{"cves":[{"id":"CVE-2009-3888","published":"2009-11-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe do_mmap_pgoff function in mm/nommu.c in the Linux kernel before\n2.6.31.6, when the CPU lacks a memory management unit, allows local users\nto cause a denial of service (OOPS) via an application that attempts to\nallocate a large amount of memory.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-864-1","https://www.cve.org/CVERecord?id=CVE-2009-3888"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-16.52","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.81","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-864-1"],"notices":[{"id":"USN-864-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2009-12-05T01:52:13.000003","description":"It was discovered that the AX.25 network subsystem did not correctly\ncheck integer signedness in certain setsockopt calls. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\nUbuntu 9.10 was not affected. (CVE-2009-2909)\n\nJan Beulich discovered that the kernel could leak register contents to\n32-bit processes that were switched to 64-bit mode. A local attacker\ncould run a specially crafted binary to read register values from an\nearlier process, leading to a loss of privacy. (CVE-2009-2910)\n\nDave Jones discovered that the gdth SCSI driver did not correctly validate\narray indexes in certain ioctl calls. A local attacker could exploit\nthis to crash the system or gain elevated privileges. (CVE-2009-3080)\n\nEric Dumazet and Jiri Pirko discovered that the TC and CLS subsystems\nwould leak kernel memory via uninitialized structure members. A local\nattacker could exploit this to read several bytes of kernel memory,\nleading to a loss of privacy. (CVE-2009-3228, CVE-2009-3612)\n\nEarl Chew discovered race conditions in pipe handling. A local attacker\ncould exploit anonymous pipes via /proc/*/fd/ and crash the system or\ngain root privileges. (CVE-2009-3547)\n\nDave Jones and Francois Romieu discovered that the r8169 network driver\ncould be made to leak kernel memory. A remote attacker could send a large\nnumber of jumbo frames until the system memory was exhausted, leading\nto a denial of service. Ubuntu 9.10 was not affected. (CVE-2009-3613).\n\nBen Hutchings discovered that the ATI Rage 128 video driver did not\ncorrectly validate initialization states. A local attacker could\nmake specially crafted ioctl calls to crash the system or gain root\nprivileges. (CVE-2009-3620)\n\nTomoki Sekiyama discovered that Unix sockets did not correctly verify\nnamespaces. A local attacker could exploit this to cause a system hang,\nleading to a denial of service. (CVE-2009-3621)\n\nJ. Bruce Fields discovered that NFSv4 did not correctly use the credential\ncache. A local attacker using a mount with AUTH_NULL authentication\ncould exploit this to crash the system or gain root privileges. Only\nUbuntu 9.10 was affected. (CVE-2009-3623)\n\nAlexander Zangerl discovered that the kernel keyring did not correctly\nreference count. A local attacker could issue a series of specially\ncrafted keyring calls to crash the system or gain root privileges.\nOnly Ubuntu 9.10 was affected. (CVE-2009-3624)\n\nDavid Wagner discovered that KVM did not correctly bounds-check CPUID\nentries. A local attacker could exploit this to crash the system\nor possibly gain elevated privileges. Ubuntu 6.06 and 9.10 were not\naffected. (CVE-2009-3638)\n\nAvi Kivity discovered that KVM did not correctly check privileges when\naccessing debug registers. A local attacker could exploit this to\ncrash a host system from within a guest system, leading to a denial of\nservice. Ubuntu 6.06 and 9.10 were not affected. (CVE-2009-3722)\n\nPhilip Reisner discovered that the connector layer for uvesafb, pohmelfs,\ndst, and dm did not correctly check capabilties. A local attacker could\nexploit this to crash the system or gain elevated privileges. Ubuntu\n6.06 was not affected. (CVE-2009-3725)\n\nTrond Myklebust discovered that NFSv4 clients did not robustly\nverify attributes. A malicious remote NFSv4 server could exploit\nthis to crash a client or gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-3726)\n\nRobin Getz discovered that NOMMU systems did not correctly validate\nNULL pointers in do_mmap_pgoff calls. A local attacker could attempt to\nallocate large amounts of memory to crash the system, leading to a denial\nof service. Only Ubuntu 6.06 and 9.10 were affected. (CVE-2009-3888)\n\nJoseph Malicki discovered that the MegaRAID SAS driver had\nworld-writable option files. A local attacker could exploit these\nto disrupt the behavior of the controller, leading to a denial of\nservice. (CVE-2009-3889, CVE-2009-3939)\n\nRoel Kluin discovered that the Hisax ISDN driver did not correctly\ncheck the size of packets. A remote attacker could send specially\ncrafted packets to cause a system crash, leading to a denial of\nservice. (CVE-2009-4005)\n\nLennert Buytenhek discovered that certain 802.11 states were not handled\ncorrectly. A physically-proximate remote attacker could send specially\ncrafted wireless traffic that would crash the system, leading to a denial\nof service. Only Ubuntu 9.10 was affected. (CVE-2009-4026, CVE-2009-4027)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-26.64","description":"","is_source":true},{"name":"linux-image-2.6.24-26-mckinley","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-generic","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-hppa32","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-386","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-sparc64-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-openvz","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-itanium","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-lpiacompat","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-xen","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-lpia","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"usb-modules-2.6.24-26-sparc64-di","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-virtual","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-rt","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-server","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc64-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-hppa64","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-sparc64","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.81","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"}],"intrepid":[{"name":"linux","version":"2.6.27-16.44","description":"","is_source":true},{"name":"linux-image-2.6.27-16-virtual","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"},{"name":"linux-image-2.6.27-16-server","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"},{"name":"linux-image-2.6.27-16-generic","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"}],"jaunty":[{"name":"linux","version":"2.6.28-17.58","description":"","is_source":true},{"name":"linux-image-2.6.28-17-imx51","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-virtual","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-server","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-versatile","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-iop32x","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-generic","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-ixp4xx","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-lpia","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"}],"karmic":[{"name":"linux","version":"2.6.31-16.52","description":"","is_source":true},{"name":"linux-image-2.6.31-16-powerpc-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-server","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-powerpc64-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-lpia","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-386","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-generic-pae","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-sparc64-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-virtual","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-sparc64","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-ia64","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-generic","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-powerpc","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"}]},"type":"USN","cves_ids":["CVE-2009-3726","CVE-2009-4027","CVE-2009-3624","CVE-2009-3612","CVE-2009-3547","CVE-2009-3613","CVE-2009-3725","CVE-2009-3620","CVE-2009-3623","CVE-2009-3888","CVE-2009-3889","CVE-2009-3939","CVE-2009-4005","CVE-2009-3621","CVE-2009-2910","CVE-2009-4026","CVE-2009-3228","CVE-2009-3080","CVE-2009-2909","CVE-2009-3722","CVE-2009-3638"]}]},{"id":"CVE-2009-3938","published":"2009-11-13T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the ABWOutputDev::endWord function in\npoppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and\npossibly other versions, as used by the Abiword pdftoabw utility, allows\nuser-assisted remote attackers to cause a denial of service and possibly\nexecute arbitrary code via a crafted PDF file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"as of 2010-01-18, upstream hasn't committed a fix yet\ndebian released patch from bug, but it's not final\nintrepid+ compiler hardening reduces this to a denial of\nservice. Can't reproduce issue on Hardy. Setting to \"low\".\nseems we don't carry the patch that Debian is carrying for this."},{"author":"jdstrand","note":"pdftoabw was removed in 0.18"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3938"],"bugs":["http://bugs.freedesktop.org/show_bug.cgi?id=23074","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534680"],"patches":{"poppler":[]},"tags":{"poppler_intrepid":["stack-protector"],"poppler_jaunty":["stack-protector"],"poppler_karmic":["stack-protector"],"poppler_lucid":["stack-protector"],"poppler_maverick":["stack-protector"],"poppler_natty":["stack-protector"],"poppler_oneiric":["stack-protector"]},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.14.3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.14.3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.12.2-2.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2841","published":"2009-11-13T15:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in\nWebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on\nMac OS X, does not perform the expected callbacks for HTML 5 media elements\nthat have external URLs for media resources, which allows remote attackers\nto trigger sub-resource requests to arbitrary web sites via a crafted HTML\ndocument, as demonstrated by an HTML e-mail message that uses a media\nelement for X-Confirm-Reading-To functionality, aka rdar problem 7271202.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2009-2841"],"bugs":[""],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/49480"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"4:4.6.2-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"4:4.7.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4:4.7.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.0-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2816","published":"2009-11-13T15:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as\nused in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33,\nincludes certain custom HTTP headers in the OPTIONS request during\ncross-origin operations with preflight, which makes it easier for remote\nattackers to conduct cross-site request forgery (CSRF) attacks via a\ncrafted web page.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2816"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=28446","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559759","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-2816"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/47494"],"qt4-x11":[]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"4:4.6.2-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"4:4.7.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4:4.7.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.1.15.2-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.0-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1570","published":"2009-11-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c\nin GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a\nBMP file with crafted width and height values that trigger a heap-based\nbuffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-880-1","https://www.cve.org/CVERecord?id=CVE-2009-1570"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=555929","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-1570"],"patches":{"gimp":["upstream: http://git.gnome.org/cgit/gimp/commit/?id=e3afc99b2fa7aeddf0dba4778663160a5bc682d3","upstream: http://git.gnome.org/cgit/gimp/commit/?id=43d57c666346320436a0b668de5525387952784e","upstream: http://git.gnome.org/cgit/gimp/commit/?id=f63ba36dd9cc01ca6da83fa05ddd12419ad8953e","upstream: http://git.gnome.org/cgit/gimp/commit/?id=16e6a37687bb4b9748c5a5d166d90f5d5bd2e9f3","vendor: https://bugzilla.redhat.com/attachment.cgi?id=374812"]},"tags":{},"packages":[{"name":"gimp","source":"https://ubuntu.com/security/cve?package=gimp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gimp","debian":"https://tracker.debian.org/pkg/gimp","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.4.5-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.1-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.6-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.7-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-880-1"],"notices":[{"id":"USN-880-1","title":"GIMP vulnerabilities","summary":"GIMP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-01-07T15:34:01.379734","description":"Stefan Cornelius discovered that GIMP did not correctly handle certain\nmalformed BMP files. If a user were tricked into opening a specially\ncrafted BMP file, an attacker could execute arbitrary code with the user's\nprivileges. (CVE-2009-1570)\n\nStefan Cornelius discovered that GIMP did not correctly handle certain\nmalformed PSD files. If a user were tricked into opening a specially\ncrafted PSD file, an attacker could execute arbitrary code with the user's\nprivileges. This issue only applied to Ubuntu 8.10, 9.04 and 9.10.\n(CVE-2009-3909)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"gimp","version":"2.4.5-1ubuntu2.1","description":"","is_source":true},{"name":"gimp","version":"2.4.5-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gimp","version_link":"https://launchpad.net/ubuntu/+source/gimp/2.4.5-1ubuntu2.1"}],"intrepid":[{"name":"gimp","version":"2.6.1-1ubuntu3.1","description":"","is_source":true},{"name":"gimp","version":"2.6.1-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gimp","version_link":"https://launchpad.net/ubuntu/+source/gimp/2.6.1-1ubuntu3.1"}],"jaunty":[{"name":"gimp","version":"2.6.6-0ubuntu1.1","description":"","is_source":true},{"name":"gimp","version":"2.6.6-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gimp","version_link":"https://launchpad.net/ubuntu/+source/gimp/2.6.6-0ubuntu1.1"}],"karmic":[{"name":"gimp","version":"2.6.7-1ubuntu1.1","description":"","is_source":true},{"name":"gimp","version":"2.6.7-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gimp","version_link":"https://launchpad.net/ubuntu/+source/gimp/2.6.7-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2009-3909","CVE-2009-1570"]}]},{"id":"CVE-2009-3933","published":"2009-11-12T17:54:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit before r50173, as used in Google Chrome before 3.0.195.32, allows\nremote attackers to cause a denial of service (CPU consumption) via a web\npage that calls the JavaScript setInterval method, which triggers an\nincompatibility between the WTF::currentTime and base::Time functions.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit"},{"author":"mdeslaur","note":"this is chromium-specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3933"],"bugs":[""],"patches":{"webkit":[],"kdelibs":[],"kde4libs":[],"qt4-x11":[]},"tags":{},"packages":[{"name":"kde4libs","source":"https://ubuntu.com/security/cve?package=kde4libs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kde4libs","debian":"https://tracker.debian.org/pkg/kde4libs","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"kdelibs","source":"https://ubuntu.com/security/cve?package=kdelibs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdelibs","debian":"https://tracker.debian.org/pkg/kdelibs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3930","published":"2009-11-10T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in Christos Zoulas file before 5.02 allow\nuser-assisted remote attackers to have an unspecified impact via a\nmalformed compound document (aka cdf) file that triggers a buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3930"],"bugs":[""],"patches":{"file":[]},"tags":{},"packages":[{"name":"file","source":"https://ubuntu.com/security/cve?package=file","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=file","debian":"https://tracker.debian.org/pkg/file","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.02","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2830","published":"2009-11-10T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac\nOS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute\narbitrary code or cause a denial of service (application crash) via a\ncrafted Common Document Format (CDF) file. NOTE: this might overlap\nCVE-2009-1515.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2830"],"bugs":[""],"patches":{"file":[]},"tags":{},"packages":[{"name":"file","source":"https://ubuntu.com/security/cve?package=file","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=file","debian":"https://tracker.debian.org/pkg/file","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.03","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3727","published":"2009-11-10T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAsterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x\nbefore 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x\nbefore B.2.5.12, C.2.x.x before C.2.4.5, and C.3.x.x before C.3.2.2;\nAsteriskNOW 1.5; and s800i 1.3.x before 1.3.0.5 generate different error\nmessages depending on whether a SIP username is valid, which allows remote\nattackers to enumerate valid usernames via multiple crafted REGISTER\nmessages with inconsistent usernames in the URI in the To header and the\nDigest in the Authorization header.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://downloads.asterisk.org/pub/security/AST-2009-008.html","https://www.cve.org/CVERecord?id=CVE-2009-3727"],"bugs":["https://bugs.launchpad.net/ubuntu/karmic/+source/asterisk/+bug/491637"],"patches":{"asterisk":["upstream: http://downloads.digium.com/pub/asa/AST-2009-008-1.4.diff.txt","debdiff: https://bugs.launchpad.net/ubuntu/karmic/+source/asterisk/+bug/491632"]},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:1.6.2.0~rc2-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1:1.6.2.0~rc2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1:1.6.2.0~rc2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1:1.6.2.0~rc2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.0.17","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3619","published":"2009-11-10T02:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2\nhas unknown impact and remote attack vectors related to \"printing illegal\nparameter names and values.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3619"],"bugs":[""],"patches":{"viewvc":[]},"tags":{},"packages":[{"name":"viewvc","source":"https://ubuntu.com/security/cve?package=viewvc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=viewvc","debian":"https://tracker.debian.org/pkg/viewvc","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.0.9-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.0.9-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.0.9-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.0.9-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3618","published":"2009-11-10T02:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before\n1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbitrary web\nscript or HTML via the view parameter. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3618"],"bugs":[""],"patches":{"viewvc":[]},"tags":{},"packages":[{"name":"viewvc","source":"https://ubuntu.com/security/cve?package=viewvc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=viewvc","debian":"https://tracker.debian.org/pkg/viewvc","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.0.9-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.0.9-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.0.9-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.0.9-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3886","published":"2009-11-09T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Java Web Start implementation in Sun Java SE 6 before Update 17 does\nnot properly handle the interaction between a signed JAR file and a JNLP\n(1) application or (2) applet, which has unspecified impact and attack\nvectors, related to a \"regression,\" aka Bug Id 6870531.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3886"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[]},"tags":{},"packages":[{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.20dlj-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.17","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3729","published":"2009-11-09T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the TrueType font parsing functionality in Sun\nJava SE 5.0 before Update 22 and 6 before Update 17 allows remote attackers\nto cause a denial of service (application crash) via a certain test suite,\naka Bug Id 6815780.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3729"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[]},"tags":{},"packages":[{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-22","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.20dlj-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.17","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3885","published":"2009-11-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows\nremote attackers to cause a denial of service via a BMP file containing a\nlink to a UNC share pathname for an International Color Consortium (ICC)\nprofile file, probably a related issue to CVE-2007-2789, aka Bug Id\n6632445.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-859-1","https://www.cve.org/CVERecord?id=CVE-2009-3885"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu12","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6b16-1.6.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b17","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-22","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.20dlj-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-859-1"],"notices":[{"id":"USN-859-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-11-12T22:06:57.164261","description":"Dan Kaminsky discovered that SSL certificates signed with MD2 could be\nspoofed given enough time. As a result, an attacker could potentially\ncreate a malicious trusted certificate to impersonate another site. This\nupdate handles this issue by completely disabling MD2 for certificate\nvalidation in OpenJDK. (CVE-2009-2409)\n\nIt was discovered that ICC profiles could be identified with\n\"..\" pathnames. If a user were tricked into running a specially\ncrafted applet, a remote attacker could gain information about a local\nsystem. (CVE-2009-3728)\n\nPeter Vreugdenhil discovered multiple flaws in the processing of graphics\nin the AWT library. If a user were tricked into running a specially\ncrafted applet, a remote attacker could crash the application or run\narbitrary code with user privileges. (CVE-2009-3869, CVE-2009-3871)\n\nMultiple flaws were discovered in JPEG and BMP image handling. If a user\nwere tricked into loading a specially crafted image, a remote attacker\ncould crash the application or run arbitrary code with user privileges.\n(CVE-2009-3873, CVE-2009-3874, CVE-2009-3885)\n\nCoda Hale discovered that HMAC-based signatures were not correctly\nvalidated. Remote attackers could bypass certain forms of authentication,\ngranting unexpected access. (CVE-2009-3875)\n\nMultiple flaws were discovered in ASN.1 parsing. A remote attacker\ncould send a specially crafted HTTP stream that would exhaust system\nmemory and lead to a denial of service. (CVE-2009-3876, CVE-2009-3877)\n\nIt was discovered that the graphics configuration subsystem did\nnot correctly handle arrays. If a user were tricked into running\na specially crafted applet, a remote attacker could exploit this\nto crash the application or execute arbitrary code with user\nprivileges. (CVE-2009-3879)\n\nIt was discovered that loggers and Swing did not correctly handle\ncertain sensitive objects. If a user were tricked into running a\nspecially crafted applet, private information could be leaked to a remote\nattacker, leading to a loss of privacy. (CVE-2009-3880, CVE-2009-3882,\nCVE-2009-3883)\n\nIt was discovered that the ClassLoader did not correctly handle certain\noptions. If a user were tricked into running a specially crafted\napplet, a remote attacker could execute arbitrary code with user\nprivileges. (CVE-2009-3881)\n\nIt was discovered that time zone file loading could be used to determine\nthe existence of files on the local system. If a user were tricked into\nrunning a specially crafted applet, private information could be leaked\nto a remote attacker, leading to a loss of privacy. (CVE-2009-3884)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.6","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu12","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"}],"karmic":[{"name":"openjdk-6","version":"6b16-1.6.1-3ubuntu1","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"},{"name":"openjdk-6-jre","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"}]},"type":"USN","cves_ids":["CVE-2009-3728","CVE-2009-3883","CVE-2009-3884","CVE-2009-3877","CVE-2009-3880","CVE-2009-3881","CVE-2009-3879","CVE-2009-3874","CVE-2009-3871","CVE-2009-3873","CVE-2009-3876","CVE-2009-3882","CVE-2009-3885","CVE-2009-3875","CVE-2009-3869","CVE-2009-2409"]}]},{"id":"CVE-2009-3884","published":"2009-11-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6\nbefore Update 17, and OpenJDK, allows remote attackers to determine the\nexistence of local files via vectors related to handling of zoneinfo (aka\ntz) files, aka Bug Id 6824265.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-859-1","https://www.cve.org/CVERecord?id=CVE-2009-3884"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu12","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6b16-1.6.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b17","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-22","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.20dlj-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-859-1"],"notices":[{"id":"USN-859-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-11-12T22:06:57.164261","description":"Dan Kaminsky discovered that SSL certificates signed with MD2 could be\nspoofed given enough time. As a result, an attacker could potentially\ncreate a malicious trusted certificate to impersonate another site. This\nupdate handles this issue by completely disabling MD2 for certificate\nvalidation in OpenJDK. (CVE-2009-2409)\n\nIt was discovered that ICC profiles could be identified with\n\"..\" pathnames. If a user were tricked into running a specially\ncrafted applet, a remote attacker could gain information about a local\nsystem. (CVE-2009-3728)\n\nPeter Vreugdenhil discovered multiple flaws in the processing of graphics\nin the AWT library. If a user were tricked into running a specially\ncrafted applet, a remote attacker could crash the application or run\narbitrary code with user privileges. (CVE-2009-3869, CVE-2009-3871)\n\nMultiple flaws were discovered in JPEG and BMP image handling. If a user\nwere tricked into loading a specially crafted image, a remote attacker\ncould crash the application or run arbitrary code with user privileges.\n(CVE-2009-3873, CVE-2009-3874, CVE-2009-3885)\n\nCoda Hale discovered that HMAC-based signatures were not correctly\nvalidated. Remote attackers could bypass certain forms of authentication,\ngranting unexpected access. (CVE-2009-3875)\n\nMultiple flaws were discovered in ASN.1 parsing. A remote attacker\ncould send a specially crafted HTTP stream that would exhaust system\nmemory and lead to a denial of service. (CVE-2009-3876, CVE-2009-3877)\n\nIt was discovered that the graphics configuration subsystem did\nnot correctly handle arrays. If a user were tricked into running\na specially crafted applet, a remote attacker could exploit this\nto crash the application or execute arbitrary code with user\nprivileges. (CVE-2009-3879)\n\nIt was discovered that loggers and Swing did not correctly handle\ncertain sensitive objects. If a user were tricked into running a\nspecially crafted applet, private information could be leaked to a remote\nattacker, leading to a loss of privacy. (CVE-2009-3880, CVE-2009-3882,\nCVE-2009-3883)\n\nIt was discovered that the ClassLoader did not correctly handle certain\noptions. If a user were tricked into running a specially crafted\napplet, a remote attacker could execute arbitrary code with user\nprivileges. (CVE-2009-3881)\n\nIt was discovered that time zone file loading could be used to determine\nthe existence of files on the local system. If a user were tricked into\nrunning a specially crafted applet, private information could be leaked\nto a remote attacker, leading to a loss of privacy. (CVE-2009-3884)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.6","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu12","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"}],"karmic":[{"name":"openjdk-6","version":"6b16-1.6.1-3ubuntu1","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"},{"name":"openjdk-6-jre","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"}]},"type":"USN","cves_ids":["CVE-2009-3728","CVE-2009-3883","CVE-2009-3884","CVE-2009-3877","CVE-2009-3880","CVE-2009-3881","CVE-2009-3879","CVE-2009-3874","CVE-2009-3871","CVE-2009-3873","CVE-2009-3876","CVE-2009-3882","CVE-2009-3885","CVE-2009-3875","CVE-2009-3869","CVE-2009-2409"]}]},{"id":"CVE-2009-3883","published":"2009-11-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the Windows Pluggable Look and Feel\n(PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update\n22 and 6 before Update 17, and OpenJDK, have unknown impact and remote\nattack vectors, related to \"information leaks in mutable variables,\" aka\nBug Id 6657138.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-859-1","https://www.cve.org/CVERecord?id=CVE-2009-3883"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu12","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6b16-1.6.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b17","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-22","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.20dlj-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-859-1"],"notices":[{"id":"USN-859-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-11-12T22:06:57.164261","description":"Dan Kaminsky discovered that SSL certificates signed with MD2 could be\nspoofed given enough time. As a result, an attacker could potentially\ncreate a malicious trusted certificate to impersonate another site. This\nupdate handles this issue by completely disabling MD2 for certificate\nvalidation in OpenJDK. (CVE-2009-2409)\n\nIt was discovered that ICC profiles could be identified with\n\"..\" pathnames. If a user were tricked into running a specially\ncrafted applet, a remote attacker could gain information about a local\nsystem. (CVE-2009-3728)\n\nPeter Vreugdenhil discovered multiple flaws in the processing of graphics\nin the AWT library. If a user were tricked into running a specially\ncrafted applet, a remote attacker could crash the application or run\narbitrary code with user privileges. (CVE-2009-3869, CVE-2009-3871)\n\nMultiple flaws were discovered in JPEG and BMP image handling. If a user\nwere tricked into loading a specially crafted image, a remote attacker\ncould crash the application or run arbitrary code with user privileges.\n(CVE-2009-3873, CVE-2009-3874, CVE-2009-3885)\n\nCoda Hale discovered that HMAC-based signatures were not correctly\nvalidated. Remote attackers could bypass certain forms of authentication,\ngranting unexpected access. (CVE-2009-3875)\n\nMultiple flaws were discovered in ASN.1 parsing. A remote attacker\ncould send a specially crafted HTTP stream that would exhaust system\nmemory and lead to a denial of service. (CVE-2009-3876, CVE-2009-3877)\n\nIt was discovered that the graphics configuration subsystem did\nnot correctly handle arrays. If a user were tricked into running\na specially crafted applet, a remote attacker could exploit this\nto crash the application or execute arbitrary code with user\nprivileges. (CVE-2009-3879)\n\nIt was discovered that loggers and Swing did not correctly handle\ncertain sensitive objects. If a user were tricked into running a\nspecially crafted applet, private information could be leaked to a remote\nattacker, leading to a loss of privacy. (CVE-2009-3880, CVE-2009-3882,\nCVE-2009-3883)\n\nIt was discovered that the ClassLoader did not correctly handle certain\noptions. If a user were tricked into running a specially crafted\napplet, a remote attacker could execute arbitrary code with user\nprivileges. (CVE-2009-3881)\n\nIt was discovered that time zone file loading could be used to determine\nthe existence of files on the local system. If a user were tricked into\nrunning a specially crafted applet, private information could be leaked\nto a remote attacker, leading to a loss of privacy. (CVE-2009-3884)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.6","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu12","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"}],"karmic":[{"name":"openjdk-6","version":"6b16-1.6.1-3ubuntu1","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"},{"name":"openjdk-6-jre","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"}]},"type":"USN","cves_ids":["CVE-2009-3728","CVE-2009-3883","CVE-2009-3884","CVE-2009-3877","CVE-2009-3880","CVE-2009-3881","CVE-2009-3879","CVE-2009-3874","CVE-2009-3871","CVE-2009-3873","CVE-2009-3876","CVE-2009-3882","CVE-2009-3885","CVE-2009-3875","CVE-2009-3869","CVE-2009-2409"]}]},{"id":"CVE-2009-3882","published":"2009-11-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the Swing implementation in Sun\nJava SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have\nunknown impact and remote attack vectors, related to \"information leaks in\nmutable variables,\" aka Bug Id 6657026.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-859-1","https://www.cve.org/CVERecord?id=CVE-2009-3882"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu12","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6b16-1.6.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b17","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-22","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.20dlj-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-859-1"],"notices":[{"id":"USN-859-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-11-12T22:06:57.164261","description":"Dan Kaminsky discovered that SSL certificates signed with MD2 could be\nspoofed given enough time. As a result, an attacker could potentially\ncreate a malicious trusted certificate to impersonate another site. This\nupdate handles this issue by completely disabling MD2 for certificate\nvalidation in OpenJDK. (CVE-2009-2409)\n\nIt was discovered that ICC profiles could be identified with\n\"..\" pathnames. If a user were tricked into running a specially\ncrafted applet, a remote attacker could gain information about a local\nsystem. (CVE-2009-3728)\n\nPeter Vreugdenhil discovered multiple flaws in the processing of graphics\nin the AWT library. If a user were tricked into running a specially\ncrafted applet, a remote attacker could crash the application or run\narbitrary code with user privileges. (CVE-2009-3869, CVE-2009-3871)\n\nMultiple flaws were discovered in JPEG and BMP image handling. If a user\nwere tricked into loading a specially crafted image, a remote attacker\ncould crash the application or run arbitrary code with user privileges.\n(CVE-2009-3873, CVE-2009-3874, CVE-2009-3885)\n\nCoda Hale discovered that HMAC-based signatures were not correctly\nvalidated. Remote attackers could bypass certain forms of authentication,\ngranting unexpected access. (CVE-2009-3875)\n\nMultiple flaws were discovered in ASN.1 parsing. A remote attacker\ncould send a specially crafted HTTP stream that would exhaust system\nmemory and lead to a denial of service. (CVE-2009-3876, CVE-2009-3877)\n\nIt was discovered that the graphics configuration subsystem did\nnot correctly handle arrays. If a user were tricked into running\na specially crafted applet, a remote attacker could exploit this\nto crash the application or execute arbitrary code with user\nprivileges. (CVE-2009-3879)\n\nIt was discovered that loggers and Swing did not correctly handle\ncertain sensitive objects. If a user were tricked into running a\nspecially crafted applet, private information could be leaked to a remote\nattacker, leading to a loss of privacy. (CVE-2009-3880, CVE-2009-3882,\nCVE-2009-3883)\n\nIt was discovered that the ClassLoader did not correctly handle certain\noptions. If a user were tricked into running a specially crafted\napplet, a remote attacker could execute arbitrary code with user\nprivileges. (CVE-2009-3881)\n\nIt was discovered that time zone file loading could be used to determine\nthe existence of files on the local system. If a user were tricked into\nrunning a specially crafted applet, private information could be leaked\nto a remote attacker, leading to a loss of privacy. (CVE-2009-3884)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.6","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu12","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"}],"karmic":[{"name":"openjdk-6","version":"6b16-1.6.1-3ubuntu1","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"},{"name":"openjdk-6-jre","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"}]},"type":"USN","cves_ids":["CVE-2009-3728","CVE-2009-3883","CVE-2009-3884","CVE-2009-3877","CVE-2009-3880","CVE-2009-3881","CVE-2009-3879","CVE-2009-3874","CVE-2009-3871","CVE-2009-3873","CVE-2009-3876","CVE-2009-3882","CVE-2009-3885","CVE-2009-3875","CVE-2009-3869","CVE-2009-2409"]}]},{"id":"CVE-2009-3881","published":"2009-11-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does\nnot prevent the existence of children of a resurrected ClassLoader, which\nallows remote attackers to gain privileges via unspecified vectors, related\nto an \"information leak vulnerability,\" aka Bug Id 6636650.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-859-1","https://www.cve.org/CVERecord?id=CVE-2009-3881"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu12","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6b16-1.6.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b17","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-22","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.20dlj-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-859-1"],"notices":[{"id":"USN-859-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-11-12T22:06:57.164261","description":"Dan Kaminsky discovered that SSL certificates signed with MD2 could be\nspoofed given enough time. As a result, an attacker could potentially\ncreate a malicious trusted certificate to impersonate another site. This\nupdate handles this issue by completely disabling MD2 for certificate\nvalidation in OpenJDK. (CVE-2009-2409)\n\nIt was discovered that ICC profiles could be identified with\n\"..\" pathnames. If a user were tricked into running a specially\ncrafted applet, a remote attacker could gain information about a local\nsystem. (CVE-2009-3728)\n\nPeter Vreugdenhil discovered multiple flaws in the processing of graphics\nin the AWT library. If a user were tricked into running a specially\ncrafted applet, a remote attacker could crash the application or run\narbitrary code with user privileges. (CVE-2009-3869, CVE-2009-3871)\n\nMultiple flaws were discovered in JPEG and BMP image handling. If a user\nwere tricked into loading a specially crafted image, a remote attacker\ncould crash the application or run arbitrary code with user privileges.\n(CVE-2009-3873, CVE-2009-3874, CVE-2009-3885)\n\nCoda Hale discovered that HMAC-based signatures were not correctly\nvalidated. Remote attackers could bypass certain forms of authentication,\ngranting unexpected access. (CVE-2009-3875)\n\nMultiple flaws were discovered in ASN.1 parsing. A remote attacker\ncould send a specially crafted HTTP stream that would exhaust system\nmemory and lead to a denial of service. (CVE-2009-3876, CVE-2009-3877)\n\nIt was discovered that the graphics configuration subsystem did\nnot correctly handle arrays. If a user were tricked into running\na specially crafted applet, a remote attacker could exploit this\nto crash the application or execute arbitrary code with user\nprivileges. (CVE-2009-3879)\n\nIt was discovered that loggers and Swing did not correctly handle\ncertain sensitive objects. If a user were tricked into running a\nspecially crafted applet, private information could be leaked to a remote\nattacker, leading to a loss of privacy. (CVE-2009-3880, CVE-2009-3882,\nCVE-2009-3883)\n\nIt was discovered that the ClassLoader did not correctly handle certain\noptions. If a user were tricked into running a specially crafted\napplet, a remote attacker could execute arbitrary code with user\nprivileges. (CVE-2009-3881)\n\nIt was discovered that time zone file loading could be used to determine\nthe existence of files on the local system. If a user were tricked into\nrunning a specially crafted applet, private information could be leaked\nto a remote attacker, leading to a loss of privacy. (CVE-2009-3884)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.6","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu12","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"}],"karmic":[{"name":"openjdk-6","version":"6b16-1.6.1-3ubuntu1","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"},{"name":"openjdk-6-jre","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"}]},"type":"USN","cves_ids":["CVE-2009-3728","CVE-2009-3883","CVE-2009-3884","CVE-2009-3877","CVE-2009-3880","CVE-2009-3881","CVE-2009-3879","CVE-2009-3874","CVE-2009-3871","CVE-2009-3873","CVE-2009-3876","CVE-2009-3882","CVE-2009-3885","CVE-2009-3875","CVE-2009-3869","CVE-2009-2409"]}]},{"id":"CVE-2009-3880","published":"2009-11-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun\nJava SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not\nproperly restrict the objects that may be sent to loggers, which allows\nattackers to obtain sensitive information via vectors related to the\nimplementation of Component, KeyboardFocusManager, and\nDefaultKeyboardFocusManager, aka Bug Id 6664512.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-859-1","https://www.cve.org/CVERecord?id=CVE-2009-3880"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu12","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6b16-1.6.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b17","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-22","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.20dlj-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-859-1"],"notices":[{"id":"USN-859-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-11-12T22:06:57.164261","description":"Dan Kaminsky discovered that SSL certificates signed with MD2 could be\nspoofed given enough time. As a result, an attacker could potentially\ncreate a malicious trusted certificate to impersonate another site. This\nupdate handles this issue by completely disabling MD2 for certificate\nvalidation in OpenJDK. (CVE-2009-2409)\n\nIt was discovered that ICC profiles could be identified with\n\"..\" pathnames. If a user were tricked into running a specially\ncrafted applet, a remote attacker could gain information about a local\nsystem. (CVE-2009-3728)\n\nPeter Vreugdenhil discovered multiple flaws in the processing of graphics\nin the AWT library. If a user were tricked into running a specially\ncrafted applet, a remote attacker could crash the application or run\narbitrary code with user privileges. (CVE-2009-3869, CVE-2009-3871)\n\nMultiple flaws were discovered in JPEG and BMP image handling. If a user\nwere tricked into loading a specially crafted image, a remote attacker\ncould crash the application or run arbitrary code with user privileges.\n(CVE-2009-3873, CVE-2009-3874, CVE-2009-3885)\n\nCoda Hale discovered that HMAC-based signatures were not correctly\nvalidated. Remote attackers could bypass certain forms of authentication,\ngranting unexpected access. (CVE-2009-3875)\n\nMultiple flaws were discovered in ASN.1 parsing. A remote attacker\ncould send a specially crafted HTTP stream that would exhaust system\nmemory and lead to a denial of service. (CVE-2009-3876, CVE-2009-3877)\n\nIt was discovered that the graphics configuration subsystem did\nnot correctly handle arrays. If a user were tricked into running\na specially crafted applet, a remote attacker could exploit this\nto crash the application or execute arbitrary code with user\nprivileges. (CVE-2009-3879)\n\nIt was discovered that loggers and Swing did not correctly handle\ncertain sensitive objects. If a user were tricked into running a\nspecially crafted applet, private information could be leaked to a remote\nattacker, leading to a loss of privacy. (CVE-2009-3880, CVE-2009-3882,\nCVE-2009-3883)\n\nIt was discovered that the ClassLoader did not correctly handle certain\noptions. If a user were tricked into running a specially crafted\napplet, a remote attacker could execute arbitrary code with user\nprivileges. (CVE-2009-3881)\n\nIt was discovered that time zone file loading could be used to determine\nthe existence of files on the local system. If a user were tricked into\nrunning a specially crafted applet, private information could be leaked\nto a remote attacker, leading to a loss of privacy. (CVE-2009-3884)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.6","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu12","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"}],"karmic":[{"name":"openjdk-6","version":"6b16-1.6.1-3ubuntu1","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"},{"name":"openjdk-6-jre","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"}]},"type":"USN","cves_ids":["CVE-2009-3728","CVE-2009-3883","CVE-2009-3884","CVE-2009-3877","CVE-2009-3880","CVE-2009-3881","CVE-2009-3879","CVE-2009-3874","CVE-2009-3871","CVE-2009-3873","CVE-2009-3876","CVE-2009-3882","CVE-2009-3885","CVE-2009-3875","CVE-2009-3869","CVE-2009-2409"]}]},{"id":"CVE-2009-3879","published":"2009-11-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the (1) X11 and (2)\nWin32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6\nbefore Update 17, and OpenJDK, have unknown impact and attack vectors,\nrelated to failure to clone arrays that are returned by the\ngetConfigurations function, aka Bug Id 6822057.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-859-1","https://www.cve.org/CVERecord?id=CVE-2009-3879"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu12","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6b16-1.6.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b17~pre2-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b17","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-22","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.20dlj-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-859-1"],"notices":[{"id":"USN-859-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-11-12T22:06:57.164261","description":"Dan Kaminsky discovered that SSL certificates signed with MD2 could be\nspoofed given enough time. As a result, an attacker could potentially\ncreate a malicious trusted certificate to impersonate another site. This\nupdate handles this issue by completely disabling MD2 for certificate\nvalidation in OpenJDK. (CVE-2009-2409)\n\nIt was discovered that ICC profiles could be identified with\n\"..\" pathnames. If a user were tricked into running a specially\ncrafted applet, a remote attacker could gain information about a local\nsystem. (CVE-2009-3728)\n\nPeter Vreugdenhil discovered multiple flaws in the processing of graphics\nin the AWT library. If a user were tricked into running a specially\ncrafted applet, a remote attacker could crash the application or run\narbitrary code with user privileges. (CVE-2009-3869, CVE-2009-3871)\n\nMultiple flaws were discovered in JPEG and BMP image handling. If a user\nwere tricked into loading a specially crafted image, a remote attacker\ncould crash the application or run arbitrary code with user privileges.\n(CVE-2009-3873, CVE-2009-3874, CVE-2009-3885)\n\nCoda Hale discovered that HMAC-based signatures were not correctly\nvalidated. Remote attackers could bypass certain forms of authentication,\ngranting unexpected access. (CVE-2009-3875)\n\nMultiple flaws were discovered in ASN.1 parsing. A remote attacker\ncould send a specially crafted HTTP stream that would exhaust system\nmemory and lead to a denial of service. (CVE-2009-3876, CVE-2009-3877)\n\nIt was discovered that the graphics configuration subsystem did\nnot correctly handle arrays. If a user were tricked into running\na specially crafted applet, a remote attacker could exploit this\nto crash the application or execute arbitrary code with user\nprivileges. (CVE-2009-3879)\n\nIt was discovered that loggers and Swing did not correctly handle\ncertain sensitive objects. If a user were tricked into running a\nspecially crafted applet, private information could be leaked to a remote\nattacker, leading to a loss of privacy. (CVE-2009-3880, CVE-2009-3882,\nCVE-2009-3883)\n\nIt was discovered that the ClassLoader did not correctly handle certain\noptions. If a user were tricked into running a specially crafted\napplet, a remote attacker could execute arbitrary code with user\nprivileges. (CVE-2009-3881)\n\nIt was discovered that time zone file loading could be used to determine\nthe existence of files on the local system. If a user were tricked into\nrunning a specially crafted applet, private information could be leaked\nto a remote attacker, leading to a loss of privacy. (CVE-2009-3884)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.6","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.6"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu12","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu12"}],"karmic":[{"name":"openjdk-6","version":"6b16-1.6.1-3ubuntu1","description":"","is_source":true},{"name":"icedtea6-plugin","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"},{"name":"openjdk-6-jre","version":"6b16-1.6.1-3ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b16-1.6.1-3ubuntu1"}]},"type":"USN","cves_ids":["CVE-2009-3728","CVE-2009-3883","CVE-2009-3884","CVE-2009-3877","CVE-2009-3880","CVE-2009-3881","CVE-2009-3879","CVE-2009-3874","CVE-2009-3871","CVE-2009-3873","CVE-2009-3876","CVE-2009-3882","CVE-2009-3885","CVE-2009-3875","CVE-2009-3869","CVE-2009-2409"]}]}],"offset":73500,"limit":20,"total_results":79316}