{"cves":[{"id":"CVE-2009-4130","published":"2009-12-14T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nVisual truncation vulnerability in the MakeScriptDialogTitle function in\nnsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the\norigin domain name of a script via a long name.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4130"],"bugs":[""],"patches":{"xulrunner-1.9.1":[]},"tags":{},"packages":[{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4129","published":"2009-12-14T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in Mozilla Firefox allows remote attackers to produce a\nJavaScript message with a spoofed domain association by writing the message\nin between the document request and document load for a web page in a\ndifferent domain.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4129"],"bugs":[""],"patches":{"xulrunner-1.9.1":[]},"tags":{},"packages":[{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4307","published":"2009-12-13T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel\nbefore 2.6.32-git6 allows user-assisted remote attackers to cause a denial\nof service (divide-by-zero error and panic) via a malformed ext4 filesystem\ncontaining a super block with a large FLEX_BG group size (aka\ns_log_groups_per_flex value).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4307"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4306","published":"2009-12-13T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the EXT4_IOC_MOVE_EXT (aka move extents) ioctl\nimplementation in the ext4 filesystem in the Linux kernel 2.6.32-git6 and\nearlier allows local users to cause a denial of service (filesystem\ncorruption) via unknown vectors, a different vulnerability than\nCVE-2009-4131.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4306"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4308","published":"2009-12-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ext4_decode_error function in fs/ext4/super.c in the ext4 filesystem in\nthe Linux kernel before 2.6.32 allows user-assisted remote attackers to\ncause a denial of service (NULL pointer dereference), and possibly have\nunspecified other impact, via a crafted read-only filesystem that lacks a\njournal.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-894-1","https://www.cve.org/CVERecord?id=CVE-2009-4308"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: 78f1ddbb498283c2445c11b0dfa666424c301803"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-27.65","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-17.45","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-18.59","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-19.56","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.32~rc1","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.32~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-894-1"],"notices":[{"id":"USN-894-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2010-02-05T00:37:17.812607","description":"Amerigo Wang and Eric Sesterhenn discovered that the HFS and ext4\nfilesystems did not correctly check certain disk structures. If a user\nwere tricked into mounting a specially crafted filesystem, a remote\nattacker could crash the system or gain root privileges. (CVE-2009-4020,\nCVE-2009-4308)\n\nIt was discovered that FUSE did not correctly check certain requests.\nA local attacker with access to FUSE mounts could exploit this to\ncrash the system or possibly gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-4021)\n\nIt was discovered that KVM did not correctly decode certain guest\ninstructions. A local attacker in a guest could exploit this to\ntrigger high scheduling latency in the host, leading to a denial of\nservice. Ubuntu 6.06 was not affected. (CVE-2009-4031)\n\nIt was discovered that the OHCI fireware driver did not correctly\nhandle certain ioctls. A local attacker could exploit this to crash\nthe system, or possibly gain root privileges. Ubuntu 6.06 was not\naffected. (CVE-2009-4138)\n\nTavis Ormandy discovered that the kernel did not correctly handle\nO_ASYNC on locked files. A local attacker could exploit this to gain\nroot privileges. Only Ubuntu 9.04 and 9.10 were affected. (CVE-2009-4141)\n\nNeil Horman and Eugene Teo discovered that the e1000 and e1000e\nnetwork drivers did not correctly check the size of Ethernet frames.\nAn attacker on the local network could send specially crafted traffic\nto bypass packet filters, crash the system, or possibly gain root\nprivileges. (CVE-2009-4536, CVE-2009-4538)\n\nIt was discovered that \"print-fatal-signals\" reporting could show\narbitrary kernel memory contents. A local attacker could exploit\nthis, leading to a loss of privacy. By default this is disabled in\nUbuntu and did not affect Ubuntu 6.06. (CVE-2010-0003)\n\nOlli Jarva and Tuomo Untinen discovered that IPv6 did not correctly\nhandle jumbo frames. A remote attacker could exploit this to crash the\nsystem, leading to a denial of service. Only Ubuntu 9.04 and 9.10 were\naffected. (CVE-2010-0006)\n\nFlorian Westphal discovered that bridging netfilter rules could be\nmodified by unprivileged users. A local attacker could disrupt network\ntraffic, leading to a denial of service. (CVE-2010-0007)\n\nAl Viro discovered that certain mremap operations could leak kernel\nmemory. A local attacker could exploit this to consume all available\nmemory, leading to a denial of service. (CVE-2010-0291)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-27.65","description":"","is_source":true},{"name":"linux-image-2.6.24-27-itanium","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpia","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa32","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpiacompat","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-386","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-mckinley","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-xen","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-generic","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-virtual","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-server","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-rt","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-openvz","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.82","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"}],"intrepid":[{"name":"linux","version":"2.6.27-17.45","description":"","is_source":true},{"name":"linux-image-2.6.27-17-generic","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-virtual","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-server","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"}],"jaunty":[{"name":"linux","version":"2.6.28-18.59","description":"","is_source":true},{"name":"linux-image-2.6.28-18-generic","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-server","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-iop32x","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-ixp4xx","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-lpia","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-virtual","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-imx51","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-versatile","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"}],"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-211.22","description":"","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-108.21","description":"","is_source":true},{"name":"linux-ec2","version":"2.6.31-304.10","description":"","is_source":true},{"name":"linux","version":"2.6.31-19.56","description":"","is_source":true},{"name":"linux-image-2.6.31-304-ec2","version":"2.6.31-304.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-304.10"},{"name":"linux-image-2.6.31-19-386","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-108-imx51","version":"2.6.31-108.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-108.21"},{"name":"linux-image-2.6.31-19-powerpc-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove-z0","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-virtual","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-server","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-generic-pae","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-generic","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-lpia","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-ia64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"}]},"type":"USN","cves_ids":["CVE-2009-4031","CVE-2009-4308","CVE-2009-4536","CVE-2009-4538","CVE-2009-4021","CVE-2010-0007","CVE-2010-0291","CVE-2009-4020","CVE-2009-4138","CVE-2010-0006","CVE-2010-0003","CVE-2009-4141"]}]},{"id":"CVE-2009-4135","published":"2009-12-11T00:00:00","updated_at":"2025-09-16T11:20:08.599808+00:00","description":"\nThe distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1\nallows local users to gain privileges via a symlink attack on a file in a\ndirectory tree under /tmp.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2473-1","https://www.cve.org/CVERecord?id=CVE-2009-4135"],"bugs":[""],"patches":{"coreutils":["upstream: http://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=ae034822c535fa5"]},"tags":{"coreutils":["hardlink-restriction","symlink-restriction"]},"packages":[{"name":"coreutils","source":"https://ubuntu.com/security/cve?package=coreutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=coreutils","debian":"https://tracker.debian.org/pkg/coreutils","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"7.4-2ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2473-1"],"notices":[{"id":"USN-2473-1","title":"coreutils vulnerabilities","summary":"date and touch could be made to crash or run programs if they\nhandled specially crafted input.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-01-14T23:27:23.306139","description":"It was discovered that the distcheck rule in dist-check.mk in GNU\ncoreutils allows local users to gain privileges via a symlink attack\non a directory tree under /tmp. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2009-4135)\n\nBertrand Jacquin and Fiedler Roman discovered date and touch incorrectly\nhandled user-supplied input. An attacker could possibly use this to cause\na denial of service or potentially execute code. (CVE-2014-9471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"coreutils","version":"7.4-2ubuntu3.1","description":"GNU core utilities","is_source":true},{"name":"coreutils","version":"7.4-2ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/coreutils","version_link":"https://launchpad.net/ubuntu/+source/coreutils/7.4-2ubuntu3.1"}],"precise":[{"name":"coreutils","version":"8.13-3ubuntu3.3","description":"GNU core utilities","is_source":true},{"name":"coreutils","version":"8.13-3ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/coreutils","version_link":"https://launchpad.net/ubuntu/+source/coreutils/8.13-3ubuntu3.3"}],"trusty":[{"name":"coreutils","version":"8.21-1ubuntu5.1","description":"GNU core utilities","is_source":true},{"name":"coreutils","version":"8.21-1ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/coreutils","version_link":"https://launchpad.net/ubuntu/+source/coreutils/8.21-1ubuntu5.1","pocket":"security"},{"name":"mktemp","version":"8.21-1ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/coreutils","version_link":"https://launchpad.net/ubuntu/+source/coreutils/8.21-1ubuntu5.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2009-4135","CVE-2014-9471"]}]},{"id":"CVE-2009-4124","published":"2009-12-11T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the rb_str_justify function in string.c in\nRuby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute\narbitrary code via unspecified vectors involving (1) String#ljust, (2)\nString#center, or (3) String#rjust. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream says 1.8 is not affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.ruby-lang.org/en/news/2009/12/07/heap-overflow-in-string/","https://ubuntu.com/security/notices/USN-900-1","https://www.cve.org/CVERecord?id=CVE-2009-4124"],"bugs":[""],"patches":{"ruby1.8":[],"ruby1.9":[],"ruby1.9.1":["upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=26038","upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=26568"]},"tags":{},"packages":[{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.9","source":"https://ubuntu.com/security/cve?package=ruby1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9","debian":"https://tracker.debian.org/pkg/ruby1.9","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.2-7ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.2-9ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.0.5-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.0.5-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.9.1","source":"https://ubuntu.com/security/cve?package=ruby1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9.1","debian":"https://tracker.debian.org/pkg/ruby1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.9.1.376-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.9.1.376-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.9.1.376-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.1.376-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.1.376","component":null,"pocket":"security"}]}],"notices_ids":["USN-900-1"],"notices":[{"id":"USN-900-1","title":"Ruby vulnerabilities","summary":"Ruby vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-02-16T14:18:53.283530","description":"Emmanouel Kellinis discovered that Ruby did not properly handle certain\nstring operations. An attacker could exploit this issue and possibly\nexecute arbitrary code with application privileges. (CVE-2009-4124)\n\nGiovanni Pellerano, Alessandro Tanasi, and Francesco Ongaro discovered that\nRuby did not properly sanitize data written to log files. An attacker could\ninsert specially-crafted data into log files which could affect certain\nterminal emulators and cause arbitrary files to be overwritten, or even\npossibly execute arbitrary commands. (CVE-2009-4492)\n\nIt was discovered that Ruby did not properly handle string arguments that\nrepresent large numbers. An attacker could exploit this and cause a denial\nof service. This issue only affected Ubuntu 9.10. (CVE-2009-1904)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"ruby1.9","version":"1.9.0.2-7ubuntu1.3","description":"","is_source":true},{"name":"ruby1.9","version":"1.9.0.2-7ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.2-7ubuntu1.3"},{"name":"libruby1.9","version":"1.9.0.2-7ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.2-7ubuntu1.3"}],"jaunty":[{"name":"ruby1.9","version":"1.9.0.2-9ubuntu1.2","description":"","is_source":true},{"name":"ruby1.9","version":"1.9.0.2-9ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.2-9ubuntu1.2"},{"name":"libruby1.9","version":"1.9.0.2-9ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.2-9ubuntu1.2"}],"karmic":[{"name":"ruby1.9","version":"1.9.0.5-1ubuntu1.2","description":"","is_source":true},{"name":"ruby1.9","version":"1.9.0.5-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.5-1ubuntu1.2"},{"name":"libruby1.9","version":"1.9.0.5-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9/1.9.0.5-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2009-1904","CVE-2009-4124","CVE-2009-4492"]}]},{"id":"CVE-2009-3800","published":"2009-12-10T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Adobe Flash Player before\n10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of\nservice (application crash) or possibly execute arbitrary code via unknown\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3800"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.0.1.218+really9.0.260.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"10.0.42.34ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.0.42.34ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.0.42.34ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.42.34","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3799","published":"2009-12-10T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the Verifier::parseExceptionHandlers function in Adobe\nFlash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote\nattackers to execute arbitrary code via an SWF file with a large\nexception_count value that triggers memory corruption, related to\n\"generation of ActionScript exception handlers.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3799"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.42.34","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.0.1.218+really9.0.260.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"10.0.42.34ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.0.42.34ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.0.42.34ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3798","published":"2009-12-10T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow\nattackers to execute arbitrary code via unspecified vectors that trigger\nmemory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3798"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.0.1.218+really9.0.260.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"10.0.42.34ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.42.34","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.0.42.34ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.0.42.34ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3797","published":"2009-12-10T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might\nallow attackers to execute arbitrary code via unspecified vectors that\ntrigger memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3797"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.0.1.218+really9.0.260.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"10.0.42.34ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.0.42.34ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.0.42.34ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.42.34","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3796","published":"2009-12-10T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow\nattackers to execute arbitrary code via unspecified vectors, related to a\n\"data injection vulnerability.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3796"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.0.1.218+really9.0.260.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"10.0.42.34ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.0.42.34ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.0.42.34ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.42.34","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3794","published":"2009-12-10T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and\nAdobe AIR before 1.5.3 allows remote attackers to execute arbitrary code\nvia crafted dimensions of JPEG data in an SWF file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3794"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.0.1.218+really9.0.260.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"10.0.42.34ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.0.42.34ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.0.42.34ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.42.34","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4131","published":"2009-12-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4\nfilesystem in the Linux kernel before 2.6.32-git6 allows local users to\noverwrite arbitrary files via a crafted request, related to insufficient\nchecks for file permissions.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-869-1","https://www.cve.org/CVERecord?id=CVE-2009-4131"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-16.53","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-869-1"],"notices":[{"id":"USN-869-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2009-12-10T00:56:34.174406","description":"David Ford discovered that the IPv4 defragmentation routine did not\ncorrectly handle oversized packets. A remote attacker could send\nspecially crafted traffic that would cause a system to crash, leading\nto a denial of service. (The fix was included in the earlier kernels\nfrom USN-864-1.) (CVE-2009-1298)\n\nAkira Fujita discovered that the Ext4 \"move extents\" ioctl did not\ncorrectly check permissions. A local attacker could exploit this to\noverwrite arbitrary files on the system, leading to root privilege\nescalation. (CVE-2009-4131)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux","version":"2.6.31-16.53","description":"","is_source":true},{"name":"linux-image-2.6.31-16-powerpc-smp","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-server","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-powerpc64-smp","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-lpia","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-386","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-generic-pae","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-sparc64-smp","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-virtual","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-sparc64","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-ia64","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-generic","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-powerpc","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"}]},"type":"USN","cves_ids":["CVE-2009-4131","CVE-2009-1298"]}]},{"id":"CVE-2009-1298","published":"2009-12-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel\n2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls\nIP_INC_STATS_BH with an incorrect argument, which allows remote attackers\nto cause a denial of service (NULL pointer dereference and hang) via long\nIP packets, possibly related to the ip_defrag function.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-869-1","https://www.cve.org/CVERecord?id=CVE-2009-1298"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-16.53","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.32","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-869-1"],"notices":[{"id":"USN-869-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2009-12-10T00:56:34.174406","description":"David Ford discovered that the IPv4 defragmentation routine did not\ncorrectly handle oversized packets. A remote attacker could send\nspecially crafted traffic that would cause a system to crash, leading\nto a denial of service. (The fix was included in the earlier kernels\nfrom USN-864-1.) (CVE-2009-1298)\n\nAkira Fujita discovered that the Ext4 \"move extents\" ioctl did not\ncorrectly check permissions. A local attacker could exploit this to\noverwrite arbitrary files on the system, leading to root privilege\nescalation. (CVE-2009-4131)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux","version":"2.6.31-16.53","description":"","is_source":true},{"name":"linux-image-2.6.31-16-powerpc-smp","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-server","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-powerpc64-smp","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-lpia","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-386","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-generic-pae","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-sparc64-smp","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-virtual","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-sparc64","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-ia64","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-generic","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"},{"name":"linux-image-2.6.31-16-powerpc","version":"2.6.31-16.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.53"}]},"type":"USN","cves_ids":["CVE-2009-4131","CVE-2009-1298"]}]},{"id":"CVE-2009-4235","published":"2009-12-08T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nacpid 1.0.4 sets an unrestrictive umask, which might allow local users to\nleverage weak permissions on /var/log/acpid, and obtain sensitive\ninformation by reading this file or cause a denial of service by\noverwriting this file, a different vulnerability than CVE-2009-4033.","ubuntu_description":"","notes":[{"author":"kees","note":"per Debian, only logs to syslog."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4235"],"bugs":[""],"patches":{"acpid":[]},"tags":{},"packages":[{"name":"acpid","source":"https://ubuntu.com/security/cve?package=acpid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acpid","debian":"https://tracker.debian.org/pkg/acpid","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4033","published":"2009-12-08T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nA certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the\nopen function with insufficient arguments, which might allow local users to\nleverage weak permissions on /var/log/acpid, and obtain sensitive\ninformation by reading this file, cause a denial of service by overwriting\nthis file, or gain privileges by executing this file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4033"],"bugs":[""],"patches":{"acpid":[]},"tags":{},"packages":[{"name":"acpid","source":"https://ubuntu.com/security/cve?package=acpid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acpid","debian":"https://tracker.debian.org/pkg/acpid","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"RH patch","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"RH patch","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4228","published":"2009-12-08T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier\nallows remote attackers to cause a denial of service (application crash)\nvia a long string in a malformed .fig file that uses the 1.3 file format,\npossibly related to the readfp_fig function in f_read.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4228"],"bugs":[""],"patches":{"xfig":[]},"tags":{},"packages":[{"name":"xfig","source":"https://ubuntu.com/security/cve?package=xfig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xfig","debian":"https://tracker.debian.org/pkg/xfig","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.5b","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4227","published":"2009-12-08T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the read_1_3_textobject function in\nf_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function\nin read1_3.c in fig2dev in Transfig 3.2.5a and earlier, allows remote\nattackers to execute arbitrary code via a long string in a malformed .fig\nfile that uses the 1.3 file format. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4227"],"bugs":[""],"patches":{"xfig":[]},"tags":{},"packages":[{"name":"xfig","source":"https://ubuntu.com/security/cve?package=xfig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xfig","debian":"https://tracker.debian.org/pkg/xfig","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:3.2.5.c-7","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:3.2.5.c-7","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:3.2.5.b-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:3.2.5.c-7","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3994","published":"2009-12-08T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the GetUID function in src-IL/src/il_dicom.c\nin DevIL 1.7.8 allows remote attackers to cause a denial of service\n(application crash) or execute arbitrary code via a crafted DICOM file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"vulnerable code isn't in 1.6.x"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3994"],"bugs":[""],"patches":{"devil":["upstream: http://sourceforge.net/tracker/download.php?group_id=4470&atid=304470&file_id=353841&aid=2908728"]},"tags":{},"packages":[{"name":"devil","source":"https://ubuntu.com/security/cve?package=devil","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=devil","debian":"https://tracker.debian.org/pkg/devil","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.6.7-5.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.7.8-6","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.7.8-6","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.7.8-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.8-6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":73420,"limit":20,"total_results":79316}