involving HTML IMG elements.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-0054"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=34076"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/53812","upstream: http://trac.webkit.org/changeset/53813","upstream: http://trac.webkit.org/changeset/54242"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0053","published":"2010-03-15T14:15:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows\nremote attackers to execute arbitrary code or cause a denial of service\n(application crash) via vectors related to the run-in Cascading Style\nSheets (CSS) display property.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"},{"author":"mdeslaur","note":"code in hardy-jaunty is different in webkit, need to test"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-0053"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=31034"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/50466"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0052","published":"2010-03-15T14:15:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows\nremote attackers to execute arbitrary code or cause a denial of service\n(application crash) via vectors related to \"callbacks for HTML elements.\"","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-0052"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=32293"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/51877"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0051","published":"2010-03-15T14:15:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit in Apple Safari before 4.0.5 does not properly validate the\ncross-origin loading of stylesheets, which allows remote attackers to\nobtain sensitive information via a crafted HTML document.  NOTE: this might\noverlap CVE-2010-0651.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"},{"author":"mdeslaur","note":"This is the same flaw as CVE-2010-0651\nThis should be ignored."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-0051"],"bugs":[""],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/52784"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0050","published":"2010-03-15T14:15:00","updated_at":"2025-08-25T19:53:14.900786+00:00","description":"\nUse-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows\nremote attackers to execute arbitrary code or cause a denial of service\n(application crash) via an HTML document with improperly nested tags.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-0050"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=32567"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/52073"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0049","published":"2010-03-15T14:15:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows\nremote attackers to execute arbitrary code or cause a denial of service\n(application crash) via HTML elements with right-to-left (RTL) text\ndirectionality.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"},{"author":"mdeslaur","note":"code is different in webkit in hardy-jaunty, need to test"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-0049"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=32749"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/52527"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0048","published":"2010-03-15T13:28:00","updated_at":"2025-08-25T19:53:10.460082+00:00","description":"\nUse-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows\nremote attackers to execute arbitrary code or cause a denial of service\n(application crash) via a crafted XML document.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"},{"author":"mdeslaur","note":"code is different in webkit in hardy-karmic, need to test"}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-0048"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=31576"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/51962"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0047","published":"2010-03-15T13:28:00","updated_at":"2025-08-25T19:53:10.460082+00:00","description":"\nUse-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows\nremote attackers to execute arbitrary code or cause a denial of service\n(application crash) via vectors related to \"HTML object element fallback\ncontent.\"","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-0047"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=31277"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/50698"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0046","published":"2010-03-15T13:28:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari\nbefore 4.0.5 allows remote attackers to execute arbitrary code or cause a\ndenial of service (memory corruption and application crash) via crafted\nformat arguments.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-0046"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=31815"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/51727"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0044","published":"2010-03-15T13:28:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPubSub in Apple Safari before 4.0.5 does not properly implement use of the\nAccept Cookies preference to block cookies, which makes it easier for\nremote web servers to track users by setting a cookie in a (1) RSS or (2)\nAtom feed.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0044"],"bugs":[""],"patches":{"libipc-pubsub-perl":[],"libpoe-component-pubsub-perl":[]},"tags":{},"packages":[{"name":"libipc-pubsub-perl","source":"https://ubuntu.com/security/cve?package=libipc-pubsub-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libipc-pubsub-perl","debian":"https://tracker.debian.org/pkg/libipc-pubsub-perl","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libpoe-component-pubsub-perl","source":"https://ubuntu.com/security/cve?package=libpoe-component-pubsub-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libpoe-component-pubsub-perl","debian":"https://tracker.debian.org/pkg/libpoe-component-pubsub-perl","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0624","published":"2010-03-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in\nthe rmt client functionality in GNU tar before 1.23 and GNU cpio before\n2.11 allows remote rmt servers to cause a denial of service (memory\ncorruption) or possibly execute arbitrary code by sending more data than\nwas requested, related to archive filenames that contain a : (colon)\ncharacter.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"both tar and cpio get their rmt client from paxutils"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.agrs.tu-berlin.de/index.php?id=78327","https://ubuntu.com/security/notices/USN-2456-1","https://www.cve.org/CVERecord?id=CVE-2010-0624"],"bugs":[""],"patches":{"tar":["vendor: https://rhn.redhat.com/errata/RHSA-2010-0142.html","upstream: http://git.savannah.gnu.org/cgit/paxutils.git/diff/lib/rtapelib.c?id=9bc39283e4cc6ab9e5913ccbf766998eab4ff093"],"cpio":["vendor: https://rhn.redhat.com/errata/RHSA-2010-0143.html","upstream: http://git.savannah.gnu.org/cgit/paxutils.git/diff/lib/rtapelib.c?id=9bc39283e4cc6ab9e5913ccbf766998eab4ff093"]},"tags":{},"packages":[{"name":"cpio","source":"https://ubuntu.com/security/cve?package=cpio","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cpio","debian":"https://tracker.debian.org/pkg/cpio","statuses":[{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.10-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"2.11-4ubuntu1","component":null,"pocket":"security"}]},{"name":"tar","source":"https://ubuntu.com/security/cve?package=tar","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tar","debian":"https://tracker.debian.org/pkg/tar","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.23-3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.23-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.23-3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.23-3","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.23-3","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.23-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.23-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.23-3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.23-3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2456-1"],"notices":[{"id":"USN-2456-1","title":"GNU cpio vulnerabilities","summary":"The GNU cpio program could be made to crash or run programs if it\nopened a specially crafted file or received specially crafted input.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-01-08T19:40:54.145621","description":"Michal Zalewski discovered an out of bounds write issue in the\nprocess_copy_in function of GNU cpio. An attacker could specially\ncraft a cpio archive that could create a denial of service or possibly\nexecute arbitrary code. (CVE-2014-9112)\n\nJakob Lell discovered a heap-based buffer overflow in the rmt_read__\nfunction of GNU cpio's rmt client functionality. An attacker\ncontrolling a remote rmt server could use this to cause a denial of\nservice or possibly execute arbitrary code. This issue only affected\nUbuntu 10.04 LTS. (CVE-2010-0624)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"cpio","version":"2.10-1ubuntu2.1","description":"a program to manage archives of files","is_source":true},{"name":"cpio","version":"2.10-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cpio","version_link":"https://launchpad.net/ubuntu/+source/cpio/2.10-1ubuntu2.1"}],"precise":[{"name":"cpio","version":"2.11-7ubuntu3.1","description":"a program to manage archives of files","is_source":true},{"name":"cpio","version":"2.11-7ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cpio","version_link":"https://launchpad.net/ubuntu/+source/cpio/2.11-7ubuntu3.1"}],"trusty":[{"name":"cpio","version":"2.11+dfsg-1ubuntu1.1","description":"a program to manage archives of files","is_source":true},{"name":"cpio","version":"2.11+dfsg-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cpio","version_link":"https://launchpad.net/ubuntu/+source/cpio/2.11+dfsg-1ubuntu1.1","pocket":"security"}],"utopic":[{"name":"cpio","version":"2.11+dfsg-2ubuntu1.1","description":"a program to manage archives of files","is_source":true},{"name":"cpio","version":"2.11+dfsg-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cpio","version_link":"https://launchpad.net/ubuntu/+source/cpio/2.11+dfsg-2ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-0624","CVE-2014-9112"]}]},{"id":"CVE-2010-0396","published":"2010-03-11T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in the dpkg-source component in dpkg\nbefore 1.14.29 allows remote attackers to modify arbitrary files via a\ncrafted Debian source archive.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-909-1","https://www.cve.org/CVERecord?id=CVE-2010-0396"],"bugs":[""],"patches":{"dpkg":[]},"tags":{},"packages":[{"name":"dpkg","source":"https://ubuntu.com/security/cve?package=dpkg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dpkg","debian":"https://tracker.debian.org/pkg/dpkg","statuses":[{"release_codename":"dapper","status":"released","description":"1.13.11ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.14.16.6ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.14.20ubuntu6.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.14.24ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.15.4ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-909-1"],"notices":[{"id":"USN-909-1","title":"dpkg vulnerability","summary":"dpkg vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-11T06:37:09.899586","description":"William Grant discovered that dpkg-source did not safely apply diffs\nwhen unpacking source packages.  If a user or an automated system were\ntricked into unpacking a specially crafted source package, a remote\nattacker could modify files outside the target unpack directory, leading\nto a denial of service or potentially gaining access to the system.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"dpkg","version":"1.14.16.6ubuntu4.1","description":"","is_source":true},{"name":"dpkg-dev","version":"1.14.16.6ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dpkg","version_link":"https://launchpad.net/ubuntu/+source/dpkg/1.14.16.6ubuntu4.1"}],"dapper":[{"name":"dpkg","version":"1.13.11ubuntu7.1","description":"","is_source":true},{"name":"dpkg-dev","version":"1.13.11ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dpkg","version_link":"https://launchpad.net/ubuntu/+source/dpkg/1.13.11ubuntu7.1"}],"intrepid":[{"name":"dpkg","version":"1.14.20ubuntu6.3","description":"","is_source":true},{"name":"dpkg-dev","version":"1.14.20ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dpkg","version_link":"https://launchpad.net/ubuntu/+source/dpkg/1.14.20ubuntu6.3"}],"jaunty":[{"name":"dpkg","version":"1.14.24ubuntu1.1","description":"","is_source":true},{"name":"dpkg-dev","version":"1.14.24ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dpkg","version_link":"https://launchpad.net/ubuntu/+source/dpkg/1.14.24ubuntu1.1"}],"karmic":[{"name":"dpkg","version":"1.15.4ubuntu2.1","description":"","is_source":true},{"name":"dpkg-dev","version":"1.15.4ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dpkg","version_link":"https://launchpad.net/ubuntu/+source/dpkg/1.15.4ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2010-0396"]}]},{"id":"CVE-2010-0791","published":"2010-03-10T20:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6\ndo not properly create lock files, which allows local users to cause a\ndenial of service (application failure) via unspecified vectors that\ntrigger the creation of a /etc/mtab~ file that persists after the program\nexits.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://seclists.org/fulldisclosure/2010/Mar/122","https://www.cve.org/CVERecord?id=CVE-2010-0791"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=572937"],"patches":{"ncpfs":[]},"tags":{},"packages":[{"name":"ncpfs","source":"https://ubuntu.com/security/cve?package=ncpfs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ncpfs","debian":"https://tracker.debian.org/pkg/ncpfs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0790","published":"2010-03-10T20:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed\nerror messages about the results of privileged file-access attempts, which\nallows local users to determine the existence of arbitrary files via the\nmountpoint name.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://seclists.org/fulldisclosure/2010/Mar/122","https://www.cve.org/CVERecord?id=CVE-2010-0790"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=572937"],"patches":{"ncpfs":[]},"tags":{},"packages":[{"name":"ncpfs","source":"https://ubuntu.com/security/cve?package=ncpfs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ncpfs","debian":"https://tracker.debian.org/pkg/ncpfs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0728","published":"2010-03-10T20:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsmbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled,\nruns with the CAP_DAC_OVERRIDE capability, which allows remote\nauthenticated users to bypass intended file permissions via standard\nfilesystem operations with any client.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"new code introduced in 3.4.6"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0728"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=7222"],"patches":{"samba":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"dapper","status":"not-affected","description":"3.0.22-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"3.0.28a-1ubuntu4.10","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2:3.2.3-1ubuntu3.7","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2:3.3.2-1ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2:3.4.0-3ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0926","published":"2010-03-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of smbd in Samba before 3.3.11, 3.4.x before\n3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows\nremote authenticated users to leverage a directory traversal vulnerability,\nand access arbitrary files, by using the symlink command in smbclient to\ncreate a symlink containing .. (dot dot) sequences, related to the\ncombination of the unix extensions and wide links options.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"In a default samba configuration, both the unix extensions\nand the wide links options are on by default.\nUnix extensions gives extra capabilities to UNIX clients, including\nsymlink support. If a client connects and uses UNIX capabilities,\nsymlinks are sent as-is by the server and are handled by the client. If\nthe client doesn't support UNIX extensions, the server will resolve the\nsymlink and send the actual file it links to.\nWide links tells the samba server to follow symlinks even if they point\noutside the shared directory.\nThe combination of these two parameters can be exploited in the following\nway:\n- Unix client creates a new symlink to /\n- Windows client can then enter the directory pointed to by the symlink\nas it is followed server-side and read any file from the server's\nfilesystem, if DAC permissions allow it.\nThere is no simple way to fix this issue without possible breaking\nexisting configurations. Leaving it unfixed results in server admins\ninadvertantly sharing the whole server filesystem. Fixing it results\nin breaking configurations where a samba share contains symlinks that\npoint outside of the shared directory.\nThe upstream patch changes samba behaviour in that the \"wide links\"\noption will get disabled automatically if \"UNIX permissions\" is enabled.\nA warning will be issued in the server's log file, which will help\ndiagnose the problem\nPoC: http://blog.metasploit.com/2010/02/exploiting-samba-symlink-traversal.html"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=samba-technical&m=126539387432412&w=2","http://www.samba.org/samba/news/symlink_attack.html","https://ubuntu.com/security/notices/USN-918-1","https://www.cve.org/CVERecord?id=CVE-2010-0926"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=7104","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=568493","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=572953"],"patches":{"samba":["upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=bd269443e311d96ef495a9db47d1b95eb83bb8f4","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=fac6d5212be3e7159896a9c67e15faa4a557c213","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=cd18695fc2e4d09ab75e9eab2f0c43dcc15adf0b","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=94865e4dbd3d721c9855aada8c55e02be8b3881e","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=5d92d969dda450cc3564dd2265d2b042d832c542","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=02a5078f1fe6285e4a0b6ad95a3aea1c5bb3e8cf","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=a6f402ad87ff0ae14d57d97278d67d0ceaaa1d82","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=9fc76f86fa2c60b81ec8afee515bb823a5cd616f","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=9e64c33b7757dd4528a9c8d31d0c0c159a33daf8","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=16e73d88944ce644cccfa19a99338f5903c061f0","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=c1b05ae4febfba1a419eee0d04c3886de9f5fee0","upstream: http://gitweb.samba.org/?p=samba.git;a=commitdiff;h=ce04bf60499104c166657df959e4033573b5be5c"]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"dapper","status":"released","description":"3.0.22-1ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.28a-1ubuntu4.11","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2:3.2.3-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2:3.3.2-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2:3.4.0-3ubuntu5.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-918-1"],"notices":[{"id":"USN-918-1","title":"Samba vulnerability","summary":"Samba vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n\nATTENTION: This update changes the default samba behaviour. For security\nreasons, it is no longer possible to use wide links and UNIX extensions at\nthe same time. After applying this security update, wide links will be\ndisabled automatically as UNIX extensions are turned on by default. If\nwide links are required, you can re-enable them by adding\n\"unix extensions = no\" to the [global] section of the /etc/samba/smb.conf\nconfiguration file.\n","references":[],"published":"2010-03-24T13:30:14.106260","description":"It was discovered the Samba handled symlinks in an unexpected way when both\n\"wide links\" and \"UNIX extensions\" were enabled, which is the default. A\nremote attacker could create symlinks and access arbitrary files from the\nserver.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"samba","version":"3.0.28a-1ubuntu4.11","description":"","is_source":true},{"name":"samba","version":"3.0.28a-1ubuntu4.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.11"}],"dapper":[{"name":"samba","version":"3.0.22-1ubuntu3.11","description":"","is_source":true},{"name":"samba","version":"3.0.22-1ubuntu3.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu3.11"}],"intrepid":[{"name":"samba","version":"2:3.2.3-1ubuntu3.8","description":"","is_source":true},{"name":"samba","version":"2:3.2.3-1ubuntu3.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.8"}],"jaunty":[{"name":"samba","version":"2:3.3.2-1ubuntu3.4","description":"","is_source":true},{"name":"samba","version":"2:3.3.2-1ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.3.2-1ubuntu3.4"}],"karmic":[{"name":"samba","version":"2:3.4.0-3ubuntu5.6","description":"","is_source":true},{"name":"samba","version":"2:3.4.0-3ubuntu5.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.4.0-3ubuntu5.6"}]},"type":"USN","cves_ids":["CVE-2010-0926"]}]},{"id":"CVE-2010-0928","published":"2010-03-05T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II\nPro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain\nsignature calculations, and does not verify the signature before providing\nit to a caller, which makes it easier for physically proximate attackers to\ndetermine the private key via a modified supply voltage for the\nmicroprocessor, related to a \"fault-based attack.\"","ubuntu_description":"","notes":[{"author":"kees","note":"if someone is glitching your powersupply, you've got other things\nto worry about."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0928"],"bugs":[""],"patches":{"openssl":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0792","published":"2010-03-05T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfcrontab in fcron before 3.0.5 allows local users to read arbitrary files\nvia a symlink attack on an unspecified file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0792"],"bugs":[""],"patches":{"fcron":[]},"tags":{},"packages":[{"name":"fcron","source":"https://ubuntu.com/security/cve?package=fcron","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fcron","debian":"https://tracker.debian.org/pkg/fcron","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0433","published":"2010-03-05T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before\n0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be\nopened, does not check a certain return value, which allows remote\nattackers to cause a denial of service (NULL pointer dereference and daemon\ncrash) via SSL cipher negotiation, as demonstrated by a chroot installation\nof Dovecot or stunnel without Kerberos configuration files inside the\nchroot.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Ubuntu doesn't build openssl with kerberos support"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0433"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=567711"],"patches":{"openssl":["upstream: http://cvs.openssl.org/chngview?cn=19374"]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no kerberos support","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no kerberos support","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"no kerberos support","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"no kerberos support","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"no kerberos support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.8n","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0425","published":"2010-03-05T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmodules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server\n2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when\nrunning on Windows, does not ensure that request processing is complete\nbefore calling isapi_unload for an ISAPI .dll module, which allows remote\nattackers to execute arbitrary code via unspecified vectors related to a\ncrafted request, a reset packet, and \"orphaned callback pointers.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0425"],"bugs":[""],"patches":{"apache2":[]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"2.3.x, Windows-only","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.3.x, Windows-only","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.3.x, Windows-only","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.3.x, Windows-only","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.3.x, Windows-only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":73120,"limit":20,"total_results":79316}