{"cves":[{"id":"CVE-2009-2989","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and\npossibly 7.x through 7.1.4 might allow attackers to execute arbitrary code\nvia unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2989"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2988","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before\n9.2 do not properly validate input, which allows attackers to cause a\ndenial of service via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2988"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2986","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple heap-based buffer overflows in Adobe Reader and Acrobat 7.x before\n7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to\nexecute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2986"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2985","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before\n9.2 allow attackers to cause a denial of service (memory corruption) or\npossibly execute arbitrary code via unspecified vectors, a different\nvulnerability than CVE-2009-2996.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2985"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2984","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the image decoder in Adobe Acrobat 9.x before\n9.2, and possibly 7.x through 7.1.4 and 8.x through 8.1.7, allows attackers\nto cause a denial of service or possibly execute arbitrary code via unknown\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2984"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2983","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x\nthrough 7.1.4 allow attackers to cause a denial of service (memory\ncorruption) or possibly execute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2983"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2982","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAn unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x\nbefore 8.1.7, and possibly 7.x through 7.1.4 might allow remote attackers\nto conduct a \"social engineering attack\" via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2982"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2981","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before\n9.2 do not properly validate input, which might allow attackers to bypass\nintended Trust Manager restrictions via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2981"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2980","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before\n8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service or\npossibly execute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2980"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2979","published":"2009-10-19T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x\nthrough 7.1.4 do not properly perform XMP-XML entity expansion, which\nallows remote attackers to cause a denial of service via a crafted\ndocument.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2979"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-4881","published":"2009-10-19T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe netlink subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x\nbefore 2.6.13-rc1 does not initialize certain padding fields in structures,\nwhich might allow local users to obtain sensitive information from kernel\nmemory via unspecified vectors, related to the (1) tc_fill_qdisc, (2)\ntcf_fill_node, (3) neightbl_fill_info, (4) neightbl_fill_param_info, (5)\nneigh_fill_info, (6) rtnetlink_fill_ifinfo, (7) rtnetlink_fill_iwinfo, (8)\nvif_delete, (9) ipmr_destroy_unres, (10) ipmr_cache_alloc_unres, (11)\nipmr_cache_resolve, (12) inet6_fill_ifinfo, (13) tca_get_fill, (14)\ntca_action_flush, (15) tcf_add_notify, (16) tc_dump_action, (17)\ncbq_dump_police, (18) __nlmsg_put, (19) __rta_fill, (20) __rta_reserve,\n(21) inet6_fill_prefix, (22) rsvp_dump, and (23) cbq_dump_ovl functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-4881"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3613","published":"2009-10-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the\nLinux kernel before 2.6.27.22 allows remote attackers to cause a denial of\nservice (IOMMU space exhaustion and system crash) by using jumbo frames for\na large amount of network traffic, as demonstrated by a flood ping.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-864-1","https://www.cve.org/CVERecord?id=CVE-2009-3613"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=97d477a914b146e7e6722ded21afa79886ae8ccd"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-26.64","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-16.44","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-17.58","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.29","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.81","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.29","component":null,"pocket":"security"}]}],"notices_ids":["USN-864-1"],"notices":[{"id":"USN-864-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2009-12-05T01:52:13.000003","description":"It was discovered that the AX.25 network subsystem did not correctly\ncheck integer signedness in certain setsockopt calls.  A local attacker\ncould exploit this to crash the system, leading to a denial of service.\nUbuntu 9.10 was not affected. (CVE-2009-2909)\n\nJan Beulich discovered that the kernel could leak register contents to\n32-bit processes that were switched to 64-bit mode.  A local attacker\ncould run a specially crafted binary to read register values from an\nearlier process, leading to a loss of privacy. (CVE-2009-2910)\n\nDave Jones discovered that the gdth SCSI driver did not correctly validate\narray indexes in certain ioctl calls.  A local attacker could exploit\nthis to crash the system or gain elevated privileges.  (CVE-2009-3080)\n\nEric Dumazet and Jiri Pirko discovered that the TC and CLS subsystems\nwould leak kernel memory via uninitialized structure members.  A local\nattacker could exploit this to read several bytes of kernel memory,\nleading to a loss of privacy. (CVE-2009-3228, CVE-2009-3612)\n\nEarl Chew discovered race conditions in pipe handling.  A local attacker\ncould exploit anonymous pipes via /proc/*/fd/ and crash the system or\ngain root privileges. (CVE-2009-3547)\n\nDave Jones and Francois Romieu discovered that the r8169 network driver\ncould be made to leak kernel memory.  A remote attacker could send a large\nnumber of jumbo frames until the system memory was exhausted, leading\nto a denial of service. Ubuntu 9.10 was not affected. (CVE-2009-3613).\n\nBen Hutchings discovered that the ATI Rage 128 video driver did not\ncorrectly validate initialization states.  A local attacker could\nmake specially crafted ioctl calls to crash the system or gain root\nprivileges. (CVE-2009-3620)\n\nTomoki Sekiyama discovered that Unix sockets did not correctly verify\nnamespaces.  A local attacker could exploit this to cause a system hang,\nleading to a denial of service. (CVE-2009-3621)\n\nJ. Bruce Fields discovered that NFSv4 did not correctly use the credential\ncache.  A local attacker using a mount with AUTH_NULL authentication\ncould exploit this to crash the system or gain root privileges. Only\nUbuntu 9.10 was affected. (CVE-2009-3623)\n\nAlexander Zangerl discovered that the kernel keyring did not correctly\nreference count.  A local attacker could issue a series of specially\ncrafted keyring calls to crash the system or gain root privileges.\nOnly Ubuntu 9.10 was affected. (CVE-2009-3624)\n\nDavid Wagner discovered that KVM did not correctly bounds-check CPUID\nentries.  A local attacker could exploit this to crash the system\nor possibly gain elevated privileges. Ubuntu 6.06 and 9.10 were not\naffected. (CVE-2009-3638)\n\nAvi Kivity discovered that KVM did not correctly check privileges when\naccessing debug registers.  A local attacker could exploit this to\ncrash a host system from within a guest system, leading to a denial of\nservice. Ubuntu 6.06 and 9.10 were not affected. (CVE-2009-3722)\n\nPhilip Reisner discovered that the connector layer for uvesafb, pohmelfs,\ndst, and dm did not correctly check capabilties.  A local attacker could\nexploit this to crash the system or gain elevated privileges. Ubuntu\n6.06 was not affected. (CVE-2009-3725)\n\nTrond Myklebust discovered that NFSv4 clients did not robustly\nverify attributes.  A malicious remote NFSv4 server could exploit\nthis to crash a client or gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-3726)\n\nRobin Getz discovered that NOMMU systems did not correctly validate\nNULL pointers in do_mmap_pgoff calls.  A local attacker could attempt to\nallocate large amounts of memory to crash the system, leading to a denial\nof service. Only Ubuntu 6.06 and 9.10 were affected. (CVE-2009-3888)\n\nJoseph Malicki discovered that the MegaRAID SAS driver had\nworld-writable option files.  A local attacker could exploit these\nto disrupt the behavior of the controller, leading to a denial of\nservice. (CVE-2009-3889, CVE-2009-3939)\n\nRoel Kluin discovered that the Hisax ISDN driver did not correctly\ncheck the size of packets.  A remote attacker could send specially\ncrafted packets to cause a system crash, leading to a denial of\nservice. (CVE-2009-4005)\n\nLennert Buytenhek discovered that certain 802.11 states were not handled\ncorrectly.  A physically-proximate remote attacker could send specially\ncrafted wireless traffic that would crash the system, leading to a denial\nof service. Only Ubuntu 9.10 was affected. (CVE-2009-4026, CVE-2009-4027)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-26.64","description":"","is_source":true},{"name":"linux-image-2.6.24-26-mckinley","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-generic","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-hppa32","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-386","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-sparc64-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-openvz","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-itanium","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-lpiacompat","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-xen","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-lpia","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"usb-modules-2.6.24-26-sparc64-di","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-virtual","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-rt","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-server","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc64-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-hppa64","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-sparc64","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.81","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"}],"intrepid":[{"name":"linux","version":"2.6.27-16.44","description":"","is_source":true},{"name":"linux-image-2.6.27-16-virtual","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"},{"name":"linux-image-2.6.27-16-server","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"},{"name":"linux-image-2.6.27-16-generic","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"}],"jaunty":[{"name":"linux","version":"2.6.28-17.58","description":"","is_source":true},{"name":"linux-image-2.6.28-17-imx51","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-virtual","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-server","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-versatile","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-iop32x","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-generic","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-ixp4xx","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-lpia","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"}],"karmic":[{"name":"linux","version":"2.6.31-16.52","description":"","is_source":true},{"name":"linux-image-2.6.31-16-powerpc-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-server","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-powerpc64-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-lpia","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-386","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-generic-pae","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-sparc64-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-virtual","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-sparc64","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-ia64","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-generic","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-powerpc","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"}]},"type":"USN","cves_ids":["CVE-2009-3726","CVE-2009-4027","CVE-2009-3624","CVE-2009-3612","CVE-2009-3547","CVE-2009-3613","CVE-2009-3725","CVE-2009-3620","CVE-2009-3623","CVE-2009-3888","CVE-2009-3889","CVE-2009-3939","CVE-2009-4005","CVE-2009-3621","CVE-2009-2910","CVE-2009-4026","CVE-2009-3228","CVE-2009-3080","CVE-2009-2909","CVE-2009-3722","CVE-2009-3638"]}]},{"id":"CVE-2009-3612","published":"2009-10-19T00:00:00","updated_at":"2025-08-04T19:23:40.469914+00:00","description":"\nThe tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem\nin the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does\nnot initialize a certain tcm__pad2 structure member, which might allow\nlocal users to obtain sensitive information from kernel memory via\nunspecified vectors.  NOTE: this issue exists because of an incomplete fix\nfor CVE-2005-4881.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-864-1","https://www.cve.org/CVERecord?id=CVE-2009-3612"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=ad61df918c44316940404891d5082c63e79c256a"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-26.64","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-16.44","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-17.58","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-16.52","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.32~rc5","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.81","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.32~rc5","component":null,"pocket":"security"}]}],"notices_ids":["USN-864-1"],"notices":[{"id":"USN-864-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2009-12-05T01:52:13.000003","description":"It was discovered that the AX.25 network subsystem did not correctly\ncheck integer signedness in certain setsockopt calls.  A local attacker\ncould exploit this to crash the system, leading to a denial of service.\nUbuntu 9.10 was not affected. (CVE-2009-2909)\n\nJan Beulich discovered that the kernel could leak register contents to\n32-bit processes that were switched to 64-bit mode.  A local attacker\ncould run a specially crafted binary to read register values from an\nearlier process, leading to a loss of privacy. (CVE-2009-2910)\n\nDave Jones discovered that the gdth SCSI driver did not correctly validate\narray indexes in certain ioctl calls.  A local attacker could exploit\nthis to crash the system or gain elevated privileges.  (CVE-2009-3080)\n\nEric Dumazet and Jiri Pirko discovered that the TC and CLS subsystems\nwould leak kernel memory via uninitialized structure members.  A local\nattacker could exploit this to read several bytes of kernel memory,\nleading to a loss of privacy. (CVE-2009-3228, CVE-2009-3612)\n\nEarl Chew discovered race conditions in pipe handling.  A local attacker\ncould exploit anonymous pipes via /proc/*/fd/ and crash the system or\ngain root privileges. (CVE-2009-3547)\n\nDave Jones and Francois Romieu discovered that the r8169 network driver\ncould be made to leak kernel memory.  A remote attacker could send a large\nnumber of jumbo frames until the system memory was exhausted, leading\nto a denial of service. Ubuntu 9.10 was not affected. (CVE-2009-3613).\n\nBen Hutchings discovered that the ATI Rage 128 video driver did not\ncorrectly validate initialization states.  A local attacker could\nmake specially crafted ioctl calls to crash the system or gain root\nprivileges. (CVE-2009-3620)\n\nTomoki Sekiyama discovered that Unix sockets did not correctly verify\nnamespaces.  A local attacker could exploit this to cause a system hang,\nleading to a denial of service. (CVE-2009-3621)\n\nJ. Bruce Fields discovered that NFSv4 did not correctly use the credential\ncache.  A local attacker using a mount with AUTH_NULL authentication\ncould exploit this to crash the system or gain root privileges. Only\nUbuntu 9.10 was affected. (CVE-2009-3623)\n\nAlexander Zangerl discovered that the kernel keyring did not correctly\nreference count.  A local attacker could issue a series of specially\ncrafted keyring calls to crash the system or gain root privileges.\nOnly Ubuntu 9.10 was affected. (CVE-2009-3624)\n\nDavid Wagner discovered that KVM did not correctly bounds-check CPUID\nentries.  A local attacker could exploit this to crash the system\nor possibly gain elevated privileges. Ubuntu 6.06 and 9.10 were not\naffected. (CVE-2009-3638)\n\nAvi Kivity discovered that KVM did not correctly check privileges when\naccessing debug registers.  A local attacker could exploit this to\ncrash a host system from within a guest system, leading to a denial of\nservice. Ubuntu 6.06 and 9.10 were not affected. (CVE-2009-3722)\n\nPhilip Reisner discovered that the connector layer for uvesafb, pohmelfs,\ndst, and dm did not correctly check capabilties.  A local attacker could\nexploit this to crash the system or gain elevated privileges. Ubuntu\n6.06 was not affected. (CVE-2009-3725)\n\nTrond Myklebust discovered that NFSv4 clients did not robustly\nverify attributes.  A malicious remote NFSv4 server could exploit\nthis to crash a client or gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-3726)\n\nRobin Getz discovered that NOMMU systems did not correctly validate\nNULL pointers in do_mmap_pgoff calls.  A local attacker could attempt to\nallocate large amounts of memory to crash the system, leading to a denial\nof service. Only Ubuntu 6.06 and 9.10 were affected. (CVE-2009-3888)\n\nJoseph Malicki discovered that the MegaRAID SAS driver had\nworld-writable option files.  A local attacker could exploit these\nto disrupt the behavior of the controller, leading to a denial of\nservice. (CVE-2009-3889, CVE-2009-3939)\n\nRoel Kluin discovered that the Hisax ISDN driver did not correctly\ncheck the size of packets.  A remote attacker could send specially\ncrafted packets to cause a system crash, leading to a denial of\nservice. (CVE-2009-4005)\n\nLennert Buytenhek discovered that certain 802.11 states were not handled\ncorrectly.  A physically-proximate remote attacker could send specially\ncrafted wireless traffic that would crash the system, leading to a denial\nof service. Only Ubuntu 9.10 was affected. (CVE-2009-4026, CVE-2009-4027)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-26.64","description":"","is_source":true},{"name":"linux-image-2.6.24-26-mckinley","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-generic","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-hppa32","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-386","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-sparc64-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-openvz","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-itanium","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-lpiacompat","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-xen","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-lpia","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"usb-modules-2.6.24-26-sparc64-di","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-virtual","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-rt","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-server","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc64-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-hppa64","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-sparc64","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.81","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"}],"intrepid":[{"name":"linux","version":"2.6.27-16.44","description":"","is_source":true},{"name":"linux-image-2.6.27-16-virtual","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"},{"name":"linux-image-2.6.27-16-server","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"},{"name":"linux-image-2.6.27-16-generic","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"}],"jaunty":[{"name":"linux","version":"2.6.28-17.58","description":"","is_source":true},{"name":"linux-image-2.6.28-17-imx51","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-virtual","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-server","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-versatile","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-iop32x","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-generic","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-ixp4xx","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-lpia","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"}],"karmic":[{"name":"linux","version":"2.6.31-16.52","description":"","is_source":true},{"name":"linux-image-2.6.31-16-powerpc-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-server","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-powerpc64-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-lpia","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-386","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-generic-pae","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-sparc64-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-virtual","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-sparc64","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-ia64","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-generic","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-powerpc","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"}]},"type":"USN","cves_ids":["CVE-2009-3726","CVE-2009-4027","CVE-2009-3624","CVE-2009-3612","CVE-2009-3547","CVE-2009-3613","CVE-2009-3725","CVE-2009-3620","CVE-2009-3623","CVE-2009-3888","CVE-2009-3889","CVE-2009-3939","CVE-2009-4005","CVE-2009-3621","CVE-2009-2910","CVE-2009-4026","CVE-2009-3228","CVE-2009-3080","CVE-2009-2909","CVE-2009-3722","CVE-2009-3638"]}]},{"id":"CVE-2009-3546","published":"2009-10-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1,\nand the GD Graphics Library 2.x, does not properly verify a certain\ncolorsTotal structure member, which might allow remote attackers to conduct\nbuffer overflow or buffer over-read attacks via a crafted GD file, a\ndifferent vulnerability than CVE-2009-3293. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"PoC in php commit\nphp not affected - uses system libgd2"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-854-1","https://www.cve.org/CVERecord?id=CVE-2009-3546"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=552534","https://bugzilla.redhat.com/show_bug.cgi?id=529213"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=289557"],"libgd2":["upstream: http://svn.php.net/viewvc?view=revision&revision=289557"]},"tags":{},"packages":[{"name":"libgd2","source":"https://ubuntu.com/security/cve?package=libgd2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libgd2","debian":"https://tracker.debian.org/pkg/libgd2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.33-2ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.35.dfsg-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.36~rc1~dfsg-3ubuntu1.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.36~rc1~dfsg-3ubuntu1.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.36~rc1~dfsg-3ubuntu1.9.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.36~rc1~dfsg-3.1","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.11","component":null,"pocket":"security"}]}],"notices_ids":["USN-854-1"],"notices":[{"id":"USN-854-1","title":"GD library vulnerabilities","summary":"GD library vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-11-05T19:13:49.978465","description":"Tomas Hoger discovered that the GD library did not properly handle the\nnumber of colors in certain malformed GD images. If a user or automated\nsystem were tricked into processing a specially crafted GD image, an\nattacker could cause a denial of service or possibly execute arbitrary\ncode. (CVE-2009-3546)\n\nIt was discovered that the GD library did not properly handle incorrect\ncolor indexes. An attacker could send specially crafted input to\napplications linked against libgd2 and cause a denial of service or\npossibly execute arbitrary code. This issue only affected Ubuntu 6.06 LTS.\n(CVE-2009-3293)\n\nIt was discovered that the GD library did not properly handle certain\nmalformed GIF images. If a user or automated system were tricked into\nprocessing a specially crafted GIF image, an attacker could cause a denial\nof service. This issue only affected Ubuntu 6.06 LTS. (CVE-2007-3475,\nCVE-2007-3476)\n\nIt was discovered that the GD library did not properly handle large angle\ndegree values. An attacker could send specially crafted input to\napplications linked against libgd2 and cause a denial of service. This\nissue only affected Ubuntu 6.06 LTS. (CVE-2007-3477)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libgd2","version":"2.0.35.dfsg-3ubuntu2.1","description":"","is_source":true},{"name":"libgd2-xpm","version":"2.0.35.dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.35.dfsg-3ubuntu2.1"},{"name":"libgd2-noxpm","version":"2.0.35.dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.35.dfsg-3ubuntu2.1"}],"dapper":[{"name":"libgd2","version":"2.0.33-2ubuntu5.4","description":"","is_source":true},{"name":"libgd2-xpm","version":"2.0.33-2ubuntu5.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.33-2ubuntu5.4"},{"name":"libgd2-noxpm","version":"2.0.33-2ubuntu5.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.33-2ubuntu5.4"}],"intrepid":[{"name":"libgd2","version":"2.0.36~rc1~dfsg-3ubuntu1.8.10.1","description":"","is_source":true},{"name":"libgd2-xpm","version":"2.0.36~rc1~dfsg-3ubuntu1.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.36~rc1~dfsg-3ubuntu1.8.10.1"},{"name":"libgd2-noxpm","version":"2.0.36~rc1~dfsg-3ubuntu1.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.36~rc1~dfsg-3ubuntu1.8.10.1"}],"jaunty":[{"name":"libgd2","version":"2.0.36~rc1~dfsg-3ubuntu1.9.04.1","description":"","is_source":true},{"name":"libgd2-xpm","version":"2.0.36~rc1~dfsg-3ubuntu1.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.36~rc1~dfsg-3ubuntu1.9.04.1"},{"name":"libgd2-noxpm","version":"2.0.36~rc1~dfsg-3ubuntu1.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.36~rc1~dfsg-3ubuntu1.9.04.1"}],"karmic":[{"name":"libgd2","version":"2.0.36~rc1~dfsg-3ubuntu1.9.10.1","description":"","is_source":true},{"name":"libgd2-xpm","version":"2.0.36~rc1~dfsg-3ubuntu1.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.36~rc1~dfsg-3ubuntu1.9.10.1"},{"name":"libgd2-noxpm","version":"2.0.36~rc1~dfsg-3ubuntu1.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libgd2","version_link":"https://launchpad.net/ubuntu/+source/libgd2/2.0.36~rc1~dfsg-3ubuntu1.9.10.1"}]},"type":"USN","cves_ids":["CVE-2007-3476","CVE-2007-3475","CVE-2009-3546","CVE-2009-3293","CVE-2007-3477"]}]},{"id":"CVE-2009-3228","published":"2009-10-19T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in\nthe Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not\ninitialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which\nmight allow local users to obtain sensitive information from kernel memory\nvia unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-864-1","https://www.cve.org/CVERecord?id=CVE-2009-3228"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=16ebb5e0b36ceadc8186f71d68b0c4fa4b6e781b"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-26.64","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-16.44","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-17.58","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.31~rc9","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.81","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.31~rc9","component":null,"pocket":"security"}]}],"notices_ids":["USN-864-1"],"notices":[{"id":"USN-864-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2009-12-05T01:52:13.000003","description":"It was discovered that the AX.25 network subsystem did not correctly\ncheck integer signedness in certain setsockopt calls.  A local attacker\ncould exploit this to crash the system, leading to a denial of service.\nUbuntu 9.10 was not affected. (CVE-2009-2909)\n\nJan Beulich discovered that the kernel could leak register contents to\n32-bit processes that were switched to 64-bit mode.  A local attacker\ncould run a specially crafted binary to read register values from an\nearlier process, leading to a loss of privacy. (CVE-2009-2910)\n\nDave Jones discovered that the gdth SCSI driver did not correctly validate\narray indexes in certain ioctl calls.  A local attacker could exploit\nthis to crash the system or gain elevated privileges.  (CVE-2009-3080)\n\nEric Dumazet and Jiri Pirko discovered that the TC and CLS subsystems\nwould leak kernel memory via uninitialized structure members.  A local\nattacker could exploit this to read several bytes of kernel memory,\nleading to a loss of privacy. (CVE-2009-3228, CVE-2009-3612)\n\nEarl Chew discovered race conditions in pipe handling.  A local attacker\ncould exploit anonymous pipes via /proc/*/fd/ and crash the system or\ngain root privileges. (CVE-2009-3547)\n\nDave Jones and Francois Romieu discovered that the r8169 network driver\ncould be made to leak kernel memory.  A remote attacker could send a large\nnumber of jumbo frames until the system memory was exhausted, leading\nto a denial of service. Ubuntu 9.10 was not affected. (CVE-2009-3613).\n\nBen Hutchings discovered that the ATI Rage 128 video driver did not\ncorrectly validate initialization states.  A local attacker could\nmake specially crafted ioctl calls to crash the system or gain root\nprivileges. (CVE-2009-3620)\n\nTomoki Sekiyama discovered that Unix sockets did not correctly verify\nnamespaces.  A local attacker could exploit this to cause a system hang,\nleading to a denial of service. (CVE-2009-3621)\n\nJ. Bruce Fields discovered that NFSv4 did not correctly use the credential\ncache.  A local attacker using a mount with AUTH_NULL authentication\ncould exploit this to crash the system or gain root privileges. Only\nUbuntu 9.10 was affected. (CVE-2009-3623)\n\nAlexander Zangerl discovered that the kernel keyring did not correctly\nreference count.  A local attacker could issue a series of specially\ncrafted keyring calls to crash the system or gain root privileges.\nOnly Ubuntu 9.10 was affected. (CVE-2009-3624)\n\nDavid Wagner discovered that KVM did not correctly bounds-check CPUID\nentries.  A local attacker could exploit this to crash the system\nor possibly gain elevated privileges. Ubuntu 6.06 and 9.10 were not\naffected. (CVE-2009-3638)\n\nAvi Kivity discovered that KVM did not correctly check privileges when\naccessing debug registers.  A local attacker could exploit this to\ncrash a host system from within a guest system, leading to a denial of\nservice. Ubuntu 6.06 and 9.10 were not affected. (CVE-2009-3722)\n\nPhilip Reisner discovered that the connector layer for uvesafb, pohmelfs,\ndst, and dm did not correctly check capabilties.  A local attacker could\nexploit this to crash the system or gain elevated privileges. Ubuntu\n6.06 was not affected. (CVE-2009-3725)\n\nTrond Myklebust discovered that NFSv4 clients did not robustly\nverify attributes.  A malicious remote NFSv4 server could exploit\nthis to crash a client or gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-3726)\n\nRobin Getz discovered that NOMMU systems did not correctly validate\nNULL pointers in do_mmap_pgoff calls.  A local attacker could attempt to\nallocate large amounts of memory to crash the system, leading to a denial\nof service. Only Ubuntu 6.06 and 9.10 were affected. (CVE-2009-3888)\n\nJoseph Malicki discovered that the MegaRAID SAS driver had\nworld-writable option files.  A local attacker could exploit these\nto disrupt the behavior of the controller, leading to a denial of\nservice. (CVE-2009-3889, CVE-2009-3939)\n\nRoel Kluin discovered that the Hisax ISDN driver did not correctly\ncheck the size of packets.  A remote attacker could send specially\ncrafted packets to cause a system crash, leading to a denial of\nservice. (CVE-2009-4005)\n\nLennert Buytenhek discovered that certain 802.11 states were not handled\ncorrectly.  A physically-proximate remote attacker could send specially\ncrafted wireless traffic that would crash the system, leading to a denial\nof service. Only Ubuntu 9.10 was affected. (CVE-2009-4026, CVE-2009-4027)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-26.64","description":"","is_source":true},{"name":"linux-image-2.6.24-26-mckinley","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-generic","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-hppa32","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-386","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-sparc64-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-openvz","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-itanium","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-lpiacompat","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-xen","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-lpia","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"usb-modules-2.6.24-26-sparc64-di","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-virtual","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-rt","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-server","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-powerpc64-smp","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-hppa64","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"},{"name":"linux-image-2.6.24-26-sparc64","version":"2.6.24-26.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-26.64"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.81","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.81"}],"intrepid":[{"name":"linux","version":"2.6.27-16.44","description":"","is_source":true},{"name":"linux-image-2.6.27-16-virtual","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"},{"name":"linux-image-2.6.27-16-server","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"},{"name":"linux-image-2.6.27-16-generic","version":"2.6.27-16.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-16.44"}],"jaunty":[{"name":"linux","version":"2.6.28-17.58","description":"","is_source":true},{"name":"linux-image-2.6.28-17-imx51","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-virtual","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-server","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-versatile","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-iop32x","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-generic","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-ixp4xx","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"},{"name":"linux-image-2.6.28-17-lpia","version":"2.6.28-17.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-17.58"}],"karmic":[{"name":"linux","version":"2.6.31-16.52","description":"","is_source":true},{"name":"linux-image-2.6.31-16-powerpc-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-server","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-powerpc64-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-lpia","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-386","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-generic-pae","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-sparc64-smp","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-virtual","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-sparc64","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-ia64","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-generic","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"},{"name":"linux-image-2.6.31-16-powerpc","version":"2.6.31-16.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-16.52"}]},"type":"USN","cves_ids":["CVE-2009-3726","CVE-2009-4027","CVE-2009-3624","CVE-2009-3612","CVE-2009-3547","CVE-2009-3613","CVE-2009-3725","CVE-2009-3620","CVE-2009-3623","CVE-2009-3888","CVE-2009-3889","CVE-2009-3939","CVE-2009-4005","CVE-2009-3621","CVE-2009-2910","CVE-2009-4026","CVE-2009-3228","CVE-2009-3080","CVE-2009-2909","CVE-2009-3722","CVE-2009-3638"]}]},{"id":"CVE-2009-3697","published":"2009-10-16T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in the PDF schema generator functionality in\nphpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote\nattackers to execute arbitrary SQL commands via unspecified interface\nparameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.phpmyadmin.net/home_page/security/PMASA-2009-6.php","https://www.cve.org/CVERecord?id=CVE-2009-3697"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/450505"],"patches":{"phpmyadmin":["upstream: http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=13034"]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4:2.11.3-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4:2.11.8.1-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4:3.1.2-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"4:3.2.2.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.2.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3696","published":"2009-10-16T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before\n2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary\nweb script or HTML via a crafted name for a MySQL table.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.phpmyadmin.net/home_page/security/PMASA-2009-6.php","https://www.cve.org/CVERecord?id=CVE-2009-3696"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/450505"],"patches":{"phpmyadmin":["upstream: http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=13034"]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4:2.11.3-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4:2.11.8.1-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4:3.1.2-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"4:3.2.2.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.2.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3695","published":"2009-10-13T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAlgorithmic complexity vulnerability in the forms library in Django 1.0\nbefore 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial\nof service (CPU consumption) via a crafted (1) EmailField (email address)\nor (2) URLField (URL) that triggers a large amount of backtracking in a\nregular expression.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3695"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=550457"],"patches":{"python-django":[]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.2-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.1.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3692","published":"2009-10-13T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun\nVirtualBox 3.0.x before 3.0.8 on Solaris x86, Linux, and Mac OS X allows\nlocal users to gain privileges via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3692"],"bugs":[""],"patches":{"virtualbox-ose":[]},"tags":{},"packages":[{"name":"virtualbox-ose","source":"https://ubuntu.com/security/cve?package=virtualbox-ose","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=virtualbox-ose","debian":"https://tracker.debian.org/pkg/virtualbox-ose","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.1.6-dfsg-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3602","published":"2009-10-13T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnbound before 1.3.4 does not properly verify signatures for NSEC3 records,\nwhich allows remote attackers to cause secure delegations to be downgraded\nvia DNS spoofing or other DNS-related attacks in conjunction with crafted\ndelegation responses.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3602"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.3.4-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.4-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":73620,"limit":20,"total_results":79316}