{"cves":[{"id":"CVE-2009-4081","published":"2009-11-29T13:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in dstat before r3199 allows local\nusers to gain privileges via a Trojan horse Python module in the current\nworking directory, a different vulnerability than CVE-2009-3894.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"according to gentoo bug report, the commit that fixed this\nissue made it into the 0.7.0 release"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4081"],"bugs":["http://bugs.gentoo.org/show_bug.cgi?id=293497"],"patches":{"dstat":[]},"tags":{},"packages":[{"name":"dstat","source":"https://ubuntu.com/security/cve?package=dstat","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dstat","debian":"https://tracker.debian.org/pkg/dstat","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.7.0","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.7.0-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.7.0-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.7.0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.7.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4032","published":"2009-11-29T13:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow\nremote attackers to inject arbitrary web script or HTML via vectors related\nto (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php,\nand (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or\n(b) graph_start parameters to graph.php; (c) the date1 parameter in a tree\naction to graph_view.php; and the (d) page_refresh and (e)\ndefault_dual_pane_width parameters to graph_settings.php.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"cross_site_fix.patch still not applied as of 0.8.7e-4"},{"author":"mdeslaur","note":"patch is in fact in the lucid package"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4032"],"bugs":["http://bugs.gentoo.org/show_bug.cgi?id=294573"],"patches":{"cacti":["upstream: http://www.cacti.net/download_patches.php","upstream: http://www.cacti.net/downloads/patches/0.8.7e/cross_site_fix.patch"]},"tags":{},"packages":[{"name":"cacti","source":"https://ubuntu.com/security/cve?package=cacti","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cacti","debian":"https://tracker.debian.org/pkg/cacti","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.8.7e-2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.8.7g-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"0.8.7g-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"0.8.7g-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.7g-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4024","published":"2009-11-29T13:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nArgument injection vulnerability in the ping function in Ping.php in the\nNet_Ping package before 2.4.5 for PEAR allows remote attackers to execute\narbitrary shell commands via the host parameter. NOTE: this has also been\nreported as a shell metacharacter problem.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blog.pear.php.net/2009/11/14/net_traceroute-and-net_ping-security-advisory/","http://pear.php.net/advisory20091114-01.txt","https://www.cve.org/CVERecord?id=CVE-2009-4024"],"bugs":[""],"patches":{"php-net-ping":[]},"tags":{},"packages":[{"name":"php-net-ping","source":"https://ubuntu.com/security/cve?package=php-net-ping","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-net-ping","debian":"https://tracker.debian.org/pkg/php-net-ping","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.4.2-1+etch1build0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.4.2-1+etch1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.4.2-1+etch1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.4.2-1+etch1build0.9.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4023","published":"2009-11-29T13:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nArgument injection vulnerability in the sendmail implementation of the\nMail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR\nallows remote attackers to read and write arbitrary files via a crafted\n$from parameter, a different vector than CVE-2009-4111.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4023"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=557121","http://pear.php.net/bugs/bug.php?id=16200"],"patches":{"php-mail":["vendor: http://www.debian.org/security/2009/dsa-1938"]},"tags":{},"packages":[{"name":"php-mail","source":"https://ubuntu.com/security/cve?package=php-mail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-mail","debian":"https://tracker.debian.org/pkg/php-mail","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.6-2+etch1build0.6.06.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.6-2+etch1build0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.14-1+lenny1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.14-1+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.14-1+lenny1build0.9.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3894","published":"2009-11-29T13:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple untrusted search path vulnerabilities in dstat before 0.7.0 allow\nlocal users to gain privileges via a Trojan horse Python module in (1) the\ncurrent working directory or (2) a certain subdirectory of the current\nworking directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3894"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=538459","http://bugs.gentoo.org/show_bug.cgi?id=293497","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=557989"],"patches":{"dstat":[]},"tags":{},"packages":[{"name":"dstat","source":"https://ubuntu.com/security/cve?package=dstat","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dstat","debian":"https://tracker.debian.org/pkg/dstat","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.7.0-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.7.0-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.7.0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.7.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.7.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3736","published":"2009-11-29T13:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in\nHam Radio Control Libraries, Q, and possibly other products, attempts to\nopen a .la file in the current working directory, which allows local users\nto gain privileges via a Trojan horse file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3736"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=537941"],"patches":{"libtool":["upstream: http://git.savannah.gnu.org/cgit/libtool.git/commit/?h=branch-1-5&id=29b48580df75f0c5baa2962548a4c101ec7ed7ec","upstream: ftp://ftp.gnu.org/gnu/libtool/libtool-2.2.6a-2.2.6b.diff.gz"]},"tags":{},"packages":[{"name":"libtool","source":"https://ubuntu.com/security/cve?package=libtool","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libtool","debian":"https://tracker.debian.org/pkg/libtool","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.6b","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4031","published":"2009-11-29T00:00:00","updated_at":"2026-07-04T07:29:49.179418+00:00","description":"\nThe do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in\nthe KVM subsystem in the Linux kernel before 2.6.32-rc8-next-20091125 tries\nto interpret instructions that contain too many bytes to be valid, which\nallows guest OS users to cause a denial of service (increased scheduling\nlatency) on the host OS via unspecified manipulations related to SMP\nsupport.","ubuntu_description":"\nIt was discovered that KVM did not correctly decode certain guest\ninstructions. A local attacker in a guest could exploit this to trigger\nhigh scheduling latency in the host, leading to a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-894-1","https://www.cve.org/CVERecord?id=CVE-2009-4031"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=541160"],"patches":{"linux-source-2.6.15":[],"linux":["break-fix: - eb3c79e64a70fb8f7473e30fa07e89c1ecc2c9bb"],"linux-fsl-imx51":[],"kvm":[],"qemu-kvm":[],"linux-ti-omap4":[],"linux-mvl-dove":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"kvm":["universe-binary"]},"packages":[{"name":"kvm","source":"https://ubuntu.com/security/cve?package=kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kvm","debian":"https://tracker.debian.org/pkg/kvm","statuses":[{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-27.65","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-17.45","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-18.59","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-19.56","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-19.56","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-108.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-211.22","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-894-1"],"notices":[{"id":"USN-894-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2010-02-05T00:37:17.812607","description":"Amerigo Wang and Eric Sesterhenn discovered that the HFS and ext4\nfilesystems did not correctly check certain disk structures. If a user\nwere tricked into mounting a specially crafted filesystem, a remote\nattacker could crash the system or gain root privileges. (CVE-2009-4020,\nCVE-2009-4308)\n\nIt was discovered that FUSE did not correctly check certain requests.\nA local attacker with access to FUSE mounts could exploit this to\ncrash the system or possibly gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-4021)\n\nIt was discovered that KVM did not correctly decode certain guest\ninstructions. A local attacker in a guest could exploit this to\ntrigger high scheduling latency in the host, leading to a denial of\nservice. Ubuntu 6.06 was not affected. (CVE-2009-4031)\n\nIt was discovered that the OHCI fireware driver did not correctly\nhandle certain ioctls. A local attacker could exploit this to crash\nthe system, or possibly gain root privileges. Ubuntu 6.06 was not\naffected. (CVE-2009-4138)\n\nTavis Ormandy discovered that the kernel did not correctly handle\nO_ASYNC on locked files. A local attacker could exploit this to gain\nroot privileges. Only Ubuntu 9.04 and 9.10 were affected. (CVE-2009-4141)\n\nNeil Horman and Eugene Teo discovered that the e1000 and e1000e\nnetwork drivers did not correctly check the size of Ethernet frames.\nAn attacker on the local network could send specially crafted traffic\nto bypass packet filters, crash the system, or possibly gain root\nprivileges. (CVE-2009-4536, CVE-2009-4538)\n\nIt was discovered that \"print-fatal-signals\" reporting could show\narbitrary kernel memory contents. A local attacker could exploit\nthis, leading to a loss of privacy. By default this is disabled in\nUbuntu and did not affect Ubuntu 6.06. (CVE-2010-0003)\n\nOlli Jarva and Tuomo Untinen discovered that IPv6 did not correctly\nhandle jumbo frames. A remote attacker could exploit this to crash the\nsystem, leading to a denial of service. Only Ubuntu 9.04 and 9.10 were\naffected. (CVE-2010-0006)\n\nFlorian Westphal discovered that bridging netfilter rules could be\nmodified by unprivileged users. A local attacker could disrupt network\ntraffic, leading to a denial of service. (CVE-2010-0007)\n\nAl Viro discovered that certain mremap operations could leak kernel\nmemory. A local attacker could exploit this to consume all available\nmemory, leading to a denial of service. (CVE-2010-0291)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-27.65","description":"","is_source":true},{"name":"linux-image-2.6.24-27-itanium","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpia","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa32","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpiacompat","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-386","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-mckinley","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-xen","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-generic","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-virtual","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-server","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-rt","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-openvz","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.82","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"}],"intrepid":[{"name":"linux","version":"2.6.27-17.45","description":"","is_source":true},{"name":"linux-image-2.6.27-17-generic","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-virtual","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-server","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"}],"jaunty":[{"name":"linux","version":"2.6.28-18.59","description":"","is_source":true},{"name":"linux-image-2.6.28-18-generic","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-server","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-iop32x","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-ixp4xx","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-lpia","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-virtual","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-imx51","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-versatile","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"}],"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-211.22","description":"","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-108.21","description":"","is_source":true},{"name":"linux-ec2","version":"2.6.31-304.10","description":"","is_source":true},{"name":"linux","version":"2.6.31-19.56","description":"","is_source":true},{"name":"linux-image-2.6.31-304-ec2","version":"2.6.31-304.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-304.10"},{"name":"linux-image-2.6.31-19-386","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-108-imx51","version":"2.6.31-108.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-108.21"},{"name":"linux-image-2.6.31-19-powerpc-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove-z0","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-virtual","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-server","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-generic-pae","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-generic","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-lpia","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-ia64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"}]},"type":"USN","cves_ids":["CVE-2009-4031","CVE-2009-4308","CVE-2009-4536","CVE-2009-4538","CVE-2009-4021","CVE-2010-0007","CVE-2010-0291","CVE-2009-4020","CVE-2009-4138","CVE-2010-0006","CVE-2010-0003","CVE-2009-4141"]}]},{"id":"CVE-2009-4079","published":"2009-11-25T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and\nearlier allows remote attackers to hijack the authentication of users for\nrequests that delete a ticket via unspecified vectors.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"fixed before package made it into any archive"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4079"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"artful","status":"not-affected","description":"0.9.0svn2902-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.9.0svn2902-1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.9.0svn2902-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [0.9.0svn2902-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4078","published":"2009-11-25T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and\nearlier allow remote attackers to inject arbitrary web script or HTML via\nunspecified vectors.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"fixed before package made it into any archive"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4078"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"artful","status":"not-affected","description":"0.9.0svn2902-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.9.0svn2902-1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.9.0svn2902-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [0.9.0svn2902-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4077","published":"2009-11-25T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2\nand earlier allows remote attackers to hijack the authentication of\nunspecified users for requests that send arbitrary emails via unspecified\nvectors, a different vulnerability than CVE-2009-4076.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4077"],"bugs":[""],"patches":{"roundcube":[]},"tags":{},"packages":[{"name":"roundcube","source":"https://ubuntu.com/security/cve?package=roundcube","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=roundcube","debian":"https://tracker.debian.org/pkg/roundcube","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.3.1-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4076","published":"2009-11-25T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2\nand earlier allows remote attackers to hijack the authentication of\nunspecified users for requests that modify user information via unspecified\nvectors, a different vulnerability than CVE-2009-4077.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4076"],"bugs":[""],"patches":{"roundcube":[]},"tags":{},"packages":[{"name":"roundcube","source":"https://ubuntu.com/security/cve?package=roundcube","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=roundcube","debian":"https://tracker.debian.org/pkg/roundcube","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.3.1-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4022","published":"2009-11-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before\n9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before\n9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows\nremote attackers to conduct DNS cache poisoning attacks by receiving a\nrecursive client query and sending a response that contains an Additional\nsection with crafted data, which is not properly handled when the response\nis processed \"at the same time as requesting DNSSEC records (DO),\" aka Bug\n20438.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.isc.org/node/504","https://ubuntu.com/security/notices/USN-865-1","https://ubuntu.com/security/notices/USN-888-1","https://www.cve.org/CVERecord?id=CVE-2009-4022"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=538744"],"patches":{"bind":[],"bind9":[]},"tags":{},"packages":[{"name":"bind","source":"https://ubuntu.com/security/cve?package=bind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind","debian":"https://tracker.debian.org/pkg/bind","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"dapper","status":"released","description":"1:9.3.2-2ubuntu1.9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:9.4.2.dfsg.P2-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:9.5.0.dfsg.P2-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1:9.5.1.dfsg.P2-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:9.6.1.dfsg.P1-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:9.6.1.dfsg.P2-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-865-1","USN-888-1"],"notices":[{"id":"USN-865-1","title":"Bind vulnerability","summary":"Bind vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-12-07T14:36:52.672591","description":"Michael Sinatra discovered that Bind did not correctly validate certain\nrecords added to its cache. When DNSSEC validation is in use, a remote\nattacker could exploit this to spoof DNS entries and poison DNS caches.\nAmong other things, this could lead to misdirected email and web traffic.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"bind9","version":"1:9.4.2.dfsg.P2-2ubuntu0.4","description":"","is_source":true},{"name":"libdns36","version":"1:9.4.2.dfsg.P2-2ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.4.2.dfsg.P2-2ubuntu0.4"}],"dapper":[{"name":"bind9","version":"1:9.3.2-2ubuntu1.9","description":"","is_source":true},{"name":"libdns23","version":"1:9.3.2-2ubuntu1.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.3.2-2ubuntu1.9"}],"intrepid":[{"name":"bind9","version":"1:9.5.0.dfsg.P2-1ubuntu3.4","description":"","is_source":true},{"name":"libdns44","version":"1:9.5.0.dfsg.P2-1ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.5.0.dfsg.P2-1ubuntu3.4"}],"jaunty":[{"name":"bind9","version":"1:9.5.1.dfsg.P2-1ubuntu0.3","description":"","is_source":true},{"name":"libdns46","version":"1:9.5.1.dfsg.P2-1ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.5.1.dfsg.P2-1ubuntu0.3"}],"karmic":[{"name":"bind9","version":"1:9.6.1.dfsg.P1-3ubuntu0.2","description":"","is_source":true},{"name":"libdns53","version":"1:9.6.1.dfsg.P1-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.6.1.dfsg.P1-3ubuntu0.2"}]},"type":"USN","cves_ids":["CVE-2009-4022"]},{"id":"USN-888-1","title":"Bind vulnerabilities","summary":"Bind vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-01-20T18:07:07.642969","description":"It was discovered that Bind would incorrectly cache bogus NXDOMAIN\nresponses. When DNSSEC validation is in use, a remote attacker could\nexploit this to cause a denial of service, and possibly poison DNS caches.\n(CVE-2010-0097)\n\nUSN-865-1 provided updated Bind packages to fix a security vulnerability.\nThe upstream security patch to fix CVE-2009-4022 was incomplete and\nCVE-2010-0290 was assigned to the issue. This update corrects the problem.\nOriginal advisory details:\n\n Michael Sinatra discovered that Bind did not correctly validate certain\n records added to its cache. When DNSSEC validation is in use, a remote\n attacker could exploit this to spoof DNS entries and poison DNS caches.\n Among other things, this could lead to misdirected email and web traffic.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"bind9","version":"1:9.4.2.dfsg.P2-2ubuntu0.5","description":"","is_source":true},{"name":"libdns36","version":"1:9.4.2.dfsg.P2-2ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.4.2.dfsg.P2-2ubuntu0.5"}],"dapper":[{"name":"bind9","version":"1:9.3.2-2ubuntu1.11","description":"","is_source":true},{"name":"libdns23","version":"1:9.3.2-2ubuntu1.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.3.2-2ubuntu1.11"}],"intrepid":[{"name":"bind9","version":"1:9.5.0.dfsg.P2-1ubuntu3.5","description":"","is_source":true},{"name":"libdns44","version":"1:9.5.0.dfsg.P2-1ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.5.0.dfsg.P2-1ubuntu3.5"}],"jaunty":[{"name":"bind9","version":"1:9.5.1.dfsg.P2-1ubuntu0.4","description":"","is_source":true},{"name":"libdns46","version":"1:9.5.1.dfsg.P2-1ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.5.1.dfsg.P2-1ubuntu0.4"}],"karmic":[{"name":"bind9","version":"1:9.6.1.dfsg.P1-3ubuntu0.3","description":"","is_source":true},{"name":"libdns53","version":"1:9.6.1.dfsg.P1-3ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.6.1.dfsg.P1-3ubuntu0.3"}]},"type":"USN","cves_ids":["CVE-2010-0097","CVE-2010-0290","CVE-2009-4022"]}]},{"id":"CVE-2009-4021","published":"2009-11-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe fuse_direct_io function in fs/fuse/file.c in the fuse subsystem in the\nLinux kernel before 2.6.32-rc7 might allow attackers to cause a denial of\nservice (invalid pointer dereference and OOPS) via vectors possibly related\nto a memory-consumption attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-894-1","https://www.cve.org/CVERecord?id=CVE-2009-4021"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=538734"],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f60311d5f7670d9539b424e4ed8b5c0872fc9e83"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-27.65","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-17.45","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-18.59","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.32~rc7","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.82","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.32~rc7","component":null,"pocket":"security"}]}],"notices_ids":["USN-894-1"],"notices":[{"id":"USN-894-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2010-02-05T00:37:17.812607","description":"Amerigo Wang and Eric Sesterhenn discovered that the HFS and ext4\nfilesystems did not correctly check certain disk structures. If a user\nwere tricked into mounting a specially crafted filesystem, a remote\nattacker could crash the system or gain root privileges. (CVE-2009-4020,\nCVE-2009-4308)\n\nIt was discovered that FUSE did not correctly check certain requests.\nA local attacker with access to FUSE mounts could exploit this to\ncrash the system or possibly gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-4021)\n\nIt was discovered that KVM did not correctly decode certain guest\ninstructions. A local attacker in a guest could exploit this to\ntrigger high scheduling latency in the host, leading to a denial of\nservice. Ubuntu 6.06 was not affected. (CVE-2009-4031)\n\nIt was discovered that the OHCI fireware driver did not correctly\nhandle certain ioctls. A local attacker could exploit this to crash\nthe system, or possibly gain root privileges. Ubuntu 6.06 was not\naffected. (CVE-2009-4138)\n\nTavis Ormandy discovered that the kernel did not correctly handle\nO_ASYNC on locked files. A local attacker could exploit this to gain\nroot privileges. Only Ubuntu 9.04 and 9.10 were affected. (CVE-2009-4141)\n\nNeil Horman and Eugene Teo discovered that the e1000 and e1000e\nnetwork drivers did not correctly check the size of Ethernet frames.\nAn attacker on the local network could send specially crafted traffic\nto bypass packet filters, crash the system, or possibly gain root\nprivileges. (CVE-2009-4536, CVE-2009-4538)\n\nIt was discovered that \"print-fatal-signals\" reporting could show\narbitrary kernel memory contents. A local attacker could exploit\nthis, leading to a loss of privacy. By default this is disabled in\nUbuntu and did not affect Ubuntu 6.06. (CVE-2010-0003)\n\nOlli Jarva and Tuomo Untinen discovered that IPv6 did not correctly\nhandle jumbo frames. A remote attacker could exploit this to crash the\nsystem, leading to a denial of service. Only Ubuntu 9.04 and 9.10 were\naffected. (CVE-2010-0006)\n\nFlorian Westphal discovered that bridging netfilter rules could be\nmodified by unprivileged users. A local attacker could disrupt network\ntraffic, leading to a denial of service. (CVE-2010-0007)\n\nAl Viro discovered that certain mremap operations could leak kernel\nmemory. A local attacker could exploit this to consume all available\nmemory, leading to a denial of service. (CVE-2010-0291)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-27.65","description":"","is_source":true},{"name":"linux-image-2.6.24-27-itanium","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpia","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa32","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpiacompat","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-386","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-mckinley","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-xen","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-generic","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-virtual","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-server","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-rt","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-openvz","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.82","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"}],"intrepid":[{"name":"linux","version":"2.6.27-17.45","description":"","is_source":true},{"name":"linux-image-2.6.27-17-generic","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-virtual","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-server","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"}],"jaunty":[{"name":"linux","version":"2.6.28-18.59","description":"","is_source":true},{"name":"linux-image-2.6.28-18-generic","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-server","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-iop32x","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-ixp4xx","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-lpia","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-virtual","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-imx51","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-versatile","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"}],"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-211.22","description":"","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-108.21","description":"","is_source":true},{"name":"linux-ec2","version":"2.6.31-304.10","description":"","is_source":true},{"name":"linux","version":"2.6.31-19.56","description":"","is_source":true},{"name":"linux-image-2.6.31-304-ec2","version":"2.6.31-304.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-304.10"},{"name":"linux-image-2.6.31-19-386","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-108-imx51","version":"2.6.31-108.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-108.21"},{"name":"linux-image-2.6.31-19-powerpc-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove-z0","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-virtual","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-server","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-generic-pae","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-generic","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-lpia","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-ia64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"}]},"type":"USN","cves_ids":["CVE-2009-4031","CVE-2009-4308","CVE-2009-4536","CVE-2009-4538","CVE-2009-4021","CVE-2010-0007","CVE-2010-0291","CVE-2009-4020","CVE-2009-4138","CVE-2010-0006","CVE-2010-0003","CVE-2009-4141"]}]},{"id":"CVE-2009-4070","published":"2009-11-24T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other\nversions allows remote attackers to execute arbitrary SQL commands via\nunknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.debian.org/security/2009/dsa-1818","https://www.cve.org/CVERecord?id=CVE-2009-4070"],"bugs":[""],"patches":{"gforge":[]},"tags":{},"packages":[{"name":"gforge","source":"https://ubuntu.com/security/cve?package=gforge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gforge","debian":"https://tracker.debian.org/pkg/gforge","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4069","published":"2009-11-24T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14,\n4.7.3, and possibly other versions allow remote attackers to inject\narbitrary web script or HTML via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.debian.org/security/2009/dsa-1818","https://www.cve.org/CVERecord?id=CVE-2009-4069"],"bugs":[""],"patches":{"gforge":[]},"tags":{},"packages":[{"name":"gforge","source":"https://ubuntu.com/security/cve?package=gforge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gforge","debian":"https://tracker.debian.org/pkg/gforge","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3898","published":"2009-11-24T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in src/http/modules/ngx_http_dav_module.c\nin nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows\nremote authenticated users to create or overwrite arbitrary files via a ..\n(dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2)\nMOVE method.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3898"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/nginx/+bug/511681","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=557389"],"patches":{"nginx":[]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.7.63-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.7.63, 0.8.17","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3897","published":"2009-11-24T17:30:00","updated_at":"2025-08-25T19:50:26.331023+00:00","description":"\nDovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain\ndirectories at installation time, which allows local users to access\narbitrary user accounts by replacing the auth socket, related to the parent\ndirectories of the base_dir directory, and possibly the base_dir directory\nitself.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects 1.2.x"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.dovecot.org/list/dovecot-news/2009-November/000143.html","https://www.cve.org/CVERecord?id=CVE-2009-3897"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=557601"],"patches":{"dovecot":[]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"dapper","status":"not-affected","description":"1.0.beta3-3ubuntu5.6","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1:1.0.10-1ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1:1.1.4-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1:1.1.11-0ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1:1.1.11-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3896","published":"2009-11-24T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsrc/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14,\n0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x\nbefore 0.8.14 allows remote attackers to cause a denial of service (NULL\npointer dereference and worker process crash) via a long URI.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3896"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/nginx/+bug/511681"],"patches":{"nginx":["upstream: http://sysoev.ru/nginx/patch.null.pointer.txt"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.7.62-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.7.62-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.5.38, 0.7.62, 0.8.14","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3303","published":"2009-11-24T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge\n4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web\nscript or HTML via the helpname parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.debian.org/security/2009/dsa-1937","https://www.cve.org/CVERecord?id=CVE-2009-3303"],"bugs":[""],"patches":{"gforge":["vendor: http://www.debian.org/security/2009/dsa-1937"]},"tags":{},"packages":[{"name":"gforge","source":"https://ubuntu.com/security/cve?package=gforge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gforge","debian":"https://tracker.debian.org/pkg/gforge","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4.7~rc2-7lenny3build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"4.8.2-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"4.8.2-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.8.1-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3559","published":"2009-11-23T17:30:00","updated_at":"2025-08-04T19:23:36.110448+00:00","description":"\nmain/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize\nthe safe_mode_include_dir directive, which allows context-dependent\nattackers to have an unknown impact by triggering the failure of PHP\nscripts that perform include or require operations, as demonstrated by a\nscript that attempts to perform a require_once on a file in a standard\nlibrary directory. NOTE: a reliable third party reports that this is not a\nvulnerability, because it results in a more restrictive security policy.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"safe_mode, and disputed\n5.3.x only as per php bug report"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3559"],"bugs":["http://bugs.php.net/bug.php?id=50063"],"patches":{"php5":["upstream: http://svn.php.net/viewvc/?view=revision&revision=290578"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"5.1.2-1ubuntu3.15","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu5.7","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"5.2.6-2ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.2.6.dfsg.1-3ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.2.10.dfsg.1-2ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":73460,"limit":20,"total_results":79316}