{"cves":[{"id":"CVE-2010-0434","published":"2010-03-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ap_read_request function in server/protocol.c in the Apache HTTP Server\n2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly\nhandle headers in subrequests in certain circumstances involving a parent\nrequest that has a body, which might allow remote attackers to obtain\nsensitive information via a crafted request that triggers access to memory\nlocations associated with an earlier request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://httpd.apache.org/security/vulnerabilities_22.html#2.2.15","https://ubuntu.com/security/notices/USN-908-1","https://www.cve.org/CVERecord?id=CVE-2010-0434"],"bugs":["https://issues.apache.org/bugzilla/show_bug.cgi?id=48359"],"patches":{"apache2":["upstream: http://svn.apache.org/viewvc?view=revision&revision=917867","upstream: http://svn.apache.org/viewvc?view=revision&revision=918427"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.2.8-1ubuntu0.15","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.2.9-7ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.2.11-2ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.2.12-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-908-1"],"notices":[{"id":"USN-908-1","title":"Apache vulnerabilities","summary":"Apache vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-10T19:39:09.227328","description":"It was discovered that mod_proxy_ajp did not properly handle errors when\na client doesn't send a request body. A remote attacker could exploit this\nwith a crafted request and cause a denial of service. This issue affected\nUbuntu 8.04 LTS, 8.10, 9.04 and 9.10. (CVE-2010-0408)\n\nIt was discovered that Apache did not properly handle headers in\nsubrequests under certain conditions. A remote attacker could exploit this\nwith a crafted request and possibly obtain sensitive information from\nprevious requests. (CVE-2010-0434)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"apache2","version":"2.2.8-1ubuntu0.15","description":"","is_source":true},{"name":"apache2.2-common","version":"2.2.8-1ubuntu0.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.15"}],"dapper":[{"name":"apache2","version":"2.0.55-4ubuntu2.10","description":"","is_source":true},{"name":"apache2-common","version":"2.0.55-4ubuntu2.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.10"}],"intrepid":[{"name":"apache2","version":"2.2.9-7ubuntu3.6","description":"","is_source":true},{"name":"apache2.2-common","version":"2.2.9-7ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.9-7ubuntu3.6"}],"jaunty":[{"name":"apache2","version":"2.2.11-2ubuntu2.6","description":"","is_source":true},{"name":"apache2.2-common","version":"2.2.11-2ubuntu2.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.11-2ubuntu2.6"}],"karmic":[{"name":"apache2","version":"2.2.12-1ubuntu2.2","description":"","is_source":true},{"name":"apache2.2-common","version":"2.2.12-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.12-1ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2010-0408","CVE-2010-0434"]}]},{"id":"CVE-2010-0419","published":"2010-03-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe x86 emulator in KVM 83, when a guest is configured for Symmetric\nMultiprocessing (SMP), does not properly restrict writing of segment\nselectors to segment registers, which might allow guest OS users to cause a\ndenial of service (guest OS crash) or gain privileges on the guest OS by\nleveraging access to a (1) IO port or (2) MMIO region, and replacing an\ninstruction in between emulator entry and instruction fetch.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"patch pulled in Lucid since the patch failed. Patch may not actually\nbe needed"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-947-1","https://www.cve.org/CVERecord?id=CVE-2010-0419"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[],"kvm":["vendor: http://security.debian.org/pool/updates/main/k/kvm/kvm_72+dfsg-5~lenny5.diff.gz"],"qemu-kvm":[],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[]},"tags":{"kvm":["universe-binary"]},"packages":[{"name":"kvm","source":"https://ubuntu.com/security/cve?package=kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kvm","debian":"https://tracker.debian.org/pkg/kvm","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.61","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.60","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.15","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.14","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-947-1"],"notices":[{"id":"USN-947-1","title":"Linux kernel vulnerabilities","summary":"Multiple flaws in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2010-06-03T06:23:23.617205","description":"It was discovered that the Linux kernel did not correctly handle memory\nprotection of the Virtual Dynamic Shared Object page when running\na 32-bit application on a 64-bit kernel. A local attacker could\nexploit this to cause a denial of service. (Only affected Ubuntu 6.06\nLTS.) (CVE-2009-4271)\n\nIt was discovered that the r8169 network driver did not correctly check\nthe size of Ethernet frames. A remote attacker could send specially\ncrafted traffic to crash the system, leading to a denial of service.\n(CVE-2009-4537)\n\nWei Yongjun discovered that SCTP did not correctly validate certain\nchunks. A remote attacker could send specially crafted traffic to\nmonopolize CPU resources, leading to a denial of service. (Only affected\nUbuntu 6.06 LTS.) (CVE-2010-0008)\n\nIt was discovered that KVM did not correctly limit certain privileged\nIO accesses on x86. Processes in the guest OS with access to IO regions\ncould gain further privileges within the guest OS. (Did not affect Ubuntu\n6.06 LTS.) (CVE-2010-0298, CVE-2010-0306, CVE-2010-0419)\n\nEvgeniy Polyakov discovered that IPv6 did not correctly handle\ncertain TUN packets. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (Only affected Ubuntu 8.04\nLTS.) (CVE-2010-0437)\n\nSachin Prabhu discovered that GFS2 did not correctly handle certain locks.\nA local attacker with write access to a GFS2 filesystem could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-0727)\n\nJamie Strandboge discovered that network virtio in KVM did not correctly\nhandle certain high-traffic conditions. A remote attacker could exploit\nthis by sending specially crafted traffic to a guest OS, causing the\nguest to crash, leading to a denial of service. (Only affected Ubuntu\n8.04 LTS.) (CVE-2010-0741)\n\nMarcus Meissner discovered that the USB subsystem did not correctly handle\ncertain error conditions. A local attacker with access to a USB device\ncould exploit this to read recently used kernel memory, leading to a\nloss of privacy and potentially root privilege escalation. (CVE-2010-1083)\n\nNeil Brown discovered that the Bluetooth subsystem did not correctly\nhandle large amounts of traffic. A physically proximate remote attacker\ncould exploit this by sending specially crafted traffic that would consume\nall available system memory, leading to a denial of service. (Ubuntu\n6.06 LTS and 10.04 LTS were not affected.) (CVE-2010-1084)\n\nJody Bruchon discovered that the sound driver for the AMD780V did not\ncorrectly handle certain conditions. A local attacker with access to\nthis hardward could exploit the flaw to cause a system crash, leading\nto a denial of service. (CVE-2010-1085)\n\nAng Way Chuang discovered that the DVB driver did not correctly handle\ncertain MPEG2-TS frames. An attacker could exploit this by delivering\nspecially crafted frames to monopolize CPU resources, leading to a denial\nof service. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1086)\n\nTrond Myklebust discovered that NFS did not correctly handle truncation\nunder certain conditions. A local attacker with write access to an NFS\nshare could exploit this to crash the system, leading to a denial of\nservice. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1087)\n\nAl Viro discovered that automount of NFS did not correctly handle symlinks\nunder certain conditions. A local attacker could exploit this to crash\nthe system, leading to a denial of service. (Ubuntu 6.06 LTS and Ubuntu\n10.04 LTS were not affected.) (CVE-2010-1088)\n\nMatt McCutchen discovered that ReiserFS did not correctly protect xattr\nfiles in the .reiserfs_priv directory. A local attacker could exploit\nthis to gain root privileges or crash the system, leading to a denial\nof service. (CVE-2010-1146)\n\nEugene Teo discovered that CIFS did not correctly validate arguments when\ncreating new files. A local attacker could exploit this to crash the\nsystem, leading to a denial of service, or possibly gain root privileges\nif mmap_min_addr was not set. (CVE-2010-1148)\n\nCatalin Marinas and Tetsuo Handa discovered that the TTY layer did not\ncorrectly release process IDs. A local attacker could exploit this to\nconsume kernel resources, leading to a denial of service. (CVE-2010-1162)\n\nNeil Horman discovered that TIPC did not correctly check its internal\nstate. A local attacker could send specially crafted packets via AF_TIPC\nthat would cause the system to crash, leading to a denial of service.\n(Ubuntu 6.06 LTS was not affected.) (CVE-2010-1187)\n\nMasayuki Nakagawa discovered that IPv6 did not correctly handle\ncertain settings when listening. If a socket were listening with the\nIPV6_RECVPKTINFO flag, a remote attacker could send specially crafted\ntraffic that would cause the system to crash, leading to a denial of\nservice. (Only Ubuntu 6.06 LTS was affected.) (CVE-2010-1188)\n\nOleg Nesterov discovered that the Out-Of-Memory handler did not correctly\nhandle certain arrangements of processes. A local attacker could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-1488)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.28","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-112.28","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.15","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.60","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.15"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.28"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"}],"hardy":[{"name":"linux","version":"2.6.24-28.70","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"}],"lucid":[{"name":"linux-ec2","version":"2.6.32-306.11","description":"Linux kernel for EC2","is_source":true},{"name":"linux-qcm-msm","version":"2.6.31-802.4","description":"Linux kernel for qcm-msm ARM","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-501.7","description":"Linux kernel for ti-omap ARM","is_source":true},{"name":"linux-mvl-dove","version":"2.6.32-205.18","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux","version":"2.6.32-22.35","description":"Linux kernel","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-608.14","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-image-2.6.32-22-powerpc","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-802-st1-5","version":"2.6.31-802.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm","version_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm/2.6.31-802.4"},{"name":"linux-image-2.6.32-22-powerpc-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-virtual","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.14"},{"name":"linux-image-2.6.32-22-powerpc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.33-501-omap","version":"2.6.33-501.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-501.7"},{"name":"linux-image-2.6.32-22-generic-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-205-dove","version":"2.6.32-205.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-205.18"},{"name":"linux-image-2.6.32-22-ia64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-306-ec2","version":"2.6.32-306.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-306.11"},{"name":"linux-image-2.6.32-22-preempt","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-preempt-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-ia64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.84","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"}],"jaunty":[{"name":"linux","version":"2.6.28-19.61","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"}]},"type":"USN","cves_ids":["CVE-2009-4271","CVE-2009-4537","CVE-2010-0008","CVE-2010-0298","CVE-2010-0306","CVE-2010-0419","CVE-2010-0437","CVE-2010-0727","CVE-2010-0741","CVE-2010-1083","CVE-2010-1084","CVE-2010-1085","CVE-2010-1086","CVE-2010-1087","CVE-2010-1088","CVE-2010-1146","CVE-2010-1148","CVE-2010-1162","CVE-2010-1187","CVE-2010-1188","CVE-2010-1488"]}]},{"id":"CVE-2010-0408","published":"2010-03-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in\nthe Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain\nsituations in which a client sends no request body, which allows remote\nattackers to cause a denial of service (backend server outage) via a\ncrafted request, related to use of a 500 error code instead of the\nappropriate 400 error code.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Apache 2.0 doesn't have mod_proxy_ajp"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://httpd.apache.org/security/vulnerabilities_22.html#2.2.15","https://ubuntu.com/security/notices/USN-908-1","https://www.cve.org/CVERecord?id=CVE-2010-0408"],"bugs":[""],"patches":{"apache2":["upstream: http://svn.apache.org/viewvc?view=revision&revision=917876"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.2.8-1ubuntu0.15","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.2.9-7ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.2.11-2ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.2.12-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-908-1"],"notices":[{"id":"USN-908-1","title":"Apache vulnerabilities","summary":"Apache vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-10T19:39:09.227328","description":"It was discovered that mod_proxy_ajp did not properly handle errors when\na client doesn't send a request body. A remote attacker could exploit this\nwith a crafted request and cause a denial of service. This issue affected\nUbuntu 8.04 LTS, 8.10, 9.04 and 9.10. (CVE-2010-0408)\n\nIt was discovered that Apache did not properly handle headers in\nsubrequests under certain conditions. A remote attacker could exploit this\nwith a crafted request and possibly obtain sensitive information from\nprevious requests. (CVE-2010-0434)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"apache2","version":"2.2.8-1ubuntu0.15","description":"","is_source":true},{"name":"apache2.2-common","version":"2.2.8-1ubuntu0.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.15"}],"dapper":[{"name":"apache2","version":"2.0.55-4ubuntu2.10","description":"","is_source":true},{"name":"apache2-common","version":"2.0.55-4ubuntu2.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.10"}],"intrepid":[{"name":"apache2","version":"2.2.9-7ubuntu3.6","description":"","is_source":true},{"name":"apache2.2-common","version":"2.2.9-7ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.9-7ubuntu3.6"}],"jaunty":[{"name":"apache2","version":"2.2.11-2ubuntu2.6","description":"","is_source":true},{"name":"apache2.2-common","version":"2.2.11-2ubuntu2.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.11-2ubuntu2.6"}],"karmic":[{"name":"apache2","version":"2.2.12-1ubuntu2.2","description":"","is_source":true},{"name":"apache2.2-common","version":"2.2.12-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.12-1ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2010-0408","CVE-2010-0434"]}]},{"id":"CVE-2009-3245","published":"2010-03-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenSSL before 0.9.8m does not check for a NULL return value from\nbn_wexpand function calls in (1) crypto/bn/bn_div.c, (2)\ncrypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c,\nwhich has unspecified impact and context-dependent attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1003-1","https://www.cve.org/CVERecord?id=CVE-2009-3245"],"bugs":["http://rt.openssl.org/Ticket/Display.html?id=2111&user=guest&pass=guest","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3245","https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/655884"],"patches":{"openssl":["upstream: http://cvs.openssl.org/chngview?cn=18936","upstream: http://cvs.openssl.org/chngview?cn=19309"]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"dapper","status":"released","description":"0.9.8a-7ubuntu0.13","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.9.8g-4ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.9.8g-15ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.8m","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.9.8g-16ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.9.8k-7ubuntu8","component":null,"pocket":"security"}]}],"notices_ids":["USN-1003-1"],"notices":[{"id":"USN-1003-1","title":"OpenSSL vulnerabilities","summary":"","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2010-10-07T14:46:34.282164","description":"It was discovered that OpenSSL incorrectly handled return codes from the\nbn_wexpand function calls. A remote attacker could trigger this flaw in\nservices that used SSL to cause a denial of service or possibly execute\narbitrary code with application privileges. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2009-3245)\n\nIt was discovered that OpenSSL incorrectly handled certain private keys\nwith an invalid prime. A remote attacker could trigger this flaw in\nservices that used SSL to cause a denial of service or possibly execute\narbitrary code with application privileges. The default compiler options\nfor affected releases should reduce the vulnerability to a denial of\nservice. (CVE-2010-2939)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"openssl","version":"0.9.8k-7ubuntu8.3","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8k-7ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8k-7ubuntu8.3"}],"karmic":[{"name":"openssl","version":"0.9.8g-16ubuntu3.3","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-16ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-16ubuntu3.3"}],"hardy":[{"name":"openssl","version":"0.9.8g-4ubuntu3.11","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-4ubuntu3.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-4ubuntu3.11"}],"dapper":[{"name":"openssl","version":"0.9.8a-7ubuntu0.13","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8a-7ubuntu0.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8a-7ubuntu0.13"}],"maverick":[{"name":"openssl","version":"0.9.8o-1ubuntu4.1","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8o-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8o-1ubuntu4.1"}],"jaunty":[{"name":"openssl","version":"0.9.8g-15ubuntu3.6","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-15ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-15ubuntu3.6"}]},"type":"USN","cves_ids":["CVE-2009-3245","CVE-2010-2939"]}]},{"id":"CVE-2009-4664","published":"2010-03-03T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nFirewall Builder 3.0.4, 3.0.5, and 3.0.6, when running on Linux, allows\nlocal users to gain privileges via a symlink attack on an unspecified\ntemporary file that is created by the iptables script.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4664"],"bugs":[""],"patches":{"fwbuilder":[]},"tags":{},"packages":[{"name":"fwbuilder","source":"https://ubuntu.com/security/cve?package=fwbuilder","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fwbuilder","debian":"https://tracker.debian.org/pkg/fwbuilder","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0923","published":"2010-03-03T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock\nmodule in kdebase in KDE SC 4.4.0 allows physically proximate attackers to\nbypass KScreenSaver screen locking and access an unattended workstation by\npressing the Enter key at a certain time, related to multiple forked\nprocesses.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0923"],"bugs":[""],"patches":{"kdebase-workspace":["upstream: http://websvn.kde.org/?view=revision&revision=1089241"]},"tags":{},"packages":[{"name":"kdebase-workspace","source":"https://ubuntu.com/security/cve?package=kdebase-workspace","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdebase-workspace","debian":"https://tracker.debian.org/pkg/kdebase-workspace","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0393","published":"2010-03-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2,\n1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the\nfile that provides localized message strings, which allows local users to\ngain privileges via a file that contains crafted localization data with\nformat string specifiers.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Fortify source removed the root escalation part"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-906-1","https://www.cve.org/CVERecord?id=CVE-2010-0393"],"bugs":[""],"patches":{"cups":[],"cupsys":[]},"tags":{"cups":["fortify-source"]},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.3.9-2ubuntu9.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.3.9-17ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.4.1-5ubuntu2.4","component":null,"pocket":"security"}]},{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.2-0ubuntu0.6.06.17","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.3.7-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-906-1"],"notices":[{"id":"USN-906-1","title":"CUPS vulnerabilities","summary":"CUPS vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-03T20:07:34.035561","description":"It was discovered that the CUPS scheduler did not properly handle certain\nnetwork operations. A remote attacker could exploit this flaw and cause the\nCUPS server to crash, resulting in a denial of service. This issue only\naffected Ubuntu 8.04 LTS, 8.10, 9.04 and 9.10. (CVE-2009-3553,\nCVE-2010-0302)\n\nRonald Volgers discovered that the CUPS lppasswd tool could be made to load\nlocalized message strings from arbitrary files by setting an environment\nvariable. A local attacker could exploit this with a format-string\nvulnerability leading to a root privilege escalation. The default compiler\noptions for Ubuntu 8.10, 9.04 and 9.10 should reduce this vulnerability to\na denial of service. (CVE-2010-0393)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"cupsys","version":"1.3.7-1ubuntu3.8","description":"","is_source":true},{"name":"cupsys-client","version":"1.3.7-1ubuntu3.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.7-1ubuntu3.8"},{"name":"cupsys","version":"1.3.7-1ubuntu3.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.7-1ubuntu3.8"}],"dapper":[{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.17","description":"","is_source":true},{"name":"cupsys-client","version":"1.2.2-0ubuntu0.6.06.17","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.2-0ubuntu0.6.06.17"},{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.17","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.2-0ubuntu0.6.06.17"}],"intrepid":[{"name":"cups","version":"1.3.9-2ubuntu9.5","description":"","is_source":true},{"name":"cups","version":"1.3.9-2ubuntu9.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.3.9-2ubuntu9.5"},{"name":"cups-client","version":"1.3.9-2ubuntu9.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.3.9-2ubuntu9.5"}],"jaunty":[{"name":"cups","version":"1.3.9-17ubuntu3.6","description":"","is_source":true},{"name":"cups","version":"1.3.9-17ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.3.9-17ubuntu3.6"},{"name":"cups-client","version":"1.3.9-17ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.3.9-17ubuntu3.6"}],"karmic":[{"name":"cups","version":"1.4.1-5ubuntu2.4","description":"","is_source":true},{"name":"cups","version":"1.4.1-5ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.4.1-5ubuntu2.4"},{"name":"cups-client","version":"1.4.1-5ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.4.1-5ubuntu2.4"}]},"type":"USN","cves_ids":["CVE-2009-3553","CVE-2010-0302","CVE-2010-0393"]}]},{"id":"CVE-2010-0302","published":"2010-03-03T00:00:00","updated_at":"2025-08-25T19:53:49.592890+00:00","description":"\nUse-after-free vulnerability in the abstract file-descriptor handling\ninterface in the cupsdDoSelect function in scheduler/select.c in the\nscheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used,\nallows remote attackers to cause a denial of service (daemon crash or hang)\nvia a client disconnection during listing of a large number of print jobs,\nrelated to improperly maintaining a reference count. NOTE: some of these\ndetails are obtained from third party information. NOTE: this vulnerability\nexists because of an incomplete fix for CVE-2009-3553.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-906-1","https://www.cve.org/CVERecord?id=CVE-2010-0302"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=557775"],"patches":{"cups":[],"cupsys":[]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.3.9-2ubuntu9.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.3.9-17ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.4.1-5ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.3.7-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-906-1"],"notices":[{"id":"USN-906-1","title":"CUPS vulnerabilities","summary":"CUPS vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-03T20:07:34.035561","description":"It was discovered that the CUPS scheduler did not properly handle certain\nnetwork operations. A remote attacker could exploit this flaw and cause the\nCUPS server to crash, resulting in a denial of service. This issue only\naffected Ubuntu 8.04 LTS, 8.10, 9.04 and 9.10. (CVE-2009-3553,\nCVE-2010-0302)\n\nRonald Volgers discovered that the CUPS lppasswd tool could be made to load\nlocalized message strings from arbitrary files by setting an environment\nvariable. A local attacker could exploit this with a format-string\nvulnerability leading to a root privilege escalation. The default compiler\noptions for Ubuntu 8.10, 9.04 and 9.10 should reduce this vulnerability to\na denial of service. (CVE-2010-0393)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"cupsys","version":"1.3.7-1ubuntu3.8","description":"","is_source":true},{"name":"cupsys-client","version":"1.3.7-1ubuntu3.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.7-1ubuntu3.8"},{"name":"cupsys","version":"1.3.7-1ubuntu3.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.7-1ubuntu3.8"}],"dapper":[{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.17","description":"","is_source":true},{"name":"cupsys-client","version":"1.2.2-0ubuntu0.6.06.17","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.2-0ubuntu0.6.06.17"},{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.17","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.2-0ubuntu0.6.06.17"}],"intrepid":[{"name":"cups","version":"1.3.9-2ubuntu9.5","description":"","is_source":true},{"name":"cups","version":"1.3.9-2ubuntu9.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.3.9-2ubuntu9.5"},{"name":"cups-client","version":"1.3.9-2ubuntu9.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.3.9-2ubuntu9.5"}],"jaunty":[{"name":"cups","version":"1.3.9-17ubuntu3.6","description":"","is_source":true},{"name":"cups","version":"1.3.9-17ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.3.9-17ubuntu3.6"},{"name":"cups-client","version":"1.3.9-17ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.3.9-17ubuntu3.6"}],"karmic":[{"name":"cups","version":"1.4.1-5ubuntu2.4","description":"","is_source":true},{"name":"cups","version":"1.4.1-5ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.4.1-5ubuntu2.4"},{"name":"cups-client","version":"1.4.1-5ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.4.1-5ubuntu2.4"}]},"type":"USN","cves_ids":["CVE-2009-3553","CVE-2010-0302","CVE-2010-0393"]}]},{"id":"CVE-2010-0205","published":"2010-03-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe png_decompress_chunk function in pngrutil.c in libpng 1.0.x before\n1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly\nhandle compressed ancillary-chunk data that has a disproportionately large\nuncompressed representation, which allows remote attackers to cause a\ndenial of service (memory and CPU consumption, and application hang) via a\ncrafted PNG file, as demonstrated by use of the deflate compression method\non data composed of many occurrences of the same character, related to a\n\"decompression bomb\" attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-913-1","https://www.cve.org/CVERecord?id=CVE-2010-0205"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=572308","https://bugs.launchpad.net/ubuntu/+source/libpng/+bug/533140"],"patches":{"libpng":["upstream: http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=a2cde53c878054847a57c2c793febcaf78f823e0#patch3"],"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.8rel-5ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.15~beta5-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.2.27-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.2.27-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.37-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-913-1"],"notices":[{"id":"USN-913-1","title":"libpng vulnerabilities","summary":"libpng vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to effect\nthe necessary changes. \n","references":[],"published":"2010-03-16T17:11:19.116846","description":"It was discovered that libpng did not properly initialize memory when\ndecoding certain 1-bit interlaced images. If a user or automated system\nwere tricked into processing crafted PNG images, an attacker could possibly\nuse this flaw to read sensitive information stored in memory. This issue\nonly affected Ubuntu 6.06 LTS, 8.04 LTS, 8.10 and 9.04. (CVE-2009-2042)\n\nIt was discovered that libpng did not properly handle certain excessively\ncompressed PNG images. If a user or automated system were tricked into\nprocessing a crafted PNG image, an attacker could possibly use this flaw to\nconsume all available resources, resulting in a denial of service.\n(CVE-2010-0205)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libpng","version":"1.2.15~beta5-3ubuntu0.2","description":"","is_source":true},{"name":"libpng12-0","version":"1.2.15~beta5-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.15~beta5-3ubuntu0.2"}],"dapper":[{"name":"libpng","version":"1.2.8rel-5ubuntu0.5","description":"","is_source":true},{"name":"libpng12-0","version":"1.2.8rel-5ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.8rel-5ubuntu0.5"}],"intrepid":[{"name":"libpng","version":"1.2.27-1ubuntu0.2","description":"","is_source":true},{"name":"libpng12-0","version":"1.2.27-1ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.27-1ubuntu0.2"}],"jaunty":[{"name":"libpng","version":"1.2.27-2ubuntu2.1","description":"","is_source":true},{"name":"libpng12-0","version":"1.2.27-2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.27-2ubuntu2.1"}],"karmic":[{"name":"libpng","version":"1.2.37-1ubuntu0.1","description":"","is_source":true},{"name":"libpng12-0","version":"1.2.37-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.37-1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2009-2042","CVE-2010-0205"]}]},{"id":"CVE-2010-0156","published":"2010-03-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPuppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to\noverwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout,\n(2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux\ntemporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://groups.google.com/group/puppet-announce/browse_thread/thread/4401823f6cbf6087","http://groups.google.com/group/puppet-announce/browse_thread/thread/73cd1b2896d986c2","https://ubuntu.com/security/notices/USN-917-1","https://www.cve.org/CVERecord?id=CVE-2010-0156"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=502881"],"patches":{"puppet":["upstream: http://projects.reductivelabs.com/projects/puppet/repository/revisions/0aae57f91dc69b22fb674f8de3a13c22edd07128/diff","upstream: http://projects.reductivelabs.com/projects/puppet/repository/revisions/0dee418554151289b13136c43f0d1d6484efbac7/diff"]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.24.8-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.25.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.25.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.25.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.25.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.25.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-917-1"],"notices":[{"id":"USN-917-1","title":"Puppet vulnerabilities","summary":"Puppet vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-24T12:40:48.566973","description":"It was discovered that Puppet did not drop supplementary groups when being\nrun as a different user. A local user may be able to use this flaw to\nbypass security restrictions and gain access to restricted files.\n(CVE-2009-3564)\n\nIt was discovered that Puppet did not correctly handle temporary files. A\nlocal user can exploit this flaw to bypass security restrictions and\noverwrite arbitrary files. (CVE-2010-0156)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"puppet","version":"0.24.8-2ubuntu4.1","description":"","is_source":true},{"name":"puppet","version":"0.24.8-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/0.24.8-2ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2010-0156","CVE-2009-3564"]}]},{"id":"CVE-2010-0726","published":"2010-03-02T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the tb-send.rb (TrackBack\ntransmission) plugin in tDiary 2.2.2 and earlier allows remote attackers to\ninject arbitrary web script or HTML via unknown vectors, possibly related\nto the (1) plugin_tb_url and (2) plugin_tb_excerpt parameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0726"],"bugs":[""],"patches":{"tdiary":[]},"tags":{},"packages":[{"name":"tdiary","source":"https://ubuntu.com/security/cve?package=tdiary","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tdiary","debian":"https://tracker.debian.org/pkg/tdiary","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.2.1-1+lenny1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.2.1-1+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.2.1-1+lenny1build0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.1-1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0789","published":"2010-03-02T18:30:00","updated_at":"2025-05-26T12:47:11.882847+00:00","description":"\nfusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users\nto unmount an arbitrary FUSE filesystem share via a symlink attack on a\nmountpoint.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0789","https://ubuntu.com/security/notices/USN-892-1"],"bugs":[""],"patches":{"fuse":[]},"tags":{},"packages":[{"name":"fuse","source":"https://ubuntu.com/security/cve?package=fuse","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fuse","debian":"https://tracker.debian.org/pkg/fuse","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.2-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.7.2-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.7.3-4ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.7.4-1.1ubuntu4.0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.7.4-1.1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-892-1"],"notices":[{"id":"USN-892-1","title":"FUSE vulnerability","summary":"FUSE vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-01-28T19:01:42.304229","description":"Dan Rosenberg discovered that FUSE did not correctly check mount\nlocations. A local attacker, with access to use FUSE, could unmount\narbitrary locations, leading to a denial of service.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"fuse","version":"2.7.2-1ubuntu2.1","description":"","is_source":true},{"name":"fuse-utils","version":"2.7.2-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/fuse","version_link":"https://launchpad.net/ubuntu/+source/fuse/2.7.2-1ubuntu2.1"}],"dapper":[{"name":"fuse","version":"2.4.2-0ubuntu3.1","description":"","is_source":true},{"name":"fuse-utils","version":"2.4.2-0ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/fuse","version_link":"https://launchpad.net/ubuntu/+source/fuse/2.4.2-0ubuntu3.1"}],"intrepid":[{"name":"fuse","version":"2.7.3-4ubuntu2.1","description":"","is_source":true},{"name":"fuse-utils","version":"2.7.3-4ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/fuse","version_link":"https://launchpad.net/ubuntu/+source/fuse/2.7.3-4ubuntu2.1"}],"jaunty":[{"name":"fuse","version":"2.7.4-1.1ubuntu4.0.9.04.1","description":"","is_source":true},{"name":"fuse-utils","version":"2.7.4-1.1ubuntu4.0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/fuse","version_link":"https://launchpad.net/ubuntu/+source/fuse/2.7.4-1.1ubuntu4.0.9.04.1"}],"karmic":[{"name":"fuse","version":"2.7.4-1.1ubuntu4.3","description":"","is_source":true},{"name":"fuse-utils","version":"2.7.4-1.1ubuntu4.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/fuse","version_link":"https://launchpad.net/ubuntu/+source/fuse/2.7.4-1.1ubuntu4.3"}]},"type":"USN","cves_ids":["CVE-2009-3297","CVE-2010-0789"]}]},{"id":"CVE-2010-0788","published":"2010-03-02T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nncpfs 2.2.6 allows local users to cause a denial of service, obtain\nsensitive information, or possibly gain privileges via symlink attacks\ninvolving the (1) ncpmount and (2) ncpumount programs.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0788"],"bugs":[""],"patches":{"ncpfs":[]},"tags":{},"packages":[{"name":"ncpfs","source":"https://ubuntu.com/security/cve?package=ncpfs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ncpfs","debian":"https://tracker.debian.org/pkg/ncpfs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.2.6-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0787","published":"2010-03-02T18:30:00","updated_at":"2025-05-26T12:47:11.882847+00:00","description":"\nclient/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3,\n3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an\narbitrary mountpoint, and gain privileges, via a symlink attack on the\nmountpoint directory file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0787","https://ubuntu.com/security/notices/USN-893-1"],"bugs":[""],"patches":{"samba":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"3.0.22-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.28a-1ubuntu4.10","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2:3.2.3-1ubuntu3.7","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2:3.3.2-1ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2:3.4.0-3ubuntu5.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-893-1"],"notices":[{"id":"USN-893-1","title":"Samba vulnerability","summary":"Samba vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-01-28T18:38:12.138203","description":"Ronald Volgers discovered that the mount.cifs utility, when installed as a\nsetuid program, suffered from a race condition when verifying user\npermissions. A local attacker could trick samba into mounting over\narbitrary locations, leading to a root privilege escalation.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"samba","version":"3.0.28a-1ubuntu4.10","description":"","is_source":true},{"name":"smbfs","version":"3.0.28a-1ubuntu4.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.10"}],"dapper":[{"name":"samba","version":"3.0.22-1ubuntu3.10","description":"","is_source":true},{"name":"smbfs","version":"3.0.22-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu3.10"}],"intrepid":[{"name":"samba","version":"2:3.2.3-1ubuntu3.7","description":"","is_source":true},{"name":"smbfs","version":"2:3.2.3-1ubuntu3.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.7"}],"jaunty":[{"name":"samba","version":"2:3.3.2-1ubuntu3.3","description":"","is_source":true},{"name":"smbfs","version":"2:3.3.2-1ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.3.2-1ubuntu3.3"}],"karmic":[{"name":"samba","version":"2:3.4.0-3ubuntu5.4","description":"","is_source":true},{"name":"smbfs","version":"2:3.4.0-3ubuntu5.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.4.0-3ubuntu5.4"}]},"type":"USN","cves_ids":["CVE-2009-3297","CVE-2010-0787"]}]},{"id":"CVE-2010-0667","published":"2010-02-26T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the\nsys.argv array in situations where the GATEWAY_INTERFACE environment\nvariable is set, which allows remote attackers to obtain sensitive\ninformation via unspecified vectors.","ubuntu_description":"","notes":[{"author":"jdstand","note":"this only affect 1.9"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0667"],"bugs":[""],"patches":{"moin":["upstream: http://hg.moinmo.in/moin/1.9/rev/04afdde50094"]},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-4886","published":"2010-02-26T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe selinux_parse_skb_ipv6 function in security/selinux/hooks.c in the\nLinux kernel before 2.6.12-rc4 allows remote attackers to cause a denial of\nservice (OOPS) via vectors associated with an incorrect call to the\nipv6_skip_exthdr function.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-4886"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.12-rc4","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.12-rc4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4652","published":"2010-02-26T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) Conn_GetCipherInfo and (2) Conn_UsesSSL functions in\nsrc/ngircd/conn.c in ngIRCd 13 and 14, when SSL/TLS support is present and\nstandalone mode is disabled, allow remote attackers to cause a denial of\nservice (application crash) by sending the MOTD command from another server\nin the same IRC network, possibly related to an array index error.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4652"],"bugs":[""],"patches":{"ngircd":[]},"tags":{},"packages":[{"name":"ngircd","source":"https://ubuntu.com/security/cve?package=ngircd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ngircd","debian":"https://tracker.debian.org/pkg/ngircd","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"21-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"21-1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"15-0.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"21-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [21-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0717","published":"2010-02-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of cfg.packagepages_actions_excluded in MoinMoin\nbefore 1.8.7 does not prevent unsafe package actions, which has unspecified\nimpact and attack vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per upstream, this is fixed via the CVE-2010-0668 patchset"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-911-1","https://www.cve.org/CVERecord?id=CVE-2010-0717"],"bugs":[""],"patches":{"moin":[]},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.2-1ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.8-5.1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.7.1-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.8.2-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.8.4-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.7, 1.9.2-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-911-1"],"notices":[{"id":"USN-911-1","title":"MoinMoin vulnerabilities","summary":"MoinMoin vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-11T23:35:10.915972","description":"It was discovered that several wiki actions and preference settings in\nMoinMoin were not protected from cross-site request forgery (CSRF). If an\nauthenticated user were tricked into visiting a malicious website while\nlogged into MoinMoin, a remote attacker could change the user's\nconfiguration or wiki content. (CVE-2010-0668, CVE-2010-0717)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\nprocessing user preferences. An attacker could enter malicious content\nwhich when viewed by a user, could render in unexpected ways.\n(CVE-2010-0669)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"moin","version":"1.5.8-5.1ubuntu2.3","description":"","is_source":true},{"name":"python-moinmoin","version":"1.5.8-5.1ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.8-5.1ubuntu2.3"}],"dapper":[{"name":"moin","version":"1.5.2-1ubuntu2.5","description":"","is_source":true},{"name":"python2.4-moinmoin","version":"1.5.2-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.2-1ubuntu2.5"}],"intrepid":[{"name":"moin","version":"1.7.1-1ubuntu1.3","description":"","is_source":true},{"name":"python-moinmoin","version":"1.7.1-1ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.7.1-1ubuntu1.3"}],"jaunty":[{"name":"moin","version":"1.8.2-2ubuntu2.2","description":"","is_source":true},{"name":"python-moinmoin","version":"1.8.2-2ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.8.2-2ubuntu2.2"}],"karmic":[{"name":"moin","version":"1.8.4-1ubuntu1.1","description":"","is_source":true},{"name":"python-moinmoin","version":"1.8.4-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.8.4-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-0668","CVE-2010-0669","CVE-2010-0717"]}]},{"id":"CVE-2010-0669","published":"2010-02-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize\nuser profiles, which has unspecified impact and attack vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"upstream plans to backport to 1.7 and 1.8 only."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-911-1","https://www.cve.org/CVERecord?id=CVE-2010-0669"],"bugs":[""],"patches":{"moin":["upstream: 3888:232cad689a08","upstream: 3889:970d94ea19f2","upstream: 3890:a7838f68fbcd","upstream: 3891:1f638ed400a0","upstream: 4478:232cad689a08","upstream: 4479:970d94ea19f2","upstream: 4480:a7838f68fbcd","upstream: 4488:1f638ed400a0"]},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.2-1ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.8-5.1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.7.1-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.8.2-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.8.4-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.7, 1.9.2-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-911-1"],"notices":[{"id":"USN-911-1","title":"MoinMoin vulnerabilities","summary":"MoinMoin vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-11T23:35:10.915972","description":"It was discovered that several wiki actions and preference settings in\nMoinMoin were not protected from cross-site request forgery (CSRF). If an\nauthenticated user were tricked into visiting a malicious website while\nlogged into MoinMoin, a remote attacker could change the user's\nconfiguration or wiki content. (CVE-2010-0668, CVE-2010-0717)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\nprocessing user preferences. An attacker could enter malicious content\nwhich when viewed by a user, could render in unexpected ways.\n(CVE-2010-0669)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"moin","version":"1.5.8-5.1ubuntu2.3","description":"","is_source":true},{"name":"python-moinmoin","version":"1.5.8-5.1ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.8-5.1ubuntu2.3"}],"dapper":[{"name":"moin","version":"1.5.2-1ubuntu2.5","description":"","is_source":true},{"name":"python2.4-moinmoin","version":"1.5.2-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.2-1ubuntu2.5"}],"intrepid":[{"name":"moin","version":"1.7.1-1ubuntu1.3","description":"","is_source":true},{"name":"python-moinmoin","version":"1.7.1-1ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.7.1-1ubuntu1.3"}],"jaunty":[{"name":"moin","version":"1.8.2-2ubuntu2.2","description":"","is_source":true},{"name":"python-moinmoin","version":"1.8.2-2ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.8.2-2ubuntu2.2"}],"karmic":[{"name":"moin","version":"1.8.4-1ubuntu1.1","description":"","is_source":true},{"name":"python-moinmoin","version":"1.8.4-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.8.4-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-0668","CVE-2010-0669","CVE-2010-0717"]}]},{"id":"CVE-2010-0668","published":"2010-02-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before\n1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors,\nrelated to configurations that have a non-empty superuser list, the xmlrpc\naction enabled, the SyncPages action enabled, or OpenID configured.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"upstream plans to backport to 1.7 and 1.8 only. Patches for 8.04 LTS\nand 6.06 LTS need a lot of work since the 1.7 patches don't apply."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://moinmo.in/SecurityFixes","https://ubuntu.com/security/notices/USN-911-1","https://www.cve.org/CVERecord?id=CVE-2010-0668"],"bugs":[""],"patches":{"moin":["upstream: 3797:f7e942210f52","upstream: 3871:bba0ab704aa9","upstream: 3872:0eab7483b474","upstream: 3873:2ce0e1c469aa","upstream: 3874:d3e1bae851ef","upstream: 3875:35df310578d7","upstream: 3876:b29b47f681dd","upstream: 3878:7f5b3389a7e1","upstream: 3879:9faee4b754c0","upstream: 3880:a283079b3f1e","upstream: 3881:478dfec03a09","upstream: 3882:0e8fa2a6d016","upstream: 3883:09de6f176a91","upstream: 3884:28d3928f6e6e","upstream: 3885:aa99f8e782dc","upstream: 3886:8a19e015d6b2","upstream: 3887:879674c9320a","upstream: 3892:369a2c879eb6","upstream: 4447:bba0ab704aa9","upstream: 4448:0eab7483b474","upstream: 4450:2ce0e1c469aa","upstream: 4452:35df310578d7","upstream: 4453:b29b47f681dd","upstream: 4454:d3e1bae851ef","upstream: 4457:7f5b3389a7e1","upstream: 4458:9faee4b754c0","upstream: 4459:a283079b3f1e","upstream: 4469:478dfec03a09","upstream: 4470:0e8fa2a6d016","upstream: 4471:09de6f176a91","upstream: 4472:28d3928f6e6e","upstream: 4474:aa99f8e782dc","upstream: 4475:8a19e015d6b2","upstream: 4476:879674c9320a","upstream: 4493:369a2c879eb6"]},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.2-1ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.8-5.1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.7.1-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.8.2-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.8.4-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.7, 1.9.2-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-911-1"],"notices":[{"id":"USN-911-1","title":"MoinMoin vulnerabilities","summary":"MoinMoin vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-11T23:35:10.915972","description":"It was discovered that several wiki actions and preference settings in\nMoinMoin were not protected from cross-site request forgery (CSRF). If an\nauthenticated user were tricked into visiting a malicious website while\nlogged into MoinMoin, a remote attacker could change the user's\nconfiguration or wiki content. (CVE-2010-0668, CVE-2010-0717)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\nprocessing user preferences. An attacker could enter malicious content\nwhich when viewed by a user, could render in unexpected ways.\n(CVE-2010-0669)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"moin","version":"1.5.8-5.1ubuntu2.3","description":"","is_source":true},{"name":"python-moinmoin","version":"1.5.8-5.1ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.8-5.1ubuntu2.3"}],"dapper":[{"name":"moin","version":"1.5.2-1ubuntu2.5","description":"","is_source":true},{"name":"python2.4-moinmoin","version":"1.5.2-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.2-1ubuntu2.5"}],"intrepid":[{"name":"moin","version":"1.7.1-1ubuntu1.3","description":"","is_source":true},{"name":"python-moinmoin","version":"1.7.1-1ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.7.1-1ubuntu1.3"}],"jaunty":[{"name":"moin","version":"1.8.2-2ubuntu2.2","description":"","is_source":true},{"name":"python-moinmoin","version":"1.8.2-2ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.8.2-2ubuntu2.2"}],"karmic":[{"name":"moin","version":"1.8.4-1ubuntu1.1","description":"","is_source":true},{"name":"python-moinmoin","version":"1.8.4-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.8.4-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-0668","CVE-2010-0669","CVE-2010-0717"]}]}],"offset":73140,"limit":20,"total_results":79316}