{"cves":[{"id":"CVE-2009-2415","published":"2009-08-10T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote\nattackers to execute arbitrary code via vectors involving length attributes\nthat trigger heap-based buffer overflows.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2415"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=540379","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=540381"],"patches":{"memcached":[]},"tags":{},"packages":[{"name":"memcached","source":"https://ubuntu.com/security/cve?package=memcached","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=memcached","debian":"https://tracker.debian.org/pkg/memcached","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.12-1+etch1build0.6.06.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.2-1+lenny1build0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.2.2-1+lenny1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.2.2-1+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.8-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2691","published":"2009-08-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and\nearlier allows local users to read (1) maps and (2) smaps files under proc/\nvia vectors related to ELF loading, a setuid process, and a race condition.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2691"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/linus/13f0feafa6b8aead57a2a328e2fca6a5828bf286","upstream: http://git.kernel.org/linus/00f89d218523b9bf6b522349c039d5ac80aa536d","upstream: http://git.kernel.org/linus/704b836cbf19e885f8366bccb2e4b0474346c02d"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.31~rc6","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2690","published":"2009-08-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read\naccess to private variables with unspecified names, which allows\ncontext-dependent attackers to obtain sensitive information via an\nuntrusted (1) applet or (2) application.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1","https://ubuntu.com/security/notices/USN-814-1","https://www.cve.org/CVERecord?id=CVE-2009-2690"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=513223"],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b16","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-814-1"],"notices":[{"id":"USN-814-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-08-11T05:45:54.377980","description":"It was discovered that the XML HMAC signature system did not\ncorrectly check certain lengths.  If an attacker sent a truncated\nHMAC, it could bypass authentication, leading to potential privilege\nescalation. (CVE-2009-0217)\n\nIt was discovered that JAR bundles would appear signed if only one element\nwas signed.  If a user were tricked into running a malicious Java applet, a\nremote attacker could exploit this to gain access to private information and\npotentially run untrusted code.  (CVE-2009-1896)\n\nIt was discovered that certain variables could leak information.  If a\nuser were tricked into running a malicious Java applet, a remote attacker\ncould exploit this to gain access to private information and potentially\nrun untrusted code. (CVE-2009-2475, CVE-2009-2690)\n\nA flaw was discovered the OpenType checking.  If a user were tricked\ninto running a malicious Java applet, a remote attacker could bypass\naccess restrictions. (CVE-2009-2476)\n\nIt was discovered that the XML processor did not correctly check\nrecursion.  If a user or automated system were tricked into processing\na specially crafted XML, the system could crash, leading to a denial of\nservice. (CVE-2009-2625)\n\nIt was discovered that the Java audio subsystem did not correctly validate\ncertain parameters.  If a user were tricked into running an untrusted\napplet, a remote attacker could read system properties.  (CVE-2009-2670)\n\nMultiple flaws were discovered in the proxy subsystem.  If a user\nwere tricked into running an untrusted applet, a remote attacker could\ndiscover local user names, obtain access to sensitive information, or\nbypass socket restrictions, leading to a loss of privacy. (CVE-2009-2671,\nCVE-2009-2672, CVE-2009-2673)\n\nFlaws were discovered in the handling of JPEG images, Unpack200 archives,\nand JDK13Services.  If a user were tricked into running an untrusted\napplet, a remote attacker could load a specially crafted file that would\nbypass local file access protections and run arbitrary code with user\nprivileges. (CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.5","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu11","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"}]},"type":"USN","cves_ids":["CVE-2009-0217","CVE-2009-1896","CVE-2009-2475","CVE-2009-2476","CVE-2009-2625","CVE-2009-2670","CVE-2009-2671","CVE-2009-2672","CVE-2009-2673","CVE-2009-2674","CVE-2009-2675","CVE-2009-2676","CVE-2009-2689","CVE-2009-2690"]}]},{"id":"CVE-2009-2689","published":"2009-08-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nJDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before\nUpdate 15, and OpenJDK, grants full privileges to instances of unspecified\nobject types, which allows context-dependent attackers to bypass intended\naccess restrictions via an untrusted (1) applet or (2) application.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1","http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1","https://ubuntu.com/security/notices/USN-814-1","https://www.cve.org/CVERecord?id=CVE-2009-2689"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=513222"],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b16","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-20","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-814-1"],"notices":[{"id":"USN-814-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-08-11T05:45:54.377980","description":"It was discovered that the XML HMAC signature system did not\ncorrectly check certain lengths.  If an attacker sent a truncated\nHMAC, it could bypass authentication, leading to potential privilege\nescalation. (CVE-2009-0217)\n\nIt was discovered that JAR bundles would appear signed if only one element\nwas signed.  If a user were tricked into running a malicious Java applet, a\nremote attacker could exploit this to gain access to private information and\npotentially run untrusted code.  (CVE-2009-1896)\n\nIt was discovered that certain variables could leak information.  If a\nuser were tricked into running a malicious Java applet, a remote attacker\ncould exploit this to gain access to private information and potentially\nrun untrusted code. (CVE-2009-2475, CVE-2009-2690)\n\nA flaw was discovered the OpenType checking.  If a user were tricked\ninto running a malicious Java applet, a remote attacker could bypass\naccess restrictions. (CVE-2009-2476)\n\nIt was discovered that the XML processor did not correctly check\nrecursion.  If a user or automated system were tricked into processing\na specially crafted XML, the system could crash, leading to a denial of\nservice. (CVE-2009-2625)\n\nIt was discovered that the Java audio subsystem did not correctly validate\ncertain parameters.  If a user were tricked into running an untrusted\napplet, a remote attacker could read system properties.  (CVE-2009-2670)\n\nMultiple flaws were discovered in the proxy subsystem.  If a user\nwere tricked into running an untrusted applet, a remote attacker could\ndiscover local user names, obtain access to sensitive information, or\nbypass socket restrictions, leading to a loss of privacy. (CVE-2009-2671,\nCVE-2009-2672, CVE-2009-2673)\n\nFlaws were discovered in the handling of JPEG images, Unpack200 archives,\nand JDK13Services.  If a user were tricked into running an untrusted\napplet, a remote attacker could load a specially crafted file that would\nbypass local file access protections and run arbitrary code with user\nprivileges. (CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.5","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu11","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"}]},"type":"USN","cves_ids":["CVE-2009-0217","CVE-2009-1896","CVE-2009-2475","CVE-2009-2476","CVE-2009-2625","CVE-2009-2670","CVE-2009-2671","CVE-2009-2672","CVE-2009-2673","CVE-2009-2674","CVE-2009-2675","CVE-2009-2676","CVE-2009-2689","CVE-2009-2690"]}]},{"id":"CVE-2009-2476","published":"2009-08-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Java Management Extensions (JMX) implementation in Sun Java SE 6 before\nUpdate 15, and OpenJDK, does not properly enforce OpenType checks, which\nallows context-dependent attackers to bypass intended access restrictions\nby leveraging finalizer resurrection to obtain a reference to a privileged\nobject.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1","https://ubuntu.com/security/notices/USN-814-1","https://www.cve.org/CVERecord?id=CVE-2009-2476"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=513220"],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"java":[]},"tags":{},"packages":[{"name":"java","source":"https://ubuntu.com/security/cve?package=java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=java","debian":"https://tracker.debian.org/pkg/java","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b16","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-814-1"],"notices":[{"id":"USN-814-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-08-11T05:45:54.377980","description":"It was discovered that the XML HMAC signature system did not\ncorrectly check certain lengths.  If an attacker sent a truncated\nHMAC, it could bypass authentication, leading to potential privilege\nescalation. (CVE-2009-0217)\n\nIt was discovered that JAR bundles would appear signed if only one element\nwas signed.  If a user were tricked into running a malicious Java applet, a\nremote attacker could exploit this to gain access to private information and\npotentially run untrusted code.  (CVE-2009-1896)\n\nIt was discovered that certain variables could leak information.  If a\nuser were tricked into running a malicious Java applet, a remote attacker\ncould exploit this to gain access to private information and potentially\nrun untrusted code. (CVE-2009-2475, CVE-2009-2690)\n\nA flaw was discovered the OpenType checking.  If a user were tricked\ninto running a malicious Java applet, a remote attacker could bypass\naccess restrictions. (CVE-2009-2476)\n\nIt was discovered that the XML processor did not correctly check\nrecursion.  If a user or automated system were tricked into processing\na specially crafted XML, the system could crash, leading to a denial of\nservice. (CVE-2009-2625)\n\nIt was discovered that the Java audio subsystem did not correctly validate\ncertain parameters.  If a user were tricked into running an untrusted\napplet, a remote attacker could read system properties.  (CVE-2009-2670)\n\nMultiple flaws were discovered in the proxy subsystem.  If a user\nwere tricked into running an untrusted applet, a remote attacker could\ndiscover local user names, obtain access to sensitive information, or\nbypass socket restrictions, leading to a loss of privacy. (CVE-2009-2671,\nCVE-2009-2672, CVE-2009-2673)\n\nFlaws were discovered in the handling of JPEG images, Unpack200 archives,\nand JDK13Services.  If a user were tricked into running an untrusted\napplet, a remote attacker could load a specially crafted file that would\nbypass local file access protections and run arbitrary code with user\nprivileges. (CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.5","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu11","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"}]},"type":"USN","cves_ids":["CVE-2009-0217","CVE-2009-1896","CVE-2009-2475","CVE-2009-2476","CVE-2009-2625","CVE-2009-2670","CVE-2009-2671","CVE-2009-2672","CVE-2009-2673","CVE-2009-2674","CVE-2009-2675","CVE-2009-2676","CVE-2009-2689","CVE-2009-2690"]}]},{"id":"CVE-2009-2475","published":"2009-08-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might\nallow context-dependent attackers to obtain sensitive information via\nvectors involving static variables that are declared without the final\nkeyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3)\nAccessibleResourceBundle.getContents, (4)\nImageReaderSpi.STANDARD_INPUT_TYPE, (5)\nImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7)\nDnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9)\nAbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap,\n(11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a\ndifferent vulnerability than CVE-2009-2673.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1","http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1","https://ubuntu.com/security/notices/USN-814-1","https://www.cve.org/CVERecord?id=CVE-2009-2475"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=513215"],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"java":[]},"tags":{},"packages":[{"name":"java","source":"https://ubuntu.com/security/cve?package=java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=java","debian":"https://tracker.debian.org/pkg/java","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b16","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"upstream","status":"released","description":"1.5.0-20","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-814-1"],"notices":[{"id":"USN-814-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-08-11T05:45:54.377980","description":"It was discovered that the XML HMAC signature system did not\ncorrectly check certain lengths.  If an attacker sent a truncated\nHMAC, it could bypass authentication, leading to potential privilege\nescalation. (CVE-2009-0217)\n\nIt was discovered that JAR bundles would appear signed if only one element\nwas signed.  If a user were tricked into running a malicious Java applet, a\nremote attacker could exploit this to gain access to private information and\npotentially run untrusted code.  (CVE-2009-1896)\n\nIt was discovered that certain variables could leak information.  If a\nuser were tricked into running a malicious Java applet, a remote attacker\ncould exploit this to gain access to private information and potentially\nrun untrusted code. (CVE-2009-2475, CVE-2009-2690)\n\nA flaw was discovered the OpenType checking.  If a user were tricked\ninto running a malicious Java applet, a remote attacker could bypass\naccess restrictions. (CVE-2009-2476)\n\nIt was discovered that the XML processor did not correctly check\nrecursion.  If a user or automated system were tricked into processing\na specially crafted XML, the system could crash, leading to a denial of\nservice. (CVE-2009-2625)\n\nIt was discovered that the Java audio subsystem did not correctly validate\ncertain parameters.  If a user were tricked into running an untrusted\napplet, a remote attacker could read system properties.  (CVE-2009-2670)\n\nMultiple flaws were discovered in the proxy subsystem.  If a user\nwere tricked into running an untrusted applet, a remote attacker could\ndiscover local user names, obtain access to sensitive information, or\nbypass socket restrictions, leading to a loss of privacy. (CVE-2009-2671,\nCVE-2009-2672, CVE-2009-2673)\n\nFlaws were discovered in the handling of JPEG images, Unpack200 archives,\nand JDK13Services.  If a user were tricked into running an untrusted\napplet, a remote attacker could load a specially crafted file that would\nbypass local file access protections and run arbitrary code with user\nprivileges. (CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.5","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu11","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"}]},"type":"USN","cves_ids":["CVE-2009-0217","CVE-2009-1896","CVE-2009-2475","CVE-2009-2476","CVE-2009-2625","CVE-2009-2670","CVE-2009-2671","CVE-2009-2672","CVE-2009-2673","CVE-2009-2674","CVE-2009-2675","CVE-2009-2676","CVE-2009-2689","CVE-2009-2690"]}]},{"id":"CVE-2009-1896","published":"2009-08-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Java Web Start framework in IcedTea in OpenJDK before\n1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora\n11, trusts an entire application when at least one of the listed jar files\nis trusted, which allows context-dependent attackers to execute arbitrary\ncode without the untrusted-code restrictions via a crafted application,\nrelated to NetX.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openjdk specific"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-814-1","https://www.cve.org/CVERecord?id=CVE-2009-1896"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=512101"],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":["vendor: http://cvs.fedora.redhat.com/viewvc/devel/java-1.6.0-openjdk/java-1.6.0-openjdk-netxandplugin.patch?revision=1.1"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b16","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-814-1"],"notices":[{"id":"USN-814-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-08-11T05:45:54.377980","description":"It was discovered that the XML HMAC signature system did not\ncorrectly check certain lengths.  If an attacker sent a truncated\nHMAC, it could bypass authentication, leading to potential privilege\nescalation. (CVE-2009-0217)\n\nIt was discovered that JAR bundles would appear signed if only one element\nwas signed.  If a user were tricked into running a malicious Java applet, a\nremote attacker could exploit this to gain access to private information and\npotentially run untrusted code.  (CVE-2009-1896)\n\nIt was discovered that certain variables could leak information.  If a\nuser were tricked into running a malicious Java applet, a remote attacker\ncould exploit this to gain access to private information and potentially\nrun untrusted code. (CVE-2009-2475, CVE-2009-2690)\n\nA flaw was discovered the OpenType checking.  If a user were tricked\ninto running a malicious Java applet, a remote attacker could bypass\naccess restrictions. (CVE-2009-2476)\n\nIt was discovered that the XML processor did not correctly check\nrecursion.  If a user or automated system were tricked into processing\na specially crafted XML, the system could crash, leading to a denial of\nservice. (CVE-2009-2625)\n\nIt was discovered that the Java audio subsystem did not correctly validate\ncertain parameters.  If a user were tricked into running an untrusted\napplet, a remote attacker could read system properties.  (CVE-2009-2670)\n\nMultiple flaws were discovered in the proxy subsystem.  If a user\nwere tricked into running an untrusted applet, a remote attacker could\ndiscover local user names, obtain access to sensitive information, or\nbypass socket restrictions, leading to a loss of privacy. (CVE-2009-2671,\nCVE-2009-2672, CVE-2009-2673)\n\nFlaws were discovered in the handling of JPEG images, Unpack200 archives,\nand JDK13Services.  If a user were tricked into running an untrusted\napplet, a remote attacker could load a specially crafted file that would\nbypass local file access protections and run arbitrary code with user\nprivileges. (CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.5","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu11","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"}]},"type":"USN","cves_ids":["CVE-2009-0217","CVE-2009-1896","CVE-2009-2475","CVE-2009-2476","CVE-2009-2625","CVE-2009-2670","CVE-2009-2671","CVE-2009-2672","CVE-2009-2673","CVE-2009-2674","CVE-2009-2675","CVE-2009-2676","CVE-2009-2689","CVE-2009-2690"]}]},{"id":"CVE-2009-2411","published":"2009-08-07T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in the libsvn_delta library in Subversion before\n1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote\nSubversion servers to execute arbitrary code via an svndiff stream with\nlarge windows that trigger a heap-based buffer overflow, a related issue to\nCVE-2009-2412.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-812-1","https://www.cve.org/CVERecord?id=CVE-2009-2411"],"bugs":[""],"patches":{"subversion":[]},"tags":{},"packages":[{"name":"subversion","source":"https://ubuntu.com/security/cve?package=subversion","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=subversion","debian":"https://tracker.debian.org/pkg/subversion","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.1-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.4.6dfsg1-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.1dfsg1-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.4dfsg1-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.4dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-812-1"],"notices":[{"id":"USN-812-1","title":"Subversion vulnerability","summary":"Subversion vulnerability","instructions":"After a standard system upgrade you need to restart any applications that\nuse Subversion, such as Apache when using mod_dav_svn, to effect the\nnecessary changes.\n","references":[],"published":"2009-08-08T00:52:21.719492","description":"Matt Lewis discovered that Subversion did not properly sanitize its input\nwhen processing svndiff streams, leading to various integer and heap\noverflows. If a user or automated system processed crafted input, a remote\nattacker could cause a denial of service or potentially execute arbitrary\ncode as the user processing the input.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"subversion","version":"1.4.6dfsg1-2ubuntu1.1","description":"","is_source":true},{"name":"libsvn1","version":"1.4.6dfsg1-2ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.4.6dfsg1-2ubuntu1.1"}],"dapper":[{"name":"subversion","version":"1.3.1-3ubuntu1.2","description":"","is_source":true},{"name":"libsvn0","version":"1.3.1-3ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.3.1-3ubuntu1.2"}],"intrepid":[{"name":"subversion","version":"1.5.1dfsg1-1ubuntu2.1","description":"","is_source":true},{"name":"libsvn1","version":"1.5.1dfsg1-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.5.1dfsg1-1ubuntu2.1"}],"jaunty":[{"name":"subversion","version":"1.5.4dfsg1-1ubuntu2.1","description":"","is_source":true},{"name":"libsvn1","version":"1.5.4dfsg1-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.5.4dfsg1-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2009-2411"]}]},{"id":"CVE-2009-2715","published":"2009-08-07T19:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSun VirtualBox 2.2 through 3.0.2 r49928 allows guest OS users to cause a\ndenial of service (Linux host OS reboot) via a sysenter instruction.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"PoC: http://www.milw0rm.com/exploits/9323"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xforce.iss.net/xforce/xfdb/52211","https://www.cve.org/CVERecord?id=CVE-2009-2715"],"bugs":["https://bugs.gentoo.org/280157?id=280157"],"patches":{"virtualbox-ose":[]},"tags":{},"packages":[{"name":"virtualbox-ose","source":"https://ubuntu.com/security/cve?package=virtualbox-ose","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=virtualbox-ose","debian":"https://tracker.debian.org/pkg/virtualbox-ose","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.1.6-dfsg-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2714","published":"2009-08-07T19:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Sun VirtualBox 3.0.0 and 3.0.2 allows guest OS\nusers to cause a denial of service (host OS reboot) via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-66-265268-1","http://secunia.com/advisories/36080","https://www.cve.org/CVERecord?id=CVE-2009-2714"],"bugs":[""],"patches":{"virtualbox-ose":[]},"tags":{},"packages":[{"name":"virtualbox-ose","source":"https://ubuntu.com/security/cve?package=virtualbox-ose","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=virtualbox-ose","debian":"https://tracker.debian.org/pkg/virtualbox-ose","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.1.6-dfsg-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2666","published":"2009-08-07T19:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsocket.c in fetchmail before 6.3.11 does not properly handle a '\\0'\ncharacter in a domain name in the subject's Common Name (CN) field of an\nX.509 certificate, which allows man-in-the-middle attackers to spoof\narbitrary SSL servers via a crafted certificate issued by a legitimate\nCertification Authority, a related issue to CVE-2009-2408.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=oss-security&m=124949601207156&w=2","http://fetchmail.berlios.de/fetchmail-SA-2009-01.txt","https://ubuntu.com/security/notices/USN-816-1","https://www.cve.org/CVERecord?id=CVE-2009-2666"],"bugs":[""],"patches":{"fetchmail":[]},"tags":{},"packages":[{"name":"fetchmail","source":"https://ubuntu.com/security/cve?package=fetchmail","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fetchmail","debian":"https://tracker.debian.org/pkg/fetchmail","statuses":[{"release_codename":"dapper","status":"released","description":"6.3.2-2ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.3.8-10ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6.3.8-11ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.3.9~rc2-4ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-816-1"],"notices":[{"id":"USN-816-1","title":"fetchmail vulnerability","summary":"fetchmail vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-08-12T22:27:05.405849","description":"Matthias Andree discovered that fetchmail did not properly handle\ncertificates with NULL characters in the certificate name. A remote\nattacker could exploit this to perform a machine-in-the-middle attack to\nview sensitive information or alter encrypted communications.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"fetchmail","version":"6.3.2-2ubuntu2.3","description":"","is_source":true},{"name":"fetchmail","version":"6.3.2-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/fetchmail","version_link":"https://launchpad.net/ubuntu/+source/fetchmail/6.3.2-2ubuntu2.3"}],"hardy":[{"name":"fetchmail","version":"6.3.8-10ubuntu1.1","description":"","is_source":true},{"name":"fetchmail","version":"6.3.8-10ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/fetchmail","version_link":"https://launchpad.net/ubuntu/+source/fetchmail/6.3.8-10ubuntu1.1"}],"intrepid":[{"name":"fetchmail","version":"6.3.8-11ubuntu3.1","description":"","is_source":true},{"name":"fetchmail","version":"6.3.8-11ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/fetchmail","version_link":"https://launchpad.net/ubuntu/+source/fetchmail/6.3.8-11ubuntu3.1"}],"jaunty":[{"name":"fetchmail","version":"6.3.9~rc2-4ubuntu1.1","description":"","is_source":true},{"name":"fetchmail","version":"6.3.9~rc2-4ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/fetchmail","version_link":"https://launchpad.net/ubuntu/+source/fetchmail/6.3.9~rc2-4ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2009-2666"]}]},{"id":"CVE-2009-0669","published":"2009-08-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nZope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise\nObjects (ZEO) database sharing is enabled, allows remote attackers to\nbypass authentication via vectors involving the ZEO network protocol.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"included in CVE-2009-0668 patch"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://pypi.python.org/pypi/ZODB3/3.8.2#whats-new-in-zodb-3-8-2","https://ubuntu.com/security/notices/USN-848-1","https://www.cve.org/CVERecord?id=CVE-2009-0669"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=540462"],"patches":{"zope3":[],"zodb":[],"zope2.8":[],"zope2.9":[],"zope2.10":[],"zope2.11":[]},"tags":{},"packages":[{"name":"zodb","source":"https://ubuntu.com/security/cve?package=zodb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zodb","debian":"https://tracker.debian.org/pkg/zodb","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1:3.9.0-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8.2","component":null,"pocket":"security"}]},{"name":"zope2.10","source":"https://ubuntu.com/security/cve?package=zope2.10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.10","debian":"https://tracker.debian.org/pkg/zope2.10","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.10.6-1+lenny1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.10.6-1+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.10.9-1","component":null,"pocket":"security"}]},{"name":"zope2.11","source":"https://ubuntu.com/security/cve?package=zope2.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.11","debian":"https://tracker.debian.org/pkg/zope2.11","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"zope2.8","source":"https://ubuntu.com/security/cve?package=zope2.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.8","debian":"https://tracker.debian.org/pkg/zope2.8","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"zope2.9","source":"https://ubuntu.com/security/cve?package=zope2.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.9","debian":"https://tracker.debian.org/pkg/zope2.9","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"zope3","source":"https://ubuntu.com/security/cve?package=zope3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope3","debian":"https://tracker.debian.org/pkg/zope3","statuses":[{"release_codename":"dapper","status":"released","description":"3.2.1-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.3.1-5ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.3.1-7ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.4.0-0ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-848-1"],"notices":[{"id":"USN-848-1","title":"Zope vulnerabilities","summary":"Zope vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-10-14T15:17:53.309552","description":"It was discovered that the Zope Object Database (ZODB) database server\n(ZEO) improperly filtered certain commands when a database is shared among\nmultiple applications or application instances. A remote attacker could\nsend malicious commands to the server and execute arbitrary code.\n(CVE-2009-0668)\n\nIt was discovered that the Zope Object Database (ZODB) database server\n(ZEO) did not handle authentication properly when a database is shared\namong multiple applications or application instances. A remote attacker\ncould use this flaw to bypass security restrictions. (CVE-2009-0669)\n\nIt was discovered that Zope did not limit the number of new object ids a\nclient could request. A remote attacker could use this flaw to consume a\nhuge amount of resources, leading to a denial of service. (No CVE\nidentifier)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"zope3","version":"3.3.1-5ubuntu2.2","description":"","is_source":true},{"name":"zope3","version":"3.3.1-5ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/zope3","version_link":"https://launchpad.net/ubuntu/+source/zope3/3.3.1-5ubuntu2.2"}],"dapper":[{"name":"zope3","version":"3.2.1-1ubuntu1.2","description":"","is_source":true},{"name":"zope3","version":"3.2.1-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/zope3","version_link":"https://launchpad.net/ubuntu/+source/zope3/3.2.1-1ubuntu1.2"}],"intrepid":[{"name":"zope3","version":"3.3.1-7ubuntu0.2","description":"","is_source":true},{"name":"zope3","version":"3.3.1-7ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/zope3","version_link":"https://launchpad.net/ubuntu/+source/zope3/3.3.1-7ubuntu0.2"}],"jaunty":[{"name":"zope3","version":"3.4.0-0ubuntu3.3","description":"","is_source":true},{"name":"zope3","version":"3.4.0-0ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/zope3","version_link":"https://launchpad.net/ubuntu/+source/zope3/3.4.0-0ubuntu3.3"}]},"type":"USN","cves_ids":["CVE-2009-0668","CVE-2009-0669"]}]},{"id":"CVE-2009-0668","published":"2009-08-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when\ncertain Zope Enterprise Objects (ZEO) database sharing is enabled, allows\nremote attackers to execute arbitrary Python code via vectors involving the\nZEO network protocol.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"patch in RH bug report is not the final version."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://pypi.python.org/pypi/ZODB3/3.8.2#whats-new-in-zodb-3-8-2","https://ubuntu.com/security/notices/USN-848-1","https://www.cve.org/CVERecord?id=CVE-2009-0668"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=540462","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-0668"],"patches":{"zope3":["vendor: https://bugzilla.redhat.com/attachment.cgi?id=354876"],"zodb":[],"zope2.8":[],"zope2.9":[],"zope2.10":[],"zope2.11":[]},"tags":{},"packages":[{"name":"zodb","source":"https://ubuntu.com/security/cve?package=zodb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zodb","debian":"https://tracker.debian.org/pkg/zodb","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1:3.9.0-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8.2","component":null,"pocket":"security"}]},{"name":"zope2.10","source":"https://ubuntu.com/security/cve?package=zope2.10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.10","debian":"https://tracker.debian.org/pkg/zope2.10","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.10.6-1+lenny1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.10.6-1+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.10.9-1","component":null,"pocket":"security"}]},{"name":"zope2.11","source":"https://ubuntu.com/security/cve?package=zope2.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.11","debian":"https://tracker.debian.org/pkg/zope2.11","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"zope2.8","source":"https://ubuntu.com/security/cve?package=zope2.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.8","debian":"https://tracker.debian.org/pkg/zope2.8","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"zope2.9","source":"https://ubuntu.com/security/cve?package=zope2.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.9","debian":"https://tracker.debian.org/pkg/zope2.9","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"zope3","source":"https://ubuntu.com/security/cve?package=zope3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope3","debian":"https://tracker.debian.org/pkg/zope3","statuses":[{"release_codename":"dapper","status":"released","description":"3.2.1-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.3.1-5ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.3.1-7ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.4.0-0ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-848-1"],"notices":[{"id":"USN-848-1","title":"Zope vulnerabilities","summary":"Zope vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-10-14T15:17:53.309552","description":"It was discovered that the Zope Object Database (ZODB) database server\n(ZEO) improperly filtered certain commands when a database is shared among\nmultiple applications or application instances. A remote attacker could\nsend malicious commands to the server and execute arbitrary code.\n(CVE-2009-0668)\n\nIt was discovered that the Zope Object Database (ZODB) database server\n(ZEO) did not handle authentication properly when a database is shared\namong multiple applications or application instances. A remote attacker\ncould use this flaw to bypass security restrictions. (CVE-2009-0669)\n\nIt was discovered that Zope did not limit the number of new object ids a\nclient could request. A remote attacker could use this flaw to consume a\nhuge amount of resources, leading to a denial of service. (No CVE\nidentifier)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"zope3","version":"3.3.1-5ubuntu2.2","description":"","is_source":true},{"name":"zope3","version":"3.3.1-5ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/zope3","version_link":"https://launchpad.net/ubuntu/+source/zope3/3.3.1-5ubuntu2.2"}],"dapper":[{"name":"zope3","version":"3.2.1-1ubuntu1.2","description":"","is_source":true},{"name":"zope3","version":"3.2.1-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/zope3","version_link":"https://launchpad.net/ubuntu/+source/zope3/3.2.1-1ubuntu1.2"}],"intrepid":[{"name":"zope3","version":"3.3.1-7ubuntu0.2","description":"","is_source":true},{"name":"zope3","version":"3.3.1-7ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/zope3","version_link":"https://launchpad.net/ubuntu/+source/zope3/3.3.1-7ubuntu0.2"}],"jaunty":[{"name":"zope3","version":"3.4.0-0ubuntu3.3","description":"","is_source":true},{"name":"zope3","version":"3.4.0-0ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/zope3","version_link":"https://launchpad.net/ubuntu/+source/zope3/3.4.0-0ubuntu3.3"}]},"type":"USN","cves_ids":["CVE-2009-0668","CVE-2009-0669"]}]},{"id":"CVE-2009-2412","published":"2009-08-06T15:30:00","updated_at":"2025-08-04T19:23:36.110448+00:00","description":"\nMultiple integer overflows in the Apache Portable Runtime (APR) library and\nthe Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow\nremote attackers to cause a denial of service (application crash) or\npossibly execute arbitrary code via vectors that trigger crafted calls to\nthe (1) allocator_alloc or (2) apr_palloc function in\nmemory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc,\n(4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in\nAPR-util; leading to buffer overflows.  NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"apache2 on hardy and higher uses system apr and apr-util"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-813-2","https://ubuntu.com/security/notices/USN-813-3","https://ubuntu.com/security/notices/USN-813-1","https://www.cve.org/CVERecord?id=CVE-2009-2412"],"bugs":[""],"patches":{"apache2":[],"apr":[],"apr-util":[]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"apr","source":"https://ubuntu.com/security/cve?package=apr","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apr","debian":"https://tracker.debian.org/pkg/apr","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.11-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.2.12-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.2.12-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.8-1","component":null,"pocket":"security"}]},{"name":"apr-util","source":"https://ubuntu.com/security/cve?package=apr-util","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apr-util","debian":"https://tracker.debian.org/pkg/apr-util","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.12+dfsg-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.2.12+dfsg-7ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.2.12+dfsg-8ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-813-3","USN-813-2","USN-813-1"],"notices":[{"id":"USN-813-3","title":"apr-util vulnerability","summary":"apr-util vulnerability","instructions":"After a standard system upgrade you need to restart any applications using\napr-util, such as Subversion and Apache, to effect the necessary changes.\n","references":[],"published":"2009-08-08T01:12:30.520863","description":"USN-813-1 fixed vulnerabilities in apr. This update provides the corresponding updates for apr-util.\n\nOriginal advisory details:\n\n Matt Lewis discovered that apr did not properly sanitize its input when\n allocating memory. If an application using apr processed crafted input, a\n remote attacker could cause a denial of service or potentially execute\n arbitrary code as the user invoking the application.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"apr-util","version":"1.2.12+dfsg-3ubuntu0.2","description":"","is_source":true},{"name":"libaprutil1","version":"1.2.12+dfsg-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr-util","version_link":"https://launchpad.net/ubuntu/+source/apr-util/1.2.12+dfsg-3ubuntu0.2"}],"intrepid":[{"name":"apr-util","version":"1.2.12+dfsg-7ubuntu0.3","description":"","is_source":true},{"name":"libaprutil1","version":"1.2.12+dfsg-7ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr-util","version_link":"https://launchpad.net/ubuntu/+source/apr-util/1.2.12+dfsg-7ubuntu0.3"}],"jaunty":[{"name":"apr-util","version":"1.2.12+dfsg-8ubuntu0.3","description":"","is_source":true},{"name":"libaprutil1","version":"1.2.12+dfsg-8ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr-util","version_link":"https://launchpad.net/ubuntu/+source/apr-util/1.2.12+dfsg-8ubuntu0.3"}]},"type":"USN","cves_ids":["CVE-2009-2412"]},{"id":"USN-813-2","title":"Apache vulnerability","summary":"Apache vulnerability","instructions":"After a standard system upgrade you need to restart any applications using\napr, such as Subversion and Apache, to effect the necessary changes.\n","references":[],"published":"2009-08-08T01:04:13.324654","description":"USN-813-1 fixed vulnerabilities in apr. This update provides the\ncorresponding updates for apr as provided by Apache on Ubuntu 6.06 LTS.\n\nOriginal advisory details:\n\n Matt Lewis discovered that apr did not properly sanitize its input when\n allocating memory. If an application using apr processed crafted input, a\n remote attacker could cause a denial of service or potentially execute\n arbitrary code as the user invoking the application.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"apache2","version":"2.0.55-4ubuntu2.7","description":"","is_source":true},{"name":"libapr0","version":"2.0.55-4ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2009-2412"]},{"id":"USN-813-1","title":"apr vulnerability","summary":"apr vulnerability","instructions":"After a standard system upgrade you need to restart any applications using\napr, such as Subversion and Apache, to effect the necessary changes.\n","references":[],"published":"2009-08-08T00:45:24.340677","description":"Matt Lewis discovered that apr did not properly sanitize its input when\nallocating memory. If an application using apr processed crafted input, a\nremote attacker could cause a denial of service or potentially execute\narbitrary code as the user invoking the application.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"apr","version":"1.2.11-1ubuntu0.1","description":"","is_source":true},{"name":"libapr1","version":"1.2.11-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr","version_link":"https://launchpad.net/ubuntu/+source/apr/1.2.11-1ubuntu0.1"}],"intrepid":[{"name":"apr","version":"1.2.12-4ubuntu0.1","description":"","is_source":true},{"name":"libapr1","version":"1.2.12-4ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr","version_link":"https://launchpad.net/ubuntu/+source/apr/1.2.12-4ubuntu0.1"}],"jaunty":[{"name":"apr","version":"1.2.12-5ubuntu0.1","description":"","is_source":true},{"name":"libapr1","version":"1.2.12-5ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apr","version_link":"https://launchpad.net/ubuntu/+source/apr/1.2.12-5ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2009-2412"]}]},{"id":"CVE-2009-2625","published":"2009-08-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nXMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime\nEnvironment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0\nbefore Update 20, and in other products, allows remote attackers to cause a\ndenial of service (infinite loop and application hang) via malformed XML\ninput, as demonstrated by the Codenomicon XML fuzzing framework.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"this originally come out as a bug in expat (#1990430).\nCVE-2009-3720 was later assigned to this identical issue, since\nthis issue was worded as a Java vulnerability. Our USN references\nthis CVE and CVE-2009-3720 will be ignored."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1","http://www.cert.fi/en/reports/2009/vulnerability2009085.html","http://www.codenomicon.com/labs/xml/","https://ubuntu.com/security/notices/USN-814-1","https://ubuntu.com/security/notices/USN-890-1","https://www.cve.org/CVERecord?id=CVE-2009-2625"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"expat":["upstream: http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patch"]},"tags":{},"packages":[{"name":"expat","source":"https://ubuntu.com/security/cve?package=expat","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=expat","debian":"https://tracker.debian.org/pkg/expat","statuses":[{"release_codename":"dapper","status":"released","description":"1.95.8-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.1-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.1-4ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.1-4ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.1-4ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.1-7ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.1-7ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b16","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-20","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-814-1","USN-890-1"],"notices":[{"id":"USN-814-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-08-11T05:45:54.377980","description":"It was discovered that the XML HMAC signature system did not\ncorrectly check certain lengths.  If an attacker sent a truncated\nHMAC, it could bypass authentication, leading to potential privilege\nescalation. (CVE-2009-0217)\n\nIt was discovered that JAR bundles would appear signed if only one element\nwas signed.  If a user were tricked into running a malicious Java applet, a\nremote attacker could exploit this to gain access to private information and\npotentially run untrusted code.  (CVE-2009-1896)\n\nIt was discovered that certain variables could leak information.  If a\nuser were tricked into running a malicious Java applet, a remote attacker\ncould exploit this to gain access to private information and potentially\nrun untrusted code. (CVE-2009-2475, CVE-2009-2690)\n\nA flaw was discovered the OpenType checking.  If a user were tricked\ninto running a malicious Java applet, a remote attacker could bypass\naccess restrictions. (CVE-2009-2476)\n\nIt was discovered that the XML processor did not correctly check\nrecursion.  If a user or automated system were tricked into processing\na specially crafted XML, the system could crash, leading to a denial of\nservice. (CVE-2009-2625)\n\nIt was discovered that the Java audio subsystem did not correctly validate\ncertain parameters.  If a user were tricked into running an untrusted\napplet, a remote attacker could read system properties.  (CVE-2009-2670)\n\nMultiple flaws were discovered in the proxy subsystem.  If a user\nwere tricked into running an untrusted applet, a remote attacker could\ndiscover local user names, obtain access to sensitive information, or\nbypass socket restrictions, leading to a loss of privacy. (CVE-2009-2671,\nCVE-2009-2672, CVE-2009-2673)\n\nFlaws were discovered in the handling of JPEG images, Unpack200 archives,\nand JDK13Services.  If a user were tricked into running an untrusted\napplet, a remote attacker could load a specially crafted file that would\nbypass local file access protections and run arbitrary code with user\nprivileges. (CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.5","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu11","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"}]},"type":"USN","cves_ids":["CVE-2009-0217","CVE-2009-1896","CVE-2009-2475","CVE-2009-2476","CVE-2009-2625","CVE-2009-2670","CVE-2009-2671","CVE-2009-2672","CVE-2009-2673","CVE-2009-2674","CVE-2009-2675","CVE-2009-2676","CVE-2009-2689","CVE-2009-2690"]},{"id":"USN-890-1","title":"Expat vulnerabilities","summary":"Expat vulnerabilities","instructions":"After a standard system upgrade you need to restart any applications linked\nagainst Expat to effect the necessary changes.\n","references":[],"published":"2010-01-20T19:02:57.745989","description":"Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did\nnot properly process malformed XML. If a user or application linked against\nExpat were tricked into opening a crafted XML file, an attacker could cause\na denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)\n\nIt was discovered that Expat did not properly process malformed UTF-8\nsequences. If a user or application linked against Expat were tricked into\nopening a crafted XML file, an attacker could cause a denial of service via\napplication crash. (CVE-2009-3560)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"expat","version":"2.0.1-0ubuntu1.1","description":"","is_source":true},{"name":"lib64expat1","version":"2.0.1-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-0ubuntu1.1"},{"name":"libexpat1-udeb","version":"2.0.1-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-0ubuntu1.1"},{"name":"libexpat1","version":"2.0.1-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-0ubuntu1.1"}],"dapper":[{"name":"expat","version":"1.95.8-3ubuntu0.1","description":"","is_source":true},{"name":"libexpat1-udeb","version":"1.95.8-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/1.95.8-3ubuntu0.1"},{"name":"libexpat1","version":"1.95.8-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/1.95.8-3ubuntu0.1"}],"intrepid":[{"name":"expat","version":"2.0.1-4ubuntu0.8.10.1","description":"","is_source":true},{"name":"lib64expat1","version":"2.0.1-4ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-4ubuntu0.8.10.1"},{"name":"libexpat1-udeb","version":"2.0.1-4ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-4ubuntu0.8.10.1"},{"name":"libexpat1","version":"2.0.1-4ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-4ubuntu0.8.10.1"}],"jaunty":[{"name":"expat","version":"2.0.1-4ubuntu0.9.04.1","description":"","is_source":true},{"name":"lib64expat1","version":"2.0.1-4ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-4ubuntu0.9.04.1"},{"name":"libexpat1-udeb","version":"2.0.1-4ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-4ubuntu0.9.04.1"},{"name":"libexpat1","version":"2.0.1-4ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-4ubuntu0.9.04.1"}],"karmic":[{"name":"expat","version":"2.0.1-4ubuntu1.1","description":"","is_source":true},{"name":"lib64expat1","version":"2.0.1-4ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-4ubuntu1.1"},{"name":"libexpat1-udeb","version":"2.0.1-4ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-4ubuntu1.1"},{"name":"libexpat1","version":"2.0.1-4ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/expat","version_link":"https://launchpad.net/ubuntu/+source/expat/2.0.1-4ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2009-2625","CVE-2009-3560","CVE-2009-3720"]}]},{"id":"CVE-2009-2688","published":"2009-08-05T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when\nrunning on Windows, allow remote attackers to cause a denial of service\n(crash) or execute arbitrary code via (1) the tiff_instantiate function\nprocessing a crafted TIFF file, (2) the png_instantiate function processing\na crafted PNG file, and (3) the jpeg_instantiate function processing a\ncrafted JPEG file, all which trigger a heap-based buffer overflow.  NOTE:\nthe provenance of this information is unknown; the details are obtained\nsolely from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2688"],"bugs":["http://tracker.xemacs.org/XEmacs/its/issue534"],"patches":{"xemacs21":[]},"tags":{},"packages":[{"name":"xemacs21","source":"https://ubuntu.com/security/cve?package=xemacs21","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xemacs21","debian":"https://tracker.debian.org/pkg/xemacs21","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"21.4.22-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"21.4.22-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"21.4.22-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"21.4.22-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"21.4.22-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"21.4.22-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"21.4.22-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2687","published":"2009-08-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe exif_read_data function in the Exif module in PHP before 5.2.10 allows\nremote attackers to cause a denial of service (crash) via a malformed JPEG\nimage with invalid offset fields, a different issue than CVE-2005-3353.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"PoC in php bug"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-824-1","https://www.cve.org/CVERecord?id=CVE-2009-2687"],"bugs":["http://bugs.php.net/bug.php?id=48378","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=535888","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=535897"],"patches":{"php4":[],"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=281307","upstream: http://svn.php.net/viewvc?view=revision&revision=281314","vendor: http://git.debian.org/?p=pkg-php/php.git;a=commitdiff;h=8615d344b20548e27ffbddd78e303af8c9a90859"]},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.15","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.7","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.2.6-2ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.2.6.dfsg.1-3ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.2.10.dfsg.1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.10.dfsg.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-824-1"],"notices":[{"id":"USN-824-1","title":"PHP vulnerability","summary":"PHP vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-08-24T15:14:40.212733","description":"It was discovered that PHP did not properly handle certain malformed\nJPEG images when being parsed by the Exif module. A remote attacker could\nexploit this flaw and cause the PHP server to crash, resulting in a denial\nof service.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.7","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.7"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.7"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.15","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.15"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.15"}],"intrepid":[{"name":"php5","version":"5.2.6-2ubuntu4.3","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6-2ubuntu4.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.3"},{"name":"php5-cgi","version":"5.2.6-2ubuntu4.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.3"}],"jaunty":[{"name":"php5","version":"5.2.6.dfsg.1-3ubuntu4.2","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6.dfsg.1-3ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.2"},{"name":"php5-cgi","version":"5.2.6.dfsg.1-3ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.2"}]},"type":"USN","cves_ids":["CVE-2009-2687"]}]},{"id":"CVE-2009-2676","published":"2009-08-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for\nBusiness, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update\n19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and\nearlier; allows remote attackers to create or modify arbitrary files via\nvectors involving an untrusted Java applet that accesses an old version of\nJNLPAppletLauncher.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1","https://ubuntu.com/security/notices/USN-814-1","https://www.cve.org/CVERecord?id=CVE-2009-2676"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b16","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-20","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-814-1"],"notices":[{"id":"USN-814-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-08-11T05:45:54.377980","description":"It was discovered that the XML HMAC signature system did not\ncorrectly check certain lengths.  If an attacker sent a truncated\nHMAC, it could bypass authentication, leading to potential privilege\nescalation. (CVE-2009-0217)\n\nIt was discovered that JAR bundles would appear signed if only one element\nwas signed.  If a user were tricked into running a malicious Java applet, a\nremote attacker could exploit this to gain access to private information and\npotentially run untrusted code.  (CVE-2009-1896)\n\nIt was discovered that certain variables could leak information.  If a\nuser were tricked into running a malicious Java applet, a remote attacker\ncould exploit this to gain access to private information and potentially\nrun untrusted code. (CVE-2009-2475, CVE-2009-2690)\n\nA flaw was discovered the OpenType checking.  If a user were tricked\ninto running a malicious Java applet, a remote attacker could bypass\naccess restrictions. (CVE-2009-2476)\n\nIt was discovered that the XML processor did not correctly check\nrecursion.  If a user or automated system were tricked into processing\na specially crafted XML, the system could crash, leading to a denial of\nservice. (CVE-2009-2625)\n\nIt was discovered that the Java audio subsystem did not correctly validate\ncertain parameters.  If a user were tricked into running an untrusted\napplet, a remote attacker could read system properties.  (CVE-2009-2670)\n\nMultiple flaws were discovered in the proxy subsystem.  If a user\nwere tricked into running an untrusted applet, a remote attacker could\ndiscover local user names, obtain access to sensitive information, or\nbypass socket restrictions, leading to a loss of privacy. (CVE-2009-2671,\nCVE-2009-2672, CVE-2009-2673)\n\nFlaws were discovered in the handling of JPEG images, Unpack200 archives,\nand JDK13Services.  If a user were tricked into running an untrusted\napplet, a remote attacker could load a specially crafted file that would\nbypass local file access protections and run arbitrary code with user\nprivileges. (CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.5","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu11","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"}]},"type":"USN","cves_ids":["CVE-2009-0217","CVE-2009-1896","CVE-2009-2475","CVE-2009-2476","CVE-2009-2625","CVE-2009-2670","CVE-2009-2671","CVE-2009-2672","CVE-2009-2673","CVE-2009-2674","CVE-2009-2675","CVE-2009-2676","CVE-2009-2689","CVE-2009-2690"]}]},{"id":"CVE-2009-2675","published":"2009-08-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the unpack200 utility in Sun Java Runtime Environment\n(JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update\n20, allows context-dependent attackers to gain privileges via unspecified\nlength fields in the header of a Pack200-compressed JAR file, which leads\nto a heap-based buffer overflow during decompression.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1","https://ubuntu.com/security/notices/USN-814-1","https://www.cve.org/CVERecord?id=CVE-2009-2675"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b16","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-20","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-814-1"],"notices":[{"id":"USN-814-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-08-11T05:45:54.377980","description":"It was discovered that the XML HMAC signature system did not\ncorrectly check certain lengths.  If an attacker sent a truncated\nHMAC, it could bypass authentication, leading to potential privilege\nescalation. (CVE-2009-0217)\n\nIt was discovered that JAR bundles would appear signed if only one element\nwas signed.  If a user were tricked into running a malicious Java applet, a\nremote attacker could exploit this to gain access to private information and\npotentially run untrusted code.  (CVE-2009-1896)\n\nIt was discovered that certain variables could leak information.  If a\nuser were tricked into running a malicious Java applet, a remote attacker\ncould exploit this to gain access to private information and potentially\nrun untrusted code. (CVE-2009-2475, CVE-2009-2690)\n\nA flaw was discovered the OpenType checking.  If a user were tricked\ninto running a malicious Java applet, a remote attacker could bypass\naccess restrictions. (CVE-2009-2476)\n\nIt was discovered that the XML processor did not correctly check\nrecursion.  If a user or automated system were tricked into processing\na specially crafted XML, the system could crash, leading to a denial of\nservice. (CVE-2009-2625)\n\nIt was discovered that the Java audio subsystem did not correctly validate\ncertain parameters.  If a user were tricked into running an untrusted\napplet, a remote attacker could read system properties.  (CVE-2009-2670)\n\nMultiple flaws were discovered in the proxy subsystem.  If a user\nwere tricked into running an untrusted applet, a remote attacker could\ndiscover local user names, obtain access to sensitive information, or\nbypass socket restrictions, leading to a loss of privacy. (CVE-2009-2671,\nCVE-2009-2672, CVE-2009-2673)\n\nFlaws were discovered in the handling of JPEG images, Unpack200 archives,\nand JDK13Services.  If a user were tricked into running an untrusted\napplet, a remote attacker could load a specially crafted file that would\nbypass local file access protections and run arbitrary code with user\nprivileges. (CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.5","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu11","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"}]},"type":"USN","cves_ids":["CVE-2009-0217","CVE-2009-1896","CVE-2009-2475","CVE-2009-2476","CVE-2009-2625","CVE-2009-2670","CVE-2009-2671","CVE-2009-2672","CVE-2009-2673","CVE-2009-2674","CVE-2009-2675","CVE-2009-2676","CVE-2009-2689","CVE-2009-2690"]}]},{"id":"CVE-2009-2674","published":"2009-08-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime\nEnvironment (JRE) in JDK and JRE 6 before Update 15 allows\ncontext-dependent attackers to execute arbitrary code via a crafted JPEG\nimage that is not properly handled during display to a splash screen, which\ntriggers a heap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1","https://ubuntu.com/security/notices/USN-814-1","https://www.cve.org/CVERecord?id=CVE-2009-2674"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"java":[]},"tags":{},"packages":[{"name":"java","source":"https://ubuntu.com/security/cve?package=java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=java","debian":"https://tracker.debian.org/pkg/java","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b18-1.8.2-4ubuntu1~8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b16","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6b14-1.4.1-0ubuntu11","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6b16-1.6.1-0ubuntu1","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-814-1"],"notices":[{"id":"USN-814-1","title":"OpenJDK vulnerabilities","summary":"OpenJDK vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-08-11T05:45:54.377980","description":"It was discovered that the XML HMAC signature system did not\ncorrectly check certain lengths.  If an attacker sent a truncated\nHMAC, it could bypass authentication, leading to potential privilege\nescalation. (CVE-2009-0217)\n\nIt was discovered that JAR bundles would appear signed if only one element\nwas signed.  If a user were tricked into running a malicious Java applet, a\nremote attacker could exploit this to gain access to private information and\npotentially run untrusted code.  (CVE-2009-1896)\n\nIt was discovered that certain variables could leak information.  If a\nuser were tricked into running a malicious Java applet, a remote attacker\ncould exploit this to gain access to private information and potentially\nrun untrusted code. (CVE-2009-2475, CVE-2009-2690)\n\nA flaw was discovered the OpenType checking.  If a user were tricked\ninto running a malicious Java applet, a remote attacker could bypass\naccess restrictions. (CVE-2009-2476)\n\nIt was discovered that the XML processor did not correctly check\nrecursion.  If a user or automated system were tricked into processing\na specially crafted XML, the system could crash, leading to a denial of\nservice. (CVE-2009-2625)\n\nIt was discovered that the Java audio subsystem did not correctly validate\ncertain parameters.  If a user were tricked into running an untrusted\napplet, a remote attacker could read system properties.  (CVE-2009-2670)\n\nMultiple flaws were discovered in the proxy subsystem.  If a user\nwere tricked into running an untrusted applet, a remote attacker could\ndiscover local user names, obtain access to sensitive information, or\nbypass socket restrictions, leading to a loss of privacy. (CVE-2009-2671,\nCVE-2009-2672, CVE-2009-2673)\n\nFlaws were discovered in the handling of JPEG images, Unpack200 archives,\nand JDK13Services.  If a user were tricked into running an untrusted\napplet, a remote attacker could load a specially crafted file that would\nbypass local file access protections and run arbitrary code with user\nprivileges. (CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.5","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.5"}],"jaunty":[{"name":"openjdk-6","version":"6b14-1.4.1-0ubuntu11","description":"","is_source":true},{"name":"openjdk-6-jre-lib","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"icedtea6-plugin","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"},{"name":"openjdk-6-jre","version":"6b14-1.4.1-0ubuntu11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b14-1.4.1-0ubuntu11"}]},"type":"USN","cves_ids":["CVE-2009-0217","CVE-2009-1896","CVE-2009-2475","CVE-2009-2476","CVE-2009-2625","CVE-2009-2670","CVE-2009-2671","CVE-2009-2672","CVE-2009-2673","CVE-2009-2674","CVE-2009-2675","CVE-2009-2676","CVE-2009-2689","CVE-2009-2690"]}]}],"offset":73820,"limit":20,"total_results":79316}