{"cves":[{"id":"CVE-2009-3238","published":"2009-09-18T10:30:00","updated_at":"2025-08-25T19:49:18.638216+00:00","description":"\nThe get_random_int function in drivers/char/random.c in the Linux kernel\nbefore 2.6.30 produces insufficiently random numbers, which allows\nattackers to predict the return value, and possibly defeat protection\nmechanisms based on randomization, via vectors that leverage the function's\ntendency to \"return the same value over and over again for long stretches\nof time.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://patchwork.kernel.org/patch/21766/","https://ubuntu.com/security/notices/USN-852-1","https://www.cve.org/CVERecord?id=CVE-2009-3238"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8a0a9bd4db63bc45e3017bedeafbd88d0eb84d02"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-25.63","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-15.43","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-16.55","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.30~rc5","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.80","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.30~rc5","component":null,"pocket":"security"}]}],"notices_ids":["USN-852-1"],"notices":[{"id":"USN-852-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2009-10-22T00:48:54.233082","description":"Solar Designer discovered that the z90crypt driver did not correctly\ncheck capabilities. A local attacker could exploit this to shut down\nthe device, leading to a denial of service. Only affected Ubuntu 6.06.\n(CVE-2009-1883)\n\nMichael Buesch discovered that the SGI GRU driver did not correctly check\nthe length when setting options. A local attacker could exploit this\nto write to the kernel stack, leading to root privilege escalation or\na denial of service. Only affected Ubuntu 8.10 and 9.04. (CVE-2009-2584)\n\nIt was discovered that SELinux did not fully implement the mmap_min_addr\nrestrictions. A local attacker could exploit this to allocate the\nNULL memory page which could lead to further attacks against kernel\nNULL-dereference vulnerabilities. Ubuntu 6.06 was not affected.\n(CVE-2009-2695)\n\nCagri Coltekin discovered that the UDP stack did not correctly handle\ncertain flags. A local user could send specially crafted commands and\ntraffic to gain root privileges or crash the systeam, leading to a denial\nof service. Only affected Ubuntu 6.06. (CVE-2009-2698)\n\nHiroshi Shimamoto discovered that monotonic timers did not correctly\nvalidate parameters. A local user could make a specially crafted timer\nrequest to gain root privileges or crash the system, leading to a denial\nof service. Only affected Ubuntu 9.04. (CVE-2009-2767)\n\nMichael Buesch discovered that the HPPA ISA EEPROM driver did not\ncorrectly validate positions. A local user could make a specially crafted\nrequest to gain root privileges or crash the system, leading to a denial\nof service. (CVE-2009-2846)\n\nUlrich Drepper discovered that kernel signal stacks were not being\ncorrectly padded on 64-bit systems. A local attacker could send specially\ncrafted calls to expose 4 bytes of kernel stack memory, leading to a\nloss of privacy. (CVE-2009-2847)\n\nJens Rosenboom discovered that the clone method did not correctly clear\ncertain fields. A local attacker could exploit this to gain privileges\nor crash the system, leading to a denial of service. (CVE-2009-2848)\n\nIt was discovered that the MD driver did not check certain sysfs files.\nA local attacker with write access to /sys could exploit this to cause\na system crash, leading to a denial of service. Ubuntu 6.06 was not\naffected. (CVE-2009-2849)\n\nMark Smith discovered that the AppleTalk stack did not correctly\nmanage memory. A remote attacker could send specially crafted traffic\nto cause the system to consume all available memory, leading to a denial\nof service. (CVE-2009-2903)\n\nLoïc Minier discovered that eCryptfs did not correctly handle writing\nto certain deleted files. A local attacker could exploit this to gain\nroot privileges or crash the system, leading to a denial of service.\nUbuntu 6.06 was not affected. (CVE-2009-2908)\n\nIt was discovered that the LLC, AppleTalk, IR, EConet, Netrom, and\nROSE network stacks did not correctly initialize their data structures.\nA local attacker could make specially crafted calls to read kernel memory,\nleading to a loss of privacy. (CVE-2009-3001, CVE-2009-3002)\n\nIt was discovered that the randomization used for Address Space Layout\nRandomization was predictable within a small window of time. A local\nattacker could exploit this to leverage further attacks that require\nknowledge of userspace memory layouts. (CVE-2009-3238)\n\nEric Paris discovered that NFSv4 did not correctly handle file creation\nfailures. An attacker with write access to an NFSv4 share could exploit\nthis to create files with arbitrary mode bits, leading to privilege\nescalation or a loss of privacy. (CVE-2009-3286)\n\nBob Tracy discovered that the SCSI generic driver did not correctly use\nthe right index for array access. A local attacker with write access\nto a CDR could exploit this to crash the system, leading to a denial\nof service. Only Ubuntu 9.04 was affected. (CVE-2009-3288)\n\nJan Kiszka discovered that KVM did not correctly validate certain\nhypercalls. A local unprivileged attacker in a virtual guest could exploit\nthis to crash the guest kernel, leading to a denial of service. Ubuntu\n6.06 was not affected. (CVE-2009-3290)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-25.63","description":"","is_source":true},{"name":"linux-image-2.6.24-25-powerpc64-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-mckinley","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-virtual","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-hppa64","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-sparc64-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-generic","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-lpia","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-powerpc-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-xen","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-hppa32","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-rt","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-386","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-powerpc","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-openvz","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-lpiacompat","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-itanium","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-sparc64","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-server","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.80","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"}],"intrepid":[{"name":"linux","version":"2.6.27-15.43","description":"","is_source":true},{"name":"linux-image-2.6.27-15-generic","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"},{"name":"linux-image-2.6.27-15-virtual","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"},{"name":"linux-image-2.6.27-15-server","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"}],"jaunty":[{"name":"linux","version":"2.6.28-16.55","description":"","is_source":true},{"name":"linux-image-2.6.28-16-virtual","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-server","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-ixp4xx","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-lpia","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-versatile","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-iop32x","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-generic","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-imx51","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"}]},"type":"USN","cves_ids":["CVE-2009-3238","CVE-2009-3286","CVE-2009-2848","CVE-2009-3288","CVE-2009-3290","CVE-2009-2698","CVE-2009-3002","CVE-2009-1883","CVE-2009-2903","CVE-2009-2849","CVE-2009-2847","CVE-2009-2584","CVE-2009-2767","CVE-2009-2908","CVE-2009-2846","CVE-2009-2695","CVE-2009-3001"]}]},{"id":"CVE-2009-2937","published":"2009-09-18T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus\nallows remote attackers to inject arbitrary web script or HTML via the SRC\nattribute of an IMG element in a feed.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://intertwingly.net/blog/2009/09/09/Venus-Updates","https://www.cve.org/CVERecord?id=CVE-2009-2937"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=546178","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=546179","https://bugzilla.redhat.com/show_bug.cgi?id=522802"],"patches":{"planet":[],"planet-venus":[]},"tags":{},"packages":[{"name":"planet","source":"https://ubuntu.com/security/cve?package=planet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=planet","debian":"https://tracker.debian.org/pkg/planet","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"planet-venus","source":"https://ubuntu.com/security/cve?package=planet-venus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=planet-venus","debian":"https://tracker.debian.org/pkg/planet-venus","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0~bzr116-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0~bzr116-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0~bzr116-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0~bzr116-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1883","published":"2009-09-18T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux\nkernel 2.6.9 does not perform a capability check for the Z90QUIESCE\noperation, which allows local users to leverage euid 0 privileges to force\na driver outage.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-852-1","https://www.cve.org/CVERecord?id=CVE-2009-1883"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=505983"],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.80","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-852-1"],"notices":[{"id":"USN-852-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2009-10-22T00:48:54.233082","description":"Solar Designer discovered that the z90crypt driver did not correctly\ncheck capabilities. A local attacker could exploit this to shut down\nthe device, leading to a denial of service. Only affected Ubuntu 6.06.\n(CVE-2009-1883)\n\nMichael Buesch discovered that the SGI GRU driver did not correctly check\nthe length when setting options. A local attacker could exploit this\nto write to the kernel stack, leading to root privilege escalation or\na denial of service. Only affected Ubuntu 8.10 and 9.04. (CVE-2009-2584)\n\nIt was discovered that SELinux did not fully implement the mmap_min_addr\nrestrictions. A local attacker could exploit this to allocate the\nNULL memory page which could lead to further attacks against kernel\nNULL-dereference vulnerabilities. Ubuntu 6.06 was not affected.\n(CVE-2009-2695)\n\nCagri Coltekin discovered that the UDP stack did not correctly handle\ncertain flags. A local user could send specially crafted commands and\ntraffic to gain root privileges or crash the systeam, leading to a denial\nof service. Only affected Ubuntu 6.06. (CVE-2009-2698)\n\nHiroshi Shimamoto discovered that monotonic timers did not correctly\nvalidate parameters. A local user could make a specially crafted timer\nrequest to gain root privileges or crash the system, leading to a denial\nof service. Only affected Ubuntu 9.04. (CVE-2009-2767)\n\nMichael Buesch discovered that the HPPA ISA EEPROM driver did not\ncorrectly validate positions. A local user could make a specially crafted\nrequest to gain root privileges or crash the system, leading to a denial\nof service. (CVE-2009-2846)\n\nUlrich Drepper discovered that kernel signal stacks were not being\ncorrectly padded on 64-bit systems. A local attacker could send specially\ncrafted calls to expose 4 bytes of kernel stack memory, leading to a\nloss of privacy. (CVE-2009-2847)\n\nJens Rosenboom discovered that the clone method did not correctly clear\ncertain fields. A local attacker could exploit this to gain privileges\nor crash the system, leading to a denial of service. (CVE-2009-2848)\n\nIt was discovered that the MD driver did not check certain sysfs files.\nA local attacker with write access to /sys could exploit this to cause\na system crash, leading to a denial of service. Ubuntu 6.06 was not\naffected. (CVE-2009-2849)\n\nMark Smith discovered that the AppleTalk stack did not correctly\nmanage memory. A remote attacker could send specially crafted traffic\nto cause the system to consume all available memory, leading to a denial\nof service. (CVE-2009-2903)\n\nLoïc Minier discovered that eCryptfs did not correctly handle writing\nto certain deleted files. A local attacker could exploit this to gain\nroot privileges or crash the system, leading to a denial of service.\nUbuntu 6.06 was not affected. (CVE-2009-2908)\n\nIt was discovered that the LLC, AppleTalk, IR, EConet, Netrom, and\nROSE network stacks did not correctly initialize their data structures.\nA local attacker could make specially crafted calls to read kernel memory,\nleading to a loss of privacy. (CVE-2009-3001, CVE-2009-3002)\n\nIt was discovered that the randomization used for Address Space Layout\nRandomization was predictable within a small window of time. A local\nattacker could exploit this to leverage further attacks that require\nknowledge of userspace memory layouts. (CVE-2009-3238)\n\nEric Paris discovered that NFSv4 did not correctly handle file creation\nfailures. An attacker with write access to an NFSv4 share could exploit\nthis to create files with arbitrary mode bits, leading to privilege\nescalation or a loss of privacy. (CVE-2009-3286)\n\nBob Tracy discovered that the SCSI generic driver did not correctly use\nthe right index for array access. A local attacker with write access\nto a CDR could exploit this to crash the system, leading to a denial\nof service. Only Ubuntu 9.04 was affected. (CVE-2009-3288)\n\nJan Kiszka discovered that KVM did not correctly validate certain\nhypercalls. A local unprivileged attacker in a virtual guest could exploit\nthis to crash the guest kernel, leading to a denial of service. Ubuntu\n6.06 was not affected. (CVE-2009-3290)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-25.63","description":"","is_source":true},{"name":"linux-image-2.6.24-25-powerpc64-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-mckinley","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-virtual","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-hppa64","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-sparc64-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-generic","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-lpia","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-powerpc-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-xen","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-hppa32","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-rt","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-386","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-powerpc","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-openvz","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-lpiacompat","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-itanium","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-sparc64","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-server","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.80","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"}],"intrepid":[{"name":"linux","version":"2.6.27-15.43","description":"","is_source":true},{"name":"linux-image-2.6.27-15-generic","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"},{"name":"linux-image-2.6.27-15-virtual","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"},{"name":"linux-image-2.6.27-15-server","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"}],"jaunty":[{"name":"linux","version":"2.6.28-16.55","description":"","is_source":true},{"name":"linux-image-2.6.28-16-virtual","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-server","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-ixp4xx","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-lpia","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-versatile","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-iop32x","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-generic","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-imx51","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"}]},"type":"USN","cves_ids":["CVE-2009-3238","CVE-2009-3286","CVE-2009-2848","CVE-2009-3288","CVE-2009-3290","CVE-2009-2698","CVE-2009-3002","CVE-2009-1883","CVE-2009-2903","CVE-2009-2849","CVE-2009-2847","CVE-2009-2584","CVE-2009-2767","CVE-2009-2908","CVE-2009-2846","CVE-2009-2695","CVE-2009-3001"]}]},{"id":"CVE-2009-3237","published":"2009-09-17T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Horde Application\nFramework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6\nand 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and\n1.2 before 1.2.4; allow remote attackers to inject arbitrary web script or\nHTML via the (1) crafted number preferences that are not properly handled\nin the preference system (services/prefs.php), as demonstrated by the\nsidebar_width parameter; or (2) crafted unknown MIME \"text parts\" that are\nnot properly handled in the MIME viewer library (config/mime_drivers.php).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3237"],"bugs":[""],"patches":{"horde3":["vendor: http://www.debian.org/security/2010/dsa-1966"]},"tags":{},"packages":[{"name":"horde3","source":"https://ubuntu.com/security/cve?package=horde3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=horde3","debian":"https://tracker.debian.org/pkg/horde3","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.2.2+debian0-2+lenny2build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.3.6+debian0-2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.3.6+debian0-2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.3.6+debian0-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.3.6+debian0-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3.6+debian0-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3236","published":"2009-09-17T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe form library in Horde Application Framework 3.2 before 3.2.5 and 3.3\nbefore 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and\nGroupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses\ntemporary filenames during the upload process which allows remote\nattackers, with privileges to write to the address book, to overwrite\narbitrary files and execute PHP code via crafted Horde_Form_Type_image form\nfield elements.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3236"],"bugs":[""],"patches":{"horde3":[]},"tags":{},"packages":[{"name":"horde3","source":"https://ubuntu.com/security/cve?package=horde3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=horde3","debian":"https://tracker.debian.org/pkg/horde3","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.2.2+debian0-2+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.3.4+debian0-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.3.4+debian0-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.3.4+debian0-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.3.4+debian0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.3.4+debian0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.2+debian0-2+lenny1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3234","published":"2009-09-17T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the perf_copy_attr function in kernel/perf_counter.c in\nthe Linux kernel 2.6.31-rc1 allows local users to cause a denial of service\n(crash) and execute arbitrary code via a \"big size data\" to the\nperf_counter_open system call.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3234"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.31","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3233","published":"2009-09-17T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nchangetrack 4.3 allows local users to execute arbitrary commands via CRLF\nsequences and shell metacharacters in a filename in a directory that is\nchecked by changetrack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3233"],"bugs":[""],"patches":{"changetrack":[]},"tags":{},"packages":[{"name":"changetrack","source":"https://ubuntu.com/security/cve?package=changetrack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=changetrack","debian":"https://tracker.debian.org/pkg/changetrack","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4.3-3+lenny1build0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4.3-3+lenny1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4.3-3+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"4.5-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3-3+lenny1, 4.5-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3232","published":"2009-09-17T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian\nGNU/Linux, does not properly handle an \"empty selection\" for system\nauthentication modules in certain rare configurations, which causes any\nattempt to be successful and allows remote attackers to bypass\nauthentication.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-828-1","https://www.cve.org/CVERecord?id=CVE-2009-3232"],"bugs":["https://launchpad.net/bugs/410171","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=519927"],"patches":{"pam":[]},"tags":{},"packages":[{"name":"pam","source":"https://ubuntu.com/security/cve?package=pam","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pam","debian":"https://tracker.debian.org/pkg/pam","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0.1-4ubuntu5.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.1-9ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.1-10","component":null,"pocket":"security"}]}],"notices_ids":["USN-828-1"],"notices":[{"id":"USN-828-1","title":"PAM vulnerability","summary":"PAM vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-09-08T22:23:59.898048","description":"Russell Senior discovered that the system authentication module\nselection mechanism for PAM did not safely handle an empty selection.\nIf an administrator had specifically removed the default list of modules\nor failed to chose a module when operating debconf in a very unlikely\nnon-default configuration, PAM would allow any authentication attempt,\nwhich could lead to remote attackers gaining access to a system with\narbitrary privileges. This did not affect default Ubuntu installations.\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"pam","version":"1.0.1-4ubuntu5.6","description":"","is_source":true},{"name":"libpam-runtime","version":"1.0.1-4ubuntu5.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.0.1-4ubuntu5.6"}],"jaunty":[{"name":"pam","version":"1.0.1-9ubuntu1.1","description":"","is_source":true},{"name":"libpam-runtime","version":"1.0.1-9ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.0.1-9ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2009-3232"]}]},{"id":"CVE-2009-3231","published":"2009-09-17T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before\n8.2.14, when using LDAP authentication with anonymous binds, allows remote\nattackers to bypass authentication via an empty password.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-834-1","https://www.cve.org/CVERecord?id=CVE-2009-3231"],"bugs":[""],"patches":{"postgresql-8.3":[]},"tags":{},"packages":[{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.3.8-0ubuntu8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"8.3.8-0ubuntu8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"8.3.8-0ubuntu9.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.3.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-834-1"],"notices":[{"id":"USN-834-1","title":"PostgreSQL vulnerabilities","summary":"PostgreSQL vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-09-21T15:16:50.560309","description":"It was discovered that PostgreSQL could be made to unload and reload an\nalready loaded module by using the LOAD command. A remote authenticated\nattacker could exploit this to cause a denial of service. This issue did\nnot affect Ubuntu 6.06 LTS. (CVE-2009-3229)\n\nDue to an incomplete fix for CVE-2007-6600, RESET ROLE and RESET SESSION\nAUTHORIZATION operations were allowed inside security-definer functions. A\nremote authenticated attacker could exploit this to escalate privileges\nwithin PostgreSQL. (CVE-2009-3230)\n\nIt was discovered that PostgreSQL did not properly perform LDAP\nauthentication under certain circumstances. When configured to use LDAP\nwith anonymous binds, a remote attacker could bypass authentication by\nsupplying an empty password. This issue did not affect Ubuntu 6.06 LTS.\n(CVE-2009-3231)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.8-0ubuntu8.04"}],"dapper":[{"name":"postgresql-8.1","version":"8.1.18-0ubuntu0.6.06","description":"","is_source":true},{"name":"postgresql-8.1","version":"8.1.18-0ubuntu0.6.06","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1/8.1.18-0ubuntu0.6.06"}],"intrepid":[{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.10","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.8-0ubuntu8.10"}],"jaunty":[{"name":"postgresql-8.3","version":"8.3.8-0ubuntu9.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.8-0ubuntu9.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.8-0ubuntu9.04"}]},"type":"USN","cves_ids":["CVE-2009-3229","CVE-2009-3230","CVE-2009-3231"]}]},{"id":"CVE-2009-3230","published":"2009-09-17T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8,\n8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before\n7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and\n(2) RESET SESSION AUTHORIZATION operations, which allows remote\nauthenticated users to gain privileges. NOTE: this is due to an incomplete\nfix for CVE-2007-6600.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-834-1","https://www.cve.org/CVERecord?id=CVE-2009-3230"],"bugs":[""],"patches":{"postgresql-8.1":[],"postgresql-8.3":[]},"tags":{},"packages":[{"name":"postgresql-8.1","source":"https://ubuntu.com/security/cve?package=postgresql-8.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.1","debian":"https://tracker.debian.org/pkg/postgresql-8.1","statuses":[{"release_codename":"dapper","status":"released","description":"8.1.18-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.1.18","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.3.8-0ubuntu8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"8.3.8-0ubuntu8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"8.3.8-0ubuntu9.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.3.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-834-1"],"notices":[{"id":"USN-834-1","title":"PostgreSQL vulnerabilities","summary":"PostgreSQL vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-09-21T15:16:50.560309","description":"It was discovered that PostgreSQL could be made to unload and reload an\nalready loaded module by using the LOAD command. A remote authenticated\nattacker could exploit this to cause a denial of service. This issue did\nnot affect Ubuntu 6.06 LTS. (CVE-2009-3229)\n\nDue to an incomplete fix for CVE-2007-6600, RESET ROLE and RESET SESSION\nAUTHORIZATION operations were allowed inside security-definer functions. A\nremote authenticated attacker could exploit this to escalate privileges\nwithin PostgreSQL. (CVE-2009-3230)\n\nIt was discovered that PostgreSQL did not properly perform LDAP\nauthentication under certain circumstances. When configured to use LDAP\nwith anonymous binds, a remote attacker could bypass authentication by\nsupplying an empty password. This issue did not affect Ubuntu 6.06 LTS.\n(CVE-2009-3231)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.8-0ubuntu8.04"}],"dapper":[{"name":"postgresql-8.1","version":"8.1.18-0ubuntu0.6.06","description":"","is_source":true},{"name":"postgresql-8.1","version":"8.1.18-0ubuntu0.6.06","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1/8.1.18-0ubuntu0.6.06"}],"intrepid":[{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.10","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.8-0ubuntu8.10"}],"jaunty":[{"name":"postgresql-8.3","version":"8.3.8-0ubuntu9.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.8-0ubuntu9.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.8-0ubuntu9.04"}]},"type":"USN","cves_ids":["CVE-2009-3229","CVE-2009-3230","CVE-2009-3231"]}]},{"id":"CVE-2009-3229","published":"2009-09-17T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8,\nand 8.2 before 8.2.14 allows remote authenticated users to cause a denial\nof service (backend shutdown) by \"re-LOAD-ing\" libraries from a certain\nplugins directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-834-1","https://www.cve.org/CVERecord?id=CVE-2009-3229"],"bugs":[""],"patches":{"postgresql-8.3":[]},"tags":{},"packages":[{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.3.8-0ubuntu8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"8.3.8-0ubuntu8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"8.3.8-0ubuntu9.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.3.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-834-1"],"notices":[{"id":"USN-834-1","title":"PostgreSQL vulnerabilities","summary":"PostgreSQL vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-09-21T15:16:50.560309","description":"It was discovered that PostgreSQL could be made to unload and reload an\nalready loaded module by using the LOAD command. A remote authenticated\nattacker could exploit this to cause a denial of service. This issue did\nnot affect Ubuntu 6.06 LTS. (CVE-2009-3229)\n\nDue to an incomplete fix for CVE-2007-6600, RESET ROLE and RESET SESSION\nAUTHORIZATION operations were allowed inside security-definer functions. A\nremote authenticated attacker could exploit this to escalate privileges\nwithin PostgreSQL. (CVE-2009-3230)\n\nIt was discovered that PostgreSQL did not properly perform LDAP\nauthentication under certain circumstances. When configured to use LDAP\nwith anonymous binds, a remote attacker could bypass authentication by\nsupplying an empty password. This issue did not affect Ubuntu 6.06 LTS.\n(CVE-2009-3231)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.8-0ubuntu8.04"}],"dapper":[{"name":"postgresql-8.1","version":"8.1.18-0ubuntu0.6.06","description":"","is_source":true},{"name":"postgresql-8.1","version":"8.1.18-0ubuntu0.6.06","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1/8.1.18-0ubuntu0.6.06"}],"intrepid":[{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.10","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.8-0ubuntu8.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.8-0ubuntu8.10"}],"jaunty":[{"name":"postgresql-8.3","version":"8.3.8-0ubuntu9.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.8-0ubuntu9.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.8-0ubuntu9.04"}]},"type":"USN","cves_ids":["CVE-2009-3229","CVE-2009-3230","CVE-2009-3231"]}]},{"id":"CVE-2009-3235","published":"2009-09-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0\nbefore 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow\ncontext-dependent attackers to cause a denial of service (crash) and\npossibly execute arbitrary code via a crafted SIEVE script, as demonstrated\nby forwarding an e-mail message to a large number of recipients, a\ndifferent vulnerability than CVE-2009-2632.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"version specified is of dovecot-sieve, not of the dovecot itself\nalthough code is present in dapper's dovecot, we don't compile\nthe sieve plugin"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-838-1","https://www.cve.org/CVERecord?id=CVE-2009-3235"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=547947 (cyrus-imapd)"],"patches":{"cyrus-imapd-2.2":["upstream: https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sieve/sieve.y.diff?r1=1.40;r2=1.41;f=h","upstream: https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sieve/bc_eval.c.diff?r1=1.14;r2=1.15;f=h","upstream: https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sieve/script.c.diff?r1=1.68;r2=1.69;f=h","debdiff: https://bugs.launchpad.net/ubuntu/+source/cyrus-imapd-2.2/+bug/438363"],"kolab-cyrus-imapd":[],"dovecot":["upstream: http://hg.dovecot.org/dovecot-sieve-1.1/rev/049f22520628","upstream: http://hg.dovecot.org/dovecot-sieve-1.1/rev/4577c4e1130d"]},"tags":{},"packages":[{"name":"cyrus-imapd-2.2","source":"https://ubuntu.com/security/cve?package=cyrus-imapd-2.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cyrus-imapd-2.2","debian":"https://tracker.debian.org/pkg/cyrus-imapd-2.2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.2.13-14ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.2.13-19","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.2.13-19","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.2.13-19","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.2.13-19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.13-17","component":null,"pocket":"security"}]},{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:1.0.10-1ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:1.1.4-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1:1.1.11-0ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:1.1.11-0ubuntu9","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1:1.1.11-0ubuntu9","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1:1.1.11-0ubuntu9","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1:1.1.11-0ubuntu9","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1:1.1.11-0ubuntu9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kolab-cyrus-imapd","source":"https://ubuntu.com/security/cve?package=kolab-cyrus-imapd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kolab-cyrus-imapd","debian":"https://tracker.debian.org/pkg/kolab-cyrus-imapd","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.2.13-9","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.2.13-9","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.2.13-9","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.2.13-9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-838-1"],"notices":[{"id":"USN-838-1","title":"Dovecot vulnerabilities","summary":"Dovecot vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-09-28T12:44:52.125658","description":"It was discovered that the ACL plugin in Dovecot would incorrectly handle\nnegative access rights. An attacker could exploit this flaw to access the\nDovecot server, bypassing the intended access restrictions. This only\naffected Ubuntu 8.04 LTS. (CVE-2008-4577)\n\nIt was discovered that the ManageSieve service in Dovecot incorrectly\nhandled \"..\" in script names. A remote attacker could exploit this to read\nand modify arbitrary sieve files on the server. This only affected Ubuntu\n8.10. (CVE-2008-5301)\n\nIt was discovered that the Sieve plugin in Dovecot incorrectly handled\ncertain sieve scripts. An authenticated user could exploit this with a\ncrafted sieve script to cause a denial of service or possibly execute\narbitrary code. (CVE-2009-2632, CVE-2009-3235)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"dovecot","version":"1:1.0.10-1ubuntu5.2","description":"","is_source":true},{"name":"dovecot-common","version":"1:1.0.10-1ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dovecot","version_link":"https://launchpad.net/ubuntu/+source/dovecot/1:1.0.10-1ubuntu5.2"}],"intrepid":[{"name":"dovecot","version":"1:1.1.4-0ubuntu1.3","description":"","is_source":true},{"name":"dovecot-common","version":"1:1.1.4-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dovecot","version_link":"https://launchpad.net/ubuntu/+source/dovecot/1:1.1.4-0ubuntu1.3"}],"jaunty":[{"name":"dovecot","version":"1:1.1.11-0ubuntu4.1","description":"","is_source":true},{"name":"dovecot-common","version":"1:1.1.11-0ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dovecot","version_link":"https://launchpad.net/ubuntu/+source/dovecot/1:1.1.11-0ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2008-4577","CVE-2008-5301","CVE-2009-2632","CVE-2009-3235"]}]},{"id":"CVE-2009-3166","published":"2009-09-15T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ntoken.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at\nthe beginning of a login session that occurs immediately after a password\nreset, which allows context-dependent attackers to discover passwords by\nreading (1) web-server access logs, (2) web-server Referer logs, or (3) the\nbrowser history.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"only 3.4.x is affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3166"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"3.4.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3165","published":"2009-09-15T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in the Bug.create WebService function in\nBugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1\nallows remote attackers to execute arbitrary SQL commands via unspecified\nparameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3165"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.5.0-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.5.0-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.5.0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.5.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3125","published":"2009-09-15T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in the Bug.search WebService function in\nBugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute\narbitrary SQL commands via unspecified parameters.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"only 3.3.2 through 3.4.1 are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3125"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"3.4.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2945","published":"2009-09-15T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nweblogin/login.fcgi (aka the WebLogin login script) in Stanford University\nWebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain\ncircumstances involving conversion of a POST request to a GET request,\nwhich allows context-dependent attackers to discover passwords by reading\n(1) web-server access logs, (2) web-server Referer logs, or (3) the browser\nhistory.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2945"],"bugs":[""],"patches":{"webauth":[]},"tags":{},"packages":[{"name":"webauth","source":"https://ubuntu.com/security/cve?package=webauth","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webauth","debian":"https://tracker.debian.org/pkg/webauth","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.6.2-2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.6.2-2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.6.2-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.6.2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2903","published":"2009-09-15T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMemory leak in the appletalk subsystem in the Linux kernel 2.4.x through\n2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are\nloaded but the ipddp\"N\" device is not found, allows remote attackers to\ncause a denial of service (memory consumption) via IP-DDP datagrams.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-852-1","https://www.cve.org/CVERecord?id=CVE-2009-2903"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-25.63","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-15.43","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-16.55","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.80","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-852-1"],"notices":[{"id":"USN-852-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2009-10-22T00:48:54.233082","description":"Solar Designer discovered that the z90crypt driver did not correctly\ncheck capabilities. A local attacker could exploit this to shut down\nthe device, leading to a denial of service. Only affected Ubuntu 6.06.\n(CVE-2009-1883)\n\nMichael Buesch discovered that the SGI GRU driver did not correctly check\nthe length when setting options. A local attacker could exploit this\nto write to the kernel stack, leading to root privilege escalation or\na denial of service. Only affected Ubuntu 8.10 and 9.04. (CVE-2009-2584)\n\nIt was discovered that SELinux did not fully implement the mmap_min_addr\nrestrictions. A local attacker could exploit this to allocate the\nNULL memory page which could lead to further attacks against kernel\nNULL-dereference vulnerabilities. Ubuntu 6.06 was not affected.\n(CVE-2009-2695)\n\nCagri Coltekin discovered that the UDP stack did not correctly handle\ncertain flags. A local user could send specially crafted commands and\ntraffic to gain root privileges or crash the systeam, leading to a denial\nof service. Only affected Ubuntu 6.06. (CVE-2009-2698)\n\nHiroshi Shimamoto discovered that monotonic timers did not correctly\nvalidate parameters. A local user could make a specially crafted timer\nrequest to gain root privileges or crash the system, leading to a denial\nof service. Only affected Ubuntu 9.04. (CVE-2009-2767)\n\nMichael Buesch discovered that the HPPA ISA EEPROM driver did not\ncorrectly validate positions. A local user could make a specially crafted\nrequest to gain root privileges or crash the system, leading to a denial\nof service. (CVE-2009-2846)\n\nUlrich Drepper discovered that kernel signal stacks were not being\ncorrectly padded on 64-bit systems. A local attacker could send specially\ncrafted calls to expose 4 bytes of kernel stack memory, leading to a\nloss of privacy. (CVE-2009-2847)\n\nJens Rosenboom discovered that the clone method did not correctly clear\ncertain fields. A local attacker could exploit this to gain privileges\nor crash the system, leading to a denial of service. (CVE-2009-2848)\n\nIt was discovered that the MD driver did not check certain sysfs files.\nA local attacker with write access to /sys could exploit this to cause\na system crash, leading to a denial of service. Ubuntu 6.06 was not\naffected. (CVE-2009-2849)\n\nMark Smith discovered that the AppleTalk stack did not correctly\nmanage memory. A remote attacker could send specially crafted traffic\nto cause the system to consume all available memory, leading to a denial\nof service. (CVE-2009-2903)\n\nLoïc Minier discovered that eCryptfs did not correctly handle writing\nto certain deleted files. A local attacker could exploit this to gain\nroot privileges or crash the system, leading to a denial of service.\nUbuntu 6.06 was not affected. (CVE-2009-2908)\n\nIt was discovered that the LLC, AppleTalk, IR, EConet, Netrom, and\nROSE network stacks did not correctly initialize their data structures.\nA local attacker could make specially crafted calls to read kernel memory,\nleading to a loss of privacy. (CVE-2009-3001, CVE-2009-3002)\n\nIt was discovered that the randomization used for Address Space Layout\nRandomization was predictable within a small window of time. A local\nattacker could exploit this to leverage further attacks that require\nknowledge of userspace memory layouts. (CVE-2009-3238)\n\nEric Paris discovered that NFSv4 did not correctly handle file creation\nfailures. An attacker with write access to an NFSv4 share could exploit\nthis to create files with arbitrary mode bits, leading to privilege\nescalation or a loss of privacy. (CVE-2009-3286)\n\nBob Tracy discovered that the SCSI generic driver did not correctly use\nthe right index for array access. A local attacker with write access\nto a CDR could exploit this to crash the system, leading to a denial\nof service. Only Ubuntu 9.04 was affected. (CVE-2009-3288)\n\nJan Kiszka discovered that KVM did not correctly validate certain\nhypercalls. A local unprivileged attacker in a virtual guest could exploit\nthis to crash the guest kernel, leading to a denial of service. Ubuntu\n6.06 was not affected. (CVE-2009-3290)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-25.63","description":"","is_source":true},{"name":"linux-image-2.6.24-25-powerpc64-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-mckinley","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-virtual","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-hppa64","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-sparc64-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-generic","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-lpia","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-powerpc-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-xen","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-hppa32","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-rt","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-386","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-powerpc","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-openvz","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-lpiacompat","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-itanium","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-sparc64","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-server","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.80","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"}],"intrepid":[{"name":"linux","version":"2.6.27-15.43","description":"","is_source":true},{"name":"linux-image-2.6.27-15-generic","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"},{"name":"linux-image-2.6.27-15-virtual","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"},{"name":"linux-image-2.6.27-15-server","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"}],"jaunty":[{"name":"linux","version":"2.6.28-16.55","description":"","is_source":true},{"name":"linux-image-2.6.28-16-virtual","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-server","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-ixp4xx","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-lpia","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-versatile","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-iop32x","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-generic","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-imx51","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"}]},"type":"USN","cves_ids":["CVE-2009-3238","CVE-2009-3286","CVE-2009-2848","CVE-2009-3288","CVE-2009-3290","CVE-2009-2698","CVE-2009-3002","CVE-2009-1883","CVE-2009-2903","CVE-2009-2849","CVE-2009-2847","CVE-2009-2584","CVE-2009-2767","CVE-2009-2908","CVE-2009-2846","CVE-2009-2695","CVE-2009-3001"]}]},{"id":"CVE-2009-2629","published":"2009-09-15T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through\n0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15\nallows remote attackers to execute arbitrary code via crafted HTTP\nrequests.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2629"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/430064"],"patches":{"nginx":["vendor: http://www.debian.org/security/2009/dsa-1884"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.5.33-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.6.32-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.6.35-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.39","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2947","published":"2009-09-14T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16\nallows remote attackers to inject arbitrary web script or HTML via\nunspecified CGI parameter values, which are sometimes included in exception\nmessages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2947"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/xapian-omega/+bug/587739"],"patches":{"xapian-omega":["vendor: http://snapshot.debian.org/package/xapian-omega/1.0.7-3%2Blenny1/","debdiff: https://bugs.edge.launchpad.net/bugs/601160"]},"tags":{},"packages":[{"name":"xapian-omega","source":"https://ubuntu.com/security/cve?package=xapian-omega","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xapian-omega","debian":"https://tracker.debian.org/pkg/xapian-omega","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.7-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.0.17-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2813","published":"2009-09-14T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSamba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12\nthrough 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when\nWindows File Sharing is enabled, Fedora 11, and other operating systems,\ndoes not properly handle errors in resolving pathnames, which allows remote\nauthenticated users to bypass intended sharing restrictions, and read,\ncreate, or modify files, in certain circumstances involving user accounts\nthat lack home directories.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"from Apple's security announce: \"An unchecked error condition exists\nin Samba. A user who does not have a configured home directory, and connects\nto the Windows File Sharing service, will be able to access the contents of\nthe file system, subject to local file system permissions. This update\naddresses the issue by improving the handling of path resolution errors.\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html","https://ubuntu.com/security/notices/USN-839-1","https://www.cve.org/CVERecord?id=CVE-2009-2813"],"bugs":[""],"patches":{"samba":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"dapper","status":"released","description":"3.0.22-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.28a-1ubuntu4.9","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2:3.2.3-1ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2:3.3.2-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-839-1"],"notices":[{"id":"USN-839-1","title":"Samba vulnerabilities","summary":"Samba vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-10-01T19:27:34.535160","description":"J. David Hester discovered that Samba incorrectly handled users that lack\nhome directories when the automated [homes] share is enabled. An\nauthenticated user could connect to that share name and gain access to the\nwhole filesystem. (CVE-2009-2813)\n\nTim Prouty discovered that the smbd daemon in Samba incorrectly handled\ncertain unexpected network replies. A remote attacker could send malicious\nreplies to the server and cause smbd to use all available CPU, leading to a\ndenial of service. (CVE-2009-2906)\n\nRonald Volgers discovered that the mount.cifs utility, when installed as a\nsetuid program, would not verify user permissions before opening a\ncredentials file. A local user could exploit this to use or read the\ncontents of unauthorized credential files. (CVE-2009-2948)\n\nReinhard Nißl discovered that the smbclient utility contained format string\nvulnerabilities in its file name handling. Because of security features in\nUbuntu, exploitation of this vulnerability is limited. If a user or\nautomated system were tricked into processing a specially crafted file\nname, smbclient could be made to crash, possibly leading to a denial of\nservice. This only affected Ubuntu 8.10. (CVE-2009-1886)\n\nJeremy Allison discovered that the smbd daemon in Samba incorrectly handled\npermissions to modify access control lists when dos filemode is enabled. A\nremote attacker could exploit this to modify access control lists. This\nonly affected Ubuntu 8.10 and Ubuntu 9.04. (CVE-2009-1886)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"samba","version":"3.0.28a-1ubuntu4.9","description":"","is_source":true},{"name":"smbfs","version":"3.0.28a-1ubuntu4.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.9"},{"name":"samba","version":"3.0.28a-1ubuntu4.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.9"}],"dapper":[{"name":"samba","version":"3.0.22-1ubuntu3.9","description":"","is_source":true},{"name":"smbfs","version":"3.0.22-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu3.9"},{"name":"samba","version":"3.0.22-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu3.9"}],"intrepid":[{"name":"samba","version":"2:3.2.3-1ubuntu3.6","description":"","is_source":true},{"name":"smbclient","version":"2:3.2.3-1ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.6"},{"name":"samba","version":"2:3.2.3-1ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.6"},{"name":"smbfs","version":"2:3.2.3-1ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.6"}],"jaunty":[{"name":"samba","version":"2:3.3.2-1ubuntu3.2","description":"","is_source":true},{"name":"smbfs","version":"2:3.3.2-1ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.3.2-1ubuntu3.2"},{"name":"samba","version":"2:3.3.2-1ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.3.2-1ubuntu3.2"}]},"type":"USN","cves_ids":["CVE-2009-1886","CVE-2009-1888","CVE-2009-2813","CVE-2009-2906","CVE-2009-2948"]}]}],"offset":73680,"limit":20,"total_results":79316}