{"cves":[{"id":"CVE-2009-4488","published":"2010-01-13T20:30:00","updated_at":"2025-08-04T19:23:40.469914+00:00","description":"\nVarnish 2.0.6 writes data to a log file without sanitizing non-printable\ncharacters, which might allow remote attackers to modify a window's title,\nor possibly execute arbitrary commands or overwrite files, via an HTTP\nrequest containing an escape sequence for a terminal emulator. NOTE: the\nvendor disputes the significance of this report, stating that \"This is not\na security problem in Varnish or any other piece of software which writes a\nlogfile. The real problem is the mistaken belief that you can cat(1) a\nrandom logfile to your terminal safely.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"if this is a problem, it is with the terminal"},{"author":"mdeslaur","note":"CVE is disputed, marking as ignored"}],"codename":null,"priority":"negligible","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4488"],"bugs":[""],"patches":{"varnish":[]},"tags":{},"packages":[{"name":"varnish","source":"https://ubuntu.com/security/cve?package=varnish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=varnish","debian":"https://tracker.debian.org/pkg/varnish","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4487","published":"2010-01-13T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnginx 0.7.64 writes data to a log file without sanitizing non-printable\ncharacters, which might allow remote attackers to modify a window's title,\nor possibly execute arbitrary commands or overwrite files, via an HTTP\nrequest containing an escape sequence for a terminal emulator.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"ignored upstream, so ignored by us too."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4487"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/nginx/+bug/511681"],"patches":{"nginx":[]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3637","published":"2010-01-13T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the M_AddToServerList function in\nclient/menu.c in Red Planet Arena Alien Arena 7.30 allows remote attackers\nto execute arbitrary code via a packet with a crafted server description to\nUDP port 27901 followed by a packet with a long print command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3637"],"bugs":[""],"patches":{"alien-arena":[]},"tags":{},"packages":[{"name":"alien-arena","source":"https://ubuntu.com/security/cve?package=alien-arena","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=alien-arena","debian":"https://tracker.debian.org/pkg/alien-arena","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"7.33-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.33","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [7.33-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4492","published":"2010-01-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through\npatchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes\ndata to a log file without sanitizing non-printable characters, which might\nallow remote attackers to modify a window's title, or possibly execute\narbitrary commands or overwrite files, via an HTTP request containing an\nescape sequence for a terminal emulator.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"if there is a problem, it is the terminal that has the issue"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-900-1","https://www.cve.org/CVERecord?id=CVE-2009-4492"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/ruby1.9.1/+bug/509392","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=564647 (1.9)","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=564598 (1.8)","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=564646 (1.9.1)"],"patches":{"ruby1.8":["upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=26267","upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=26281"],"ruby1.9":["upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=26267","upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=26281"],"ruby1.9.1":[]},"tags":{},"packages":[{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.8.7.249-2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.7.249-1","component":null,"pocket":"security"}]},{"name":"ruby1.9","source":"https://ubuntu.com/security/cve?package=ruby1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9","debian":"https://tracker.debian.org/pkg/ruby1.9","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.2-7ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.2-9ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.0.5-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.0.5-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.9.1","source":"https://ubuntu.com/security/cve?package=ruby1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9.1","debian":"https://tracker.debian.org/pkg/ruby1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.9.1.378-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.1.378-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-900-1"],"notices":[{"id":"USN-900-1","title":"Ruby vulnerabilities","summary":"Ruby vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-02-16T14:18:53.283530","description":"Emmanouel Kellinis discovered that Ruby did not properly handle certain\nstring operations. An attacker could exploit this issue and possibly\nexecute arbitrary code with application privileges. (CVE-2009-4124)\n\nGiovanni Pellerano, Alessandro Tanasi, and Francesco Ongaro discovered that\nRuby did not properly sanitize data written to log files. An attacker could\ninsert specially-crafted data into log files which could affect certain\nterminal emulators and cause arbitrary files to be overwritten, or even\npossibly execute arbitrary commands. (CVE-2009-4492)\n\nIt was discovered that Ruby did not properly handle string arguments that\nrepresent large numbers. An attacker could exploit this and cause a denial\nof service. This issue only affected Ubuntu 9.10. (CVE-2009-1904)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"ruby1.9","version":"1.9.0.2-7ubuntu1.3","description":"","is_source":true},{"name":"ruby1.9","version":"1.9.0.2-7ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.2-7ubuntu1.3"},{"name":"libruby1.9","version":"1.9.0.2-7ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.2-7ubuntu1.3"}],"jaunty":[{"name":"ruby1.9","version":"1.9.0.2-9ubuntu1.2","description":"","is_source":true},{"name":"ruby1.9","version":"1.9.0.2-9ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.2-9ubuntu1.2"},{"name":"libruby1.9","version":"1.9.0.2-9ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.2-9ubuntu1.2"}],"karmic":[{"name":"ruby1.9","version":"1.9.0.5-1ubuntu1.2","description":"","is_source":true},{"name":"ruby1.9","version":"1.9.0.5-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.5-1ubuntu1.2"},{"name":"libruby1.9","version":"1.9.0.5-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.5-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2009-1904","CVE-2009-4124","CVE-2009-4492"]}]},{"id":"CVE-2009-4355","published":"2010-01-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMemory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in\nOpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote\nattackers to cause a denial of service (memory consumption) via vectors\nthat trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as\ndemonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related\nissue to CVE-2008-1678.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-884-1","https://www.cve.org/CVERecord?id=CVE-2009-4355"],"bugs":[""],"patches":{"openssl":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"dapper","status":"released","description":"0.9.8a-7ubuntu0.11","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.9.8g-4ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.9.8g-10.1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.9.8g-15ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.9.8g-16ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-884-1"],"notices":[{"id":"USN-884-1","title":"OpenSSL vulnerability","summary":"OpenSSL vulnerability","instructions":"After a standard system upgrade you need to restart any applications\nusing OpenSSL, especially Apache, to effect the necessary changes.\n","references":[],"published":"2010-01-14T00:23:13.340753","description":"It was discovered that OpenSSL did not correctly free unused memory in\ncertain situations. A remote attacker could trigger this flaw in services\nthat used SSL, causing the service to use all available system memory,\nleading to a denial of service.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"openssl","version":"0.9.8g-4ubuntu3.9","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-4ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-4ubuntu3.9"}],"dapper":[{"name":"openssl","version":"0.9.8a-7ubuntu0.11","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8a-7ubuntu0.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8a-7ubuntu0.11"}],"intrepid":[{"name":"openssl","version":"0.9.8g-10.1ubuntu2.6","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-10.1ubuntu2.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-10.1ubuntu2.6"}],"jaunty":[{"name":"openssl","version":"0.9.8g-15ubuntu3.4","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-15ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-15ubuntu3.4"}],"karmic":[{"name":"openssl","version":"0.9.8g-16ubuntu3.1","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-16ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-16ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2009-4355"]}]},{"id":"CVE-2009-4538","published":"2010-01-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ndrivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel\n2.6.32.3 and earlier does not properly check the size of an Ethernet frame\nthat exceeds the MTU, which allows remote attackers to have an unspecified\nimpact via crafted packets, a related issue to CVE-2009-4537.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same patch as CVE-2009-4536, but applied to e1000e"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-894-1","https://www.cve.org/CVERecord?id=CVE-2009-4538"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-4538"],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-27.65","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-17.45","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-18.59","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-19.56","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-894-1"],"notices":[{"id":"USN-894-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2010-02-05T00:37:17.812607","description":"Amerigo Wang and Eric Sesterhenn discovered that the HFS and ext4\nfilesystems did not correctly check certain disk structures. If a user\nwere tricked into mounting a specially crafted filesystem, a remote\nattacker could crash the system or gain root privileges. (CVE-2009-4020,\nCVE-2009-4308)\n\nIt was discovered that FUSE did not correctly check certain requests.\nA local attacker with access to FUSE mounts could exploit this to\ncrash the system or possibly gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-4021)\n\nIt was discovered that KVM did not correctly decode certain guest\ninstructions. A local attacker in a guest could exploit this to\ntrigger high scheduling latency in the host, leading to a denial of\nservice. Ubuntu 6.06 was not affected. (CVE-2009-4031)\n\nIt was discovered that the OHCI fireware driver did not correctly\nhandle certain ioctls. A local attacker could exploit this to crash\nthe system, or possibly gain root privileges. Ubuntu 6.06 was not\naffected. (CVE-2009-4138)\n\nTavis Ormandy discovered that the kernel did not correctly handle\nO_ASYNC on locked files. A local attacker could exploit this to gain\nroot privileges. Only Ubuntu 9.04 and 9.10 were affected. (CVE-2009-4141)\n\nNeil Horman and Eugene Teo discovered that the e1000 and e1000e\nnetwork drivers did not correctly check the size of Ethernet frames.\nAn attacker on the local network could send specially crafted traffic\nto bypass packet filters, crash the system, or possibly gain root\nprivileges. (CVE-2009-4536, CVE-2009-4538)\n\nIt was discovered that \"print-fatal-signals\" reporting could show\narbitrary kernel memory contents. A local attacker could exploit\nthis, leading to a loss of privacy. By default this is disabled in\nUbuntu and did not affect Ubuntu 6.06. (CVE-2010-0003)\n\nOlli Jarva and Tuomo Untinen discovered that IPv6 did not correctly\nhandle jumbo frames. A remote attacker could exploit this to crash the\nsystem, leading to a denial of service. Only Ubuntu 9.04 and 9.10 were\naffected. (CVE-2010-0006)\n\nFlorian Westphal discovered that bridging netfilter rules could be\nmodified by unprivileged users. A local attacker could disrupt network\ntraffic, leading to a denial of service. (CVE-2010-0007)\n\nAl Viro discovered that certain mremap operations could leak kernel\nmemory. A local attacker could exploit this to consume all available\nmemory, leading to a denial of service. (CVE-2010-0291)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-27.65","description":"","is_source":true},{"name":"linux-image-2.6.24-27-itanium","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpia","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa32","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpiacompat","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-386","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-mckinley","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-xen","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-generic","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-virtual","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-server","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-rt","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-openvz","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.82","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"}],"intrepid":[{"name":"linux","version":"2.6.27-17.45","description":"","is_source":true},{"name":"linux-image-2.6.27-17-generic","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-virtual","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-server","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"}],"jaunty":[{"name":"linux","version":"2.6.28-18.59","description":"","is_source":true},{"name":"linux-image-2.6.28-18-generic","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-server","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-iop32x","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-ixp4xx","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-lpia","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-virtual","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-imx51","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-versatile","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"}],"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-211.22","description":"","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-108.21","description":"","is_source":true},{"name":"linux-ec2","version":"2.6.31-304.10","description":"","is_source":true},{"name":"linux","version":"2.6.31-19.56","description":"","is_source":true},{"name":"linux-image-2.6.31-304-ec2","version":"2.6.31-304.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-304.10"},{"name":"linux-image-2.6.31-19-386","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-108-imx51","version":"2.6.31-108.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-108.21"},{"name":"linux-image-2.6.31-19-powerpc-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove-z0","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-virtual","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-server","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-generic-pae","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-generic","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-lpia","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-ia64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"}]},"type":"USN","cves_ids":["CVE-2009-4031","CVE-2009-4308","CVE-2009-4536","CVE-2009-4538","CVE-2009-4021","CVE-2010-0007","CVE-2010-0291","CVE-2009-4020","CVE-2009-4138","CVE-2010-0006","CVE-2010-0003","CVE-2009-4141"]}]},{"id":"CVE-2009-4537","published":"2010-01-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ndrivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and\nearlier does not properly check the size of an Ethernet frame that exceeds\nthe MTU, which allows remote attackers to (1) cause a denial of service\n(temporary network outage) via a packet with a crafted size, in conjunction\nwith certain packets containing A characters and certain packets containing\nE characters; or (2) cause a denial of service (system crash) via a packet\nwith a crafted size, in conjunction with certain packets containing '\\0'\ncharacters, related to the value of the status register and erroneous\nbehavior associated with the RxMaxSize register. NOTE: this vulnerability\nexists because of an incorrect fix for CVE-2009-1389.","ubuntu_description":"","notes":[{"author":"kees","note":"http://marc.info/?l=linux-netdev&m=126202972828626&w=2\nhttp://marc.info/?l=linux-netdev&m=126269986618934&w=2"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?t=126202986900002&r=1&w=2","https://ubuntu.com/security/notices/USN-947-1","https://www.cve.org/CVERecord?id=CVE-2009-4537"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-4537"],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=c0cd884af045338476b8e69a61fceb3f34ff22f1","upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=8812304cf1110ae16b0778680f6022216cf4716a"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.70","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.61","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.60","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-22.35","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc3","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.84","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc3","component":null,"pocket":"security"}]}],"notices_ids":["USN-947-1"],"notices":[{"id":"USN-947-1","title":"Linux kernel vulnerabilities","summary":"Multiple flaws in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2010-06-03T06:23:23.617205","description":"It was discovered that the Linux kernel did not correctly handle memory\nprotection of the Virtual Dynamic Shared Object page when running\na 32-bit application on a 64-bit kernel. A local attacker could\nexploit this to cause a denial of service. (Only affected Ubuntu 6.06\nLTS.) (CVE-2009-4271)\n\nIt was discovered that the r8169 network driver did not correctly check\nthe size of Ethernet frames. A remote attacker could send specially\ncrafted traffic to crash the system, leading to a denial of service.\n(CVE-2009-4537)\n\nWei Yongjun discovered that SCTP did not correctly validate certain\nchunks. A remote attacker could send specially crafted traffic to\nmonopolize CPU resources, leading to a denial of service. (Only affected\nUbuntu 6.06 LTS.) (CVE-2010-0008)\n\nIt was discovered that KVM did not correctly limit certain privileged\nIO accesses on x86. Processes in the guest OS with access to IO regions\ncould gain further privileges within the guest OS. (Did not affect Ubuntu\n6.06 LTS.) (CVE-2010-0298, CVE-2010-0306, CVE-2010-0419)\n\nEvgeniy Polyakov discovered that IPv6 did not correctly handle\ncertain TUN packets. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (Only affected Ubuntu 8.04\nLTS.) (CVE-2010-0437)\n\nSachin Prabhu discovered that GFS2 did not correctly handle certain locks.\nA local attacker with write access to a GFS2 filesystem could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-0727)\n\nJamie Strandboge discovered that network virtio in KVM did not correctly\nhandle certain high-traffic conditions. A remote attacker could exploit\nthis by sending specially crafted traffic to a guest OS, causing the\nguest to crash, leading to a denial of service. (Only affected Ubuntu\n8.04 LTS.) (CVE-2010-0741)\n\nMarcus Meissner discovered that the USB subsystem did not correctly handle\ncertain error conditions. A local attacker with access to a USB device\ncould exploit this to read recently used kernel memory, leading to a\nloss of privacy and potentially root privilege escalation. (CVE-2010-1083)\n\nNeil Brown discovered that the Bluetooth subsystem did not correctly\nhandle large amounts of traffic. A physically proximate remote attacker\ncould exploit this by sending specially crafted traffic that would consume\nall available system memory, leading to a denial of service. (Ubuntu\n6.06 LTS and 10.04 LTS were not affected.) (CVE-2010-1084)\n\nJody Bruchon discovered that the sound driver for the AMD780V did not\ncorrectly handle certain conditions. A local attacker with access to\nthis hardward could exploit the flaw to cause a system crash, leading\nto a denial of service. (CVE-2010-1085)\n\nAng Way Chuang discovered that the DVB driver did not correctly handle\ncertain MPEG2-TS frames. An attacker could exploit this by delivering\nspecially crafted frames to monopolize CPU resources, leading to a denial\nof service. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1086)\n\nTrond Myklebust discovered that NFS did not correctly handle truncation\nunder certain conditions. A local attacker with write access to an NFS\nshare could exploit this to crash the system, leading to a denial of\nservice. (Ubuntu 10.04 LTS was not affected.) (CVE-2010-1087)\n\nAl Viro discovered that automount of NFS did not correctly handle symlinks\nunder certain conditions. A local attacker could exploit this to crash\nthe system, leading to a denial of service. (Ubuntu 6.06 LTS and Ubuntu\n10.04 LTS were not affected.) (CVE-2010-1088)\n\nMatt McCutchen discovered that ReiserFS did not correctly protect xattr\nfiles in the .reiserfs_priv directory. A local attacker could exploit\nthis to gain root privileges or crash the system, leading to a denial\nof service. (CVE-2010-1146)\n\nEugene Teo discovered that CIFS did not correctly validate arguments when\ncreating new files. A local attacker could exploit this to crash the\nsystem, leading to a denial of service, or possibly gain root privileges\nif mmap_min_addr was not set. (CVE-2010-1148)\n\nCatalin Marinas and Tetsuo Handa discovered that the TTY layer did not\ncorrectly release process IDs. A local attacker could exploit this to\nconsume kernel resources, leading to a denial of service. (CVE-2010-1162)\n\nNeil Horman discovered that TIPC did not correctly check its internal\nstate. A local attacker could send specially crafted packets via AF_TIPC\nthat would cause the system to crash, leading to a denial of service.\n(Ubuntu 6.06 LTS was not affected.) (CVE-2010-1187)\n\nMasayuki Nakagawa discovered that IPv6 did not correctly handle\ncertain settings when listening. If a socket were listening with the\nIPV6_RECVPKTINFO flag, a remote attacker could send specially crafted\ntraffic that would cause the system to crash, leading to a denial of\nservice. (Only Ubuntu 6.06 LTS was affected.) (CVE-2010-1188)\n\nOleg Nesterov discovered that the Out-Of-Memory handler did not correctly\nhandle certain arrangements of processes. A local attacker could exploit\nthis to crash the system, leading to a denial of service. (CVE-2010-1488)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-214.28","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-112.28","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-ec2","version":"2.6.31-307.15","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.60","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.15"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.28"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.60"},{"name":"linux-image-2.6.31-214-dove-z0","version":"2.6.31-214.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-214.28"}],"hardy":[{"name":"linux","version":"2.6.24-28.70","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.70","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.70"}],"lucid":[{"name":"linux-ec2","version":"2.6.32-306.11","description":"Linux kernel for EC2","is_source":true},{"name":"linux-qcm-msm","version":"2.6.31-802.4","description":"Linux kernel for qcm-msm ARM","is_source":true},{"name":"linux-ti-omap","version":"2.6.33-501.7","description":"Linux kernel for ti-omap ARM","is_source":true},{"name":"linux-mvl-dove","version":"2.6.32-205.18","description":"Linux kernel for mvl-dove ARM","is_source":true},{"name":"linux","version":"2.6.32-22.35","description":"Linux kernel","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-608.14","description":"Linux kernel for fsl-imx51 ARM","is_source":true},{"name":"linux-image-2.6.32-22-powerpc","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-802-st1-5","version":"2.6.31-802.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm","version_link":"https://launchpad.net/ubuntu/+source/linux-qcm-msm/2.6.31-802.4"},{"name":"linux-image-2.6.32-22-powerpc-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-virtual","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.14"},{"name":"linux-image-2.6.32-22-powerpc64-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.33-501-omap","version":"2.6.33-501.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap/2.6.33-501.7"},{"name":"linux-image-2.6.32-22-generic-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-205-dove","version":"2.6.32-205.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-205.18"},{"name":"linux-image-2.6.32-22-ia64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-versatile-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-306-ec2","version":"2.6.32-306.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-306.11"},{"name":"linux-image-2.6.32-22-preempt","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc-smp","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-lpia","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-386-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-preempt-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-ia64","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-generic-pae-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-powerpc64-smp-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-sparc64-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"},{"name":"linux-image-2.6.32-22-server-dbgsym","version":"2.6.32-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-22.35"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.84","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.84","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.84"}],"jaunty":[{"name":"linux","version":"2.6.28-19.61","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.61"}]},"type":"USN","cves_ids":["CVE-2009-4271","CVE-2009-4537","CVE-2010-0008","CVE-2010-0298","CVE-2010-0306","CVE-2010-0419","CVE-2010-0437","CVE-2010-0727","CVE-2010-0741","CVE-2010-1083","CVE-2010-1084","CVE-2010-1085","CVE-2010-1086","CVE-2010-1087","CVE-2010-1088","CVE-2010-1146","CVE-2010-1148","CVE-2010-1162","CVE-2010-1187","CVE-2010-1188","CVE-2010-1488"]}]},{"id":"CVE-2009-4536","published":"2010-01-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ndrivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel\n2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by\nprocessing certain trailing payload data as if it were a complete frame,\nwhich allows remote attackers to bypass packet filters via a large packet\nwith a crafted payload. NOTE: this vulnerability exists because of an\nincorrect fix for CVE-2009-1385.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blog.c22.cc/2009/12/27/26c3-cat-procsysnetipv4fuckups/","http://marc.info/?t=126203102000001&r=1&w=2","https://ubuntu.com/security/notices/USN-894-1","https://www.cve.org/CVERecord?id=CVE-2009-4536"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-4536"],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-27.65","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-17.45","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-18.59","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-19.56","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.82","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-894-1"],"notices":[{"id":"USN-894-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2010-02-05T00:37:17.812607","description":"Amerigo Wang and Eric Sesterhenn discovered that the HFS and ext4\nfilesystems did not correctly check certain disk structures. If a user\nwere tricked into mounting a specially crafted filesystem, a remote\nattacker could crash the system or gain root privileges. (CVE-2009-4020,\nCVE-2009-4308)\n\nIt was discovered that FUSE did not correctly check certain requests.\nA local attacker with access to FUSE mounts could exploit this to\ncrash the system or possibly gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-4021)\n\nIt was discovered that KVM did not correctly decode certain guest\ninstructions. A local attacker in a guest could exploit this to\ntrigger high scheduling latency in the host, leading to a denial of\nservice. Ubuntu 6.06 was not affected. (CVE-2009-4031)\n\nIt was discovered that the OHCI fireware driver did not correctly\nhandle certain ioctls. A local attacker could exploit this to crash\nthe system, or possibly gain root privileges. Ubuntu 6.06 was not\naffected. (CVE-2009-4138)\n\nTavis Ormandy discovered that the kernel did not correctly handle\nO_ASYNC on locked files. A local attacker could exploit this to gain\nroot privileges. Only Ubuntu 9.04 and 9.10 were affected. (CVE-2009-4141)\n\nNeil Horman and Eugene Teo discovered that the e1000 and e1000e\nnetwork drivers did not correctly check the size of Ethernet frames.\nAn attacker on the local network could send specially crafted traffic\nto bypass packet filters, crash the system, or possibly gain root\nprivileges. (CVE-2009-4536, CVE-2009-4538)\n\nIt was discovered that \"print-fatal-signals\" reporting could show\narbitrary kernel memory contents. A local attacker could exploit\nthis, leading to a loss of privacy. By default this is disabled in\nUbuntu and did not affect Ubuntu 6.06. (CVE-2010-0003)\n\nOlli Jarva and Tuomo Untinen discovered that IPv6 did not correctly\nhandle jumbo frames. A remote attacker could exploit this to crash the\nsystem, leading to a denial of service. Only Ubuntu 9.04 and 9.10 were\naffected. (CVE-2010-0006)\n\nFlorian Westphal discovered that bridging netfilter rules could be\nmodified by unprivileged users. A local attacker could disrupt network\ntraffic, leading to a denial of service. (CVE-2010-0007)\n\nAl Viro discovered that certain mremap operations could leak kernel\nmemory. A local attacker could exploit this to consume all available\nmemory, leading to a denial of service. (CVE-2010-0291)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-27.65","description":"","is_source":true},{"name":"linux-image-2.6.24-27-itanium","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpia","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa32","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpiacompat","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-386","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-mckinley","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-xen","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-generic","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-virtual","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-server","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-rt","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-openvz","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.82","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"}],"intrepid":[{"name":"linux","version":"2.6.27-17.45","description":"","is_source":true},{"name":"linux-image-2.6.27-17-generic","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-virtual","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-server","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"}],"jaunty":[{"name":"linux","version":"2.6.28-18.59","description":"","is_source":true},{"name":"linux-image-2.6.28-18-generic","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-server","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-iop32x","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-ixp4xx","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-lpia","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-virtual","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-imx51","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-versatile","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"}],"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-211.22","description":"","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-108.21","description":"","is_source":true},{"name":"linux-ec2","version":"2.6.31-304.10","description":"","is_source":true},{"name":"linux","version":"2.6.31-19.56","description":"","is_source":true},{"name":"linux-image-2.6.31-304-ec2","version":"2.6.31-304.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-304.10"},{"name":"linux-image-2.6.31-19-386","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-108-imx51","version":"2.6.31-108.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-108.21"},{"name":"linux-image-2.6.31-19-powerpc-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove-z0","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-virtual","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-server","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-generic-pae","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-generic","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-lpia","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-ia64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"}]},"type":"USN","cves_ids":["CVE-2009-4031","CVE-2009-4308","CVE-2009-4536","CVE-2009-4538","CVE-2009-4021","CVE-2010-0007","CVE-2010-0291","CVE-2009-4020","CVE-2009-4138","CVE-2010-0006","CVE-2010-0003","CVE-2009-4141"]}]},{"id":"CVE-2009-4212","published":"2010-01-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer underflows in the (1) AES and (2) RC4 decryption\nfunctionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3\nthrough 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a\ndenial of service (daemon crash) or possibly execute arbitrary code by\nproviding ciphertext with a length that is too short to be valid.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-881-1","https://www.cve.org/CVERecord?id=CVE-2009-4212"],"bugs":[""],"patches":{"krb5":[]},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.6.dfsg.3~beta1-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.6.dfsg.4~beta1-3ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.6.dfsg.4~beta1-5ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.7dfsg~beta3-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-881-1"],"notices":[{"id":"USN-881-1","title":"Kerberos vulnerability","summary":"Kerberos vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-01-12T20:04:07.340372","description":"It was discovered that Kerberos did not correctly handle invalid AES\nblocks. An unauthenticated remote attacker could send specially crafted\ntraffic that would crash the KDC service, leading to a denial of service,\nor possibly execute arbitrary code with root privileges.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"krb5","version":"1.6.dfsg.3~beta1-2ubuntu1.3","description":"","is_source":true},{"name":"libkrb53","version":"1.6.dfsg.3~beta1-2ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.6.dfsg.3~beta1-2ubuntu1.3"}],"dapper":[{"name":"krb5","version":"1.4.3-5ubuntu0.10","description":"","is_source":true},{"name":"libkrb53","version":"1.4.3-5ubuntu0.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.4.3-5ubuntu0.10"}],"intrepid":[{"name":"krb5","version":"1.6.dfsg.4~beta1-3ubuntu0.3","description":"","is_source":true},{"name":"libkrb53","version":"1.6.dfsg.4~beta1-3ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.6.dfsg.4~beta1-3ubuntu0.3"}],"jaunty":[{"name":"krb5","version":"1.6.dfsg.4~beta1-5ubuntu2.2","description":"","is_source":true},{"name":"libkrb53","version":"1.6.dfsg.4~beta1-5ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.6.dfsg.4~beta1-5ubuntu2.2"}],"karmic":[{"name":"krb5","version":"1.7dfsg~beta3-1ubuntu0.3","description":"","is_source":true},{"name":"libk5crypto3","version":"1.7dfsg~beta3-1ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.7dfsg~beta3-1ubuntu0.3"}]},"type":"USN","cves_ids":["CVE-2009-4212"]}]},{"id":"CVE-2010-0277","published":"2010-01-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nslp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6,\nincluding 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial\nof service (memory corruption and application crash) or possibly have\nunspecified other impact via a malformed MSNSLP INVITE request in an SLP\nmessage, a different issue than CVE-2010-0013.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2010/01/07/2","http://pidgin.im/news/security/?id=43","https://ubuntu.com/security/notices/USN-902-1","https://www.cve.org/CVERecord?id=CVE-2010-0277"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=566775"],"patches":{"pidgin":["upstream: http://developer.pidgin.im/viewmtn/revision/info/784bc8bff5affb83cee8a5a9353cb0a8220a72ce"]},"tags":{},"packages":[{"name":"pidgin","source":"https://ubuntu.com/security/cve?package=pidgin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pidgin","debian":"https://tracker.debian.org/pkg/pidgin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:2.4.1-1ubuntu2.9","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:2.5.2-0ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1:2.5.5-1ubuntu8.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:2.6.2-1ubuntu7.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-902-1"],"notices":[{"id":"USN-902-1","title":"Pidgin vulnerabilities","summary":"Pidgin vulnerabilities","instructions":"After a standard system upgrade you need to restart Pidgin to effect\nthe necessary changes.\n","references":[],"published":"2010-02-22T15:36:46.719175","description":"Fabian Yamaguchi discovered that Pidgin incorrectly validated all fields of\nan incoming message in the MSN protocol handler. A remote attacker could\nsend a specially crafted message and cause Pidgin to crash, leading to a\ndenial of service. (CVE-2010-0277)\n\nSadrul Habib Chowdhury discovered that Pidgin incorrectly handled certain\nnicknames in Finch group chat rooms. A remote attacker could use a\nspecially crafted nickname and cause Pidgin to crash, leading to a denial\nof service. (CVE-2010-0420)\n\nAntti Hayrynen discovered that Pidgin incorrectly handled large numbers of\nsmileys. A remote attacker could send a specially crafted message and cause\nPidgin to become unresponsive, leading to a denial of service.\n(CVE-2010-0423)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"pidgin","version":"1:2.4.1-1ubuntu2.9","description":"","is_source":true},{"name":"pidgin","version":"1:2.4.1-1ubuntu2.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.4.1-1ubuntu2.9"}],"intrepid":[{"name":"pidgin","version":"1:2.5.2-0ubuntu1.7","description":"","is_source":true},{"name":"pidgin","version":"1:2.5.2-0ubuntu1.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.5.2-0ubuntu1.7"}],"jaunty":[{"name":"pidgin","version":"1:2.5.5-1ubuntu8.6","description":"","is_source":true},{"name":"pidgin","version":"1:2.5.5-1ubuntu8.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.5.5-1ubuntu8.6"}],"karmic":[{"name":"pidgin","version":"1:2.6.2-1ubuntu7.2","description":"","is_source":true},{"name":"pidgin","version":"1:2.6.2-1ubuntu7.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.6.2-1ubuntu7.2"}]},"type":"USN","cves_ids":["CVE-2010-0423","CVE-2010-0277","CVE-2010-0420"]}]},{"id":"CVE-2010-0013","published":"2010-01-09T00:00:00","updated_at":"2025-08-25T19:53:10.460082+00:00","description":"\nDirectory traversal vulnerability in slp.c in the MSN protocol plugin in\nlibpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read\narbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN\nemoticon (aka custom smiley) request, a related issue to CVE-2004-0122.\nNOTE: it could be argued that this is resultant from a vulnerability in\nwhich an emoticon download request is processed even without a preceding\ntext/x-mms-emoticon message that announced availability of the emoticon.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"pidgin in hardy doesn't support MSN_OBJECT_EMOTICON"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html","http://pidgin.im/news/security/?id=42","https://ubuntu.com/security/notices/USN-886-1","https://www.cve.org/CVERecord?id=CVE-2010-0013"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=563206","https://bugs.launchpad.net/bugs/501089"],"patches":{"pidgin":["upstream: http://developer.pidgin.im/viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92f","upstream: http://developer.pidgin.im/viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467","upstream: http://developer.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810"]},"tags":{},"packages":[{"name":"pidgin","source":"https://ubuntu.com/security/cve?package=pidgin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pidgin","debian":"https://tracker.debian.org/pkg/pidgin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:2.5.2-0ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1:2.5.5-1ubuntu8.5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:2.6.2-1ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-886-1"],"notices":[{"id":"USN-886-1","title":"Pidgin vulnerabilities","summary":"Pidgin vulnerabilities","instructions":"After a standard system upgrade you need to restart Pidgin to effect\nthe necessary changes.\n","references":[],"published":"2010-01-18T15:37:32.660741","description":"It was discovered that Pidgin did not properly handle certain topic\nmessages in the IRC protocol handler. If a user were tricked into\nconnecting to a malicious IRC server, an attacker could cause Pidgin to\ncrash, leading to a denial of service. This issue only affected Ubuntu 8.04\nLTS, Ubuntu 8.10 and Ubuntu 9.04. (CVE-2009-2703)\n\nIt was discovered that Pidgin did not properly enforce the \"require\nTLS/SSL\" setting when connecting to certain older Jabber servers. If a\nremote attacker were able to perform a machine-in-the-middle attack, this flaw\ncould be exploited to view sensitive information. This issue only affected\nUbuntu 8.04 LTS, Ubuntu 8.10 and Ubuntu 9.04. (CVE-2009-3026)\n\nIt was discovered that Pidgin did not properly handle certain SLP invite\nmessages in the MSN protocol handler. A remote attacker could send a\nspecially crafted invite message and cause Pidgin to crash, leading to a\ndenial of service. This issue only affected Ubuntu 8.04 LTS, Ubuntu 8.10\nand Ubuntu 9.04. (CVE-2009-3083)\n\nIt was discovered that Pidgin did not properly handle certain errors in the\nXMPP protocol handler. A remote attacker could send a specially crafted\nmessage and cause Pidgin to crash, leading to a denial of service. This\nissue only affected Ubuntu 8.10 and Ubuntu 9.04. (CVE-2009-3085)\n\nIt was discovered that Pidgin did not properly handle malformed\ncontact-list data in the OSCAR protocol handler. A remote attacker could\nsend specially crafted contact-list data and cause Pidgin to crash, leading\nto a denial of service. (CVE-2009-3615)\n\nIt was discovered that Pidgin did not properly handle custom smiley\nrequests in the MSN protocol handler. A remote attacker could send a\nspecially crafted filename in a custom smiley request and obtain arbitrary\nfiles via directory traversal. This issue only affected Ubuntu 8.10, Ubuntu\n9.04 and Ubuntu 9.10. (CVE-2010-0013)\n\nPidgin for Ubuntu 8.04 LTS was also updated to fix connection issues with\nthe MSN protocol.\n\nUSN-675-1 and USN-781-1 provided updated Pidgin packages to fix multiple\nsecurity vulnerabilities in Ubuntu 8.04 LTS. The security patches to fix\nCVE-2008-2955 and CVE-2009-1376 were incomplete. This update corrects the\nproblem. Original advisory details:\n\n It was discovered that Pidgin did not properly handle file transfers\n containing a long filename and special characters in the MSN protocol\n handler. A remote attacker could send a specially crafted filename in a\n file transfer request and cause Pidgin to crash, leading to a denial of\n service. (CVE-2008-2955)\n\n It was discovered that Pidgin did not properly handle certain malformed\n messages in the MSN protocol handler. A remote attacker could send a\n specially crafted message and possibly execute arbitrary code with user\n privileges. (CVE-2009-1376)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"pidgin","version":"1:2.4.1-1ubuntu2.8","description":"","is_source":true},{"name":"pidgin","version":"1:2.4.1-1ubuntu2.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.4.1-1ubuntu2.8"}],"intrepid":[{"name":"pidgin","version":"1:2.5.2-0ubuntu1.6","description":"","is_source":true},{"name":"pidgin","version":"1:2.5.2-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.5.2-0ubuntu1.6"}],"jaunty":[{"name":"pidgin","version":"1:2.5.5-1ubuntu8.5","description":"","is_source":true},{"name":"pidgin","version":"1:2.5.5-1ubuntu8.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.5.5-1ubuntu8.5"}],"karmic":[{"name":"pidgin","version":"1:2.6.2-1ubuntu7.1","description":"","is_source":true},{"name":"pidgin","version":"1:2.6.2-1ubuntu7.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.6.2-1ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2008-2955","CVE-2009-1376","CVE-2009-2703","CVE-2009-3026","CVE-2009-3083","CVE-2009-3085","CVE-2009-3615","CVE-2010-0013"]}]},{"id":"CVE-2009-4010","published":"2010-01-08T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote\nattackers to spoof DNS data via crafted zones.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://doc.powerdns.com/powerdns-advisory-2010-01.html","https://www.cve.org/CVERecord?id=CVE-2009-4010"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/pdns-recursor/+bug/502987"],"patches":{"pdns-recursor":[]},"tags":{},"packages":[{"name":"pdns-recursor","source":"https://ubuntu.com/security/cve?package=pdns-recursor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdns-recursor","debian":"https://tracker.debian.org/pkg/pdns-recursor","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.1.7-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.1.7-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.1.7-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.1.7.2-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.1.7.2-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.1.7.2-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.1.7.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.7.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4009","published":"2010-01-08T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers\nto cause a denial of service (daemon crash) or possibly execute arbitrary\ncode via crafted packets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://doc.powerdns.com/powerdns-advisory-2010-01.html","https://www.cve.org/CVERecord?id=CVE-2009-4009"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/pdns-recursor/+bug/502987"],"patches":{"pdns-recursor":[]},"tags":{},"packages":[{"name":"pdns-recursor","source":"https://ubuntu.com/security/cve?package=pdns-recursor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdns-recursor","debian":"https://tracker.debian.org/pkg/pdns-recursor","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.1.7-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.1.7-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.1.7-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.1.7.2-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.1.7.2-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.1.7.2-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.1.7.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.7.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0012","published":"2010-01-08T00:00:00","updated_at":"2025-08-25T19:53:10.460082+00:00","description":"\nDirectory traversal vulnerability in libtransmission/metainfo.c in\nTransmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to\noverwrite arbitrary files via a .. (dot dot) in a pathname within a\n.torrent file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://trac.transmissionbt.com/wiki/Changes#version-1.77","https://ubuntu.com/security/notices/USN-885-1","https://www.cve.org/CVERecord?id=CVE-2010-0012"],"bugs":["https://launchpad.net/bugs/500625"],"patches":{"transmission":["upstream: http://trac.transmissionbt.com/changeset/9829/"]},"tags":{},"packages":[{"name":"transmission","source":"https://ubuntu.com/security/cve?package=transmission","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=transmission","debian":"https://tracker.debian.org/pkg/transmission","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.06-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.34-0ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.51-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.75-0ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.77, 1.80beta3","component":null,"pocket":"security"}]}],"notices_ids":["USN-885-1"],"notices":[{"id":"USN-885-1","title":"Transmission vulnerabilities","summary":"Transmission vulnerabilities","instructions":"After a standard system upgrade you need to restart Transmission to effect\nthe necessary changes.\n","references":[],"published":"2010-01-18T17:49:12.594135","description":"It was discovered that the Transmission web interface was vulnerable to\ncross-site request forgery (CSRF) attacks. If a user were tricked into\nopening a specially crafted web page in a browser while Transmission was\nrunning, an attacker could trigger commands in Transmission. This issue\naffected Ubuntu 9.04. (CVE-2009-1757)\n\nDan Rosenberg discovered that Transmission did not properly perform input\nvalidation when processing torrent files. If a user were tricked into\nopening a crafted torrent file, an attacker could overwrite files via\ndirectory traversal. (CVE-2010-0012)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"transmission","version":"1.06-0ubuntu6.1","description":"","is_source":true},{"name":"transmission-gtk","version":"1.06-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/transmission","version_link":"https://launchpad.net/ubuntu/+source/transmission/1.06-0ubuntu6.1"},{"name":"transmission-cli","version":"1.06-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/transmission","version_link":"https://launchpad.net/ubuntu/+source/transmission/1.06-0ubuntu6.1"}],"intrepid":[{"name":"transmission","version":"1.34-0ubuntu2.3","description":"","is_source":true},{"name":"transmission-gtk","version":"1.34-0ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/transmission","version_link":"https://launchpad.net/ubuntu/+source/transmission/1.34-0ubuntu2.3"},{"name":"transmission-cli","version":"1.34-0ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/transmission","version_link":"https://launchpad.net/ubuntu/+source/transmission/1.34-0ubuntu2.3"}],"jaunty":[{"name":"transmission","version":"1.51-0ubuntu3.1","description":"","is_source":true},{"name":"transmission-gtk","version":"1.51-0ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/transmission","version_link":"https://launchpad.net/ubuntu/+source/transmission/1.51-0ubuntu3.1"},{"name":"transmission-cli","version":"1.51-0ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/transmission","version_link":"https://launchpad.net/ubuntu/+source/transmission/1.51-0ubuntu3.1"}],"karmic":[{"name":"transmission","version":"1.75-0ubuntu2.2","description":"","is_source":true},{"name":"transmission-gtk","version":"1.75-0ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/transmission","version_link":"https://launchpad.net/ubuntu/+source/transmission/1.75-0ubuntu2.2"},{"name":"transmission-cli","version":"1.75-0ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/transmission","version_link":"https://launchpad.net/ubuntu/+source/transmission/1.75-0ubuntu2.2"},{"name":"transmission-qt","version":"1.75-0ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/transmission","version_link":"https://launchpad.net/ubuntu/+source/transmission/1.75-0ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2010-0012","CVE-2009-1757"]}]},{"id":"CVE-2010-0220","published":"2010-01-07T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe nsObserverList::FillObserverArray function in\nxpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote\nattackers to cause a denial of service (application crash) via a crafted\nweb site that triggers memory consumption and an accompanying Low Memory\nalert dialog, and also triggers attempted removal of an observer from an\nempty observers array.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per upstream, xulrunner-1.9 not affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0220"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=507114"],"patches":{"firefox":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.9+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.9+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.1.7","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4497","published":"2010-01-07T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and\n0.9.6 allows remote attackers to inject arbitrary web script or HTML via\nthe i parameter to the ident program.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sourceforge.net/mailarchive/message.php?msg_name=E1NS2s4-0001PE-F2%403bkjzd1.ch3.sourceforge.com","https://www.cve.org/CVERecord?id=CVE-2009-4497"],"bugs":[""],"patches":{"lxr-cvs":[]},"tags":{},"packages":[{"name":"lxr-cvs","source":"https://ubuntu.com/security/cve?package=lxr-cvs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxr-cvs","debian":"https://tracker.debian.org/pkg/lxr-cvs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4592","published":"2010-01-07T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in base_local_rules.php in Basic Analysis and\nSecurity Engine (BASE) before 1.4.4 allows remote attackers to include\narbitrary local files via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://base.secureideas.net/news.php","https://www.cve.org/CVERecord?id=CVE-2009-4592"],"bugs":[""],"patches":{"acidbase":[]},"tags":{},"packages":[{"name":"acidbase","source":"https://ubuntu.com/security/cve?package=acidbase","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acidbase","debian":"https://tracker.debian.org/pkg/acidbase","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4591","published":"2010-01-07T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in Basic Analysis and Security Engine (BASE)\nbefore 1.4.4 allows remote attackers to execute arbitrary SQL commands via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://base.secureideas.net/news.php","https://www.cve.org/CVERecord?id=CVE-2009-4591"],"bugs":[""],"patches":{"acidbase":[]},"tags":{},"packages":[{"name":"acidbase","source":"https://ubuntu.com/security/cve?package=acidbase","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acidbase","debian":"https://tracker.debian.org/pkg/acidbase","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4590","published":"2010-01-07T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in base_local_rules.php in Basic\nAnalysis and Security Engine (BASE) before 1.4.4 allows remote attackers to\ninject arbitrary web script or HTML via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://base.secureideas.net/news.php","https://www.cve.org/CVERecord?id=CVE-2009-4590"],"bugs":[""],"patches":{"acidbase":[]},"tags":{},"packages":[{"name":"acidbase","source":"https://ubuntu.com/security/cve?package=acidbase","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acidbase","debian":"https://tracker.debian.org/pkg/acidbase","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.4.4-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4589","published":"2010-01-07T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the Special:Block\nimplementation in the getContribsLink function in SpecialBlockip.php in\nMediaWiki 1.14.0 and 1.15.0 allows remote attackers to inject arbitrary web\nscript or HTML via the ip parameter.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Only versions 1.14.0, 1.15.0 and release candidates are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.wikimedia.org/pipermail/mediawiki-announce/2009-July/000087.html","https://www.cve.org/CVERecord?id=CVE-2009-4589"],"bugs":["https://bugzilla.wikimedia.org/show_bug.cgi?id=19693"],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1:1.11.2-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1:1.12.0-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1:1.13.3-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1:1.15.0-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.14.1, 1.15.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":73320,"limit":20,"total_results":79316}