{"cves":[{"id":"CVE-2009-0605","published":"2009-02-17T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack consumption vulnerability in the do_page_fault function in\narch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users\nto cause a denial of service (memory corruption) or possibly gain\nprivileges via unspecified vectors that trigger page faults on a machine\nthat has a registered Kprobes probe.","ubuntu_description":"\nThe page fault handler could consume stack memory. A local attacker\ncould exploit this to crash the system or gain root privileges with a\nKprobe registered.","notes":[{"author":"jdsstrand","note":"needs CONFIG_KPROBES set. Ubuntu 7.10 and after have this set."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-751-1","https://www.cve.org/CVERecord?id=CVE-2009-0605"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-23.52","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-11.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-16.62","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-751-1"],"notices":[{"id":"USN-751-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2009-04-06T23:52:35.518644","description":"NFS did not correctly handle races between fcntl and interrupts. A local\nattacker on an NFS mount could consume unlimited kernel memory, leading to\na denial of service. Ubuntu 8.10 was not affected. (CVE-2008-4307)\n\nSparc syscalls did not correctly check mmap regions. A local attacker\ncould cause a system panic, leading to a denial of service. Ubuntu 8.10\nwas not affected. (CVE-2008-6107)\n\nIn certain situations, cloned processes were able to send signals to parent\nprocesses, crossing privilege boundaries. A local attacker could send\narbitrary signals to parent processes, leading to a denial of service.\n(CVE-2009-0028)\n\nThe kernel keyring did not free memory correctly. A local attacker could\nconsume unlimited kernel memory, leading to a denial of service.\n(CVE-2009-0031)\n\nThe SCTP stack did not correctly validate FORWARD-TSN packets. A remote\nattacker could send specially crafted SCTP traffic causing a system crash,\nleading to a denial of service. (CVE-2009-0065)\n\nThe eCryptfs filesystem did not correctly handle certain VFS return codes.\nA local attacker with write-access to an eCryptfs filesystem could cause a\nsystem crash, leading to a denial of service. (CVE-2009-0269)\n\nThe Dell platform device did not correctly validate user parameters. A\nlocal attacker could perform specially crafted reads to crash the system,\nleading to a denial of service. (CVE-2009-0322)\n\nThe page fault handler could consume stack memory. A local attacker could\nexploit this to crash the system or gain root privileges with a Kprobe\nregistered. Only Ubuntu 8.10 was affected. (CVE-2009-0605)\n\nNetwork interfaces statistics for the SysKonnect FDDI driver did not check\ncapabilities. A local user could reset statistics, potentially interfering\nwith packet accounting systems. (CVE-2009-0675)\n\nThe getsockopt function did not correctly clear certain parameters. A local\nattacker could read leaked kernel memory, leading to a loss of privacy.\n(CVE-2009-0676)\n\nThe ext4 filesystem did not correctly clear group descriptors when\nresizing. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2009-0745)\n\nThe ext4 filesystem did not correctly validate certain fields. A local\nattacker could mount a malicious ext4 filesystem, causing a system\ncrash, leading to a denial of service. (CVE-2009-0746, CVE-2009-0747,\nCVE-2009-0748)\n\nThe syscall interface did not correctly validate parameters when crossing\nthe 64-bit/32-bit boundary. A local attacker could bypass certain syscall\nrestricts via crafted syscalls. (CVE-2009-0834, CVE-2009-0835)\n\nThe shared memory subsystem did not correctly handle certain shmctl calls\nwhen CONFIG_SHMEM was disabled. Ubuntu kernels were not vulnerable, since\nCONFIG_SHMEM is enabled by default. (CVE-2009-0859)\n\nThe virtual consoles did not correctly handle certain UTF-8 sequences. A\nlocal attacker on the physical console could exploit this to cause a system\ncrash, leading to a denial of service. (CVE-2009-1046)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-16.62","description":"","is_source":true},{"name":"linux-image-2.6.22-16-mckinley","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-powerpc64-smp","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-virtual","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-cell","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-hppa64","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-sparc64-smp","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-generic","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-lpia","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-powerpc-smp","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-386","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-hppa32","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-rt","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-xen","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-powerpc","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-itanium","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-lpiacompat","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-ume","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-sparc64","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-server","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"}],"intrepid":[{"name":"linux","version":"2.6.27-11.31","description":"","is_source":true},{"name":"linux-image-2.6.27-11-server","version":"2.6.27-11.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.31"},{"name":"linux-image-2.6.27-11-generic","version":"2.6.27-11.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.31"},{"name":"linux-image-2.6.27-11-virtual","version":"2.6.27-11.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.31"}],"hardy":[{"name":"linux","version":"2.6.24-23.52","description":"","is_source":true},{"name":"linux-image-2.6.24-23-virtual","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-server","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-mckinley","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-sparc64-smp","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-xen","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-powerpc-smp","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-lpiacompat","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-sparc64","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-rt","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-openvz","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-lpia","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-hppa64","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-386","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-powerpc","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-powerpc64-smp","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-itanium","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-hppa32","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-generic","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"}]},"type":"USN","cves_ids":["CVE-2008-4307","CVE-2008-6107","CVE-2009-0028","CVE-2009-0031","CVE-2009-0065","CVE-2009-0269","CVE-2009-0322","CVE-2009-0605","CVE-2009-0675","CVE-2009-0676","CVE-2009-0745","CVE-2009-0746","CVE-2009-0747","CVE-2009-0748","CVE-2009-0834","CVE-2009-0835","CVE-2009-0859","CVE-2009-1046"]}]},{"id":"CVE-2009-0363","published":"2009-02-17T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11\nallow remote attackers to execute arbitrary code via vectors involving (1)\na crafted zcrypt message, related to zcrypt.c; (2) a reply command on a\nmessage with a Zephyr Cc: list, related to zwrite.c; and unspecified other\nuse of the products.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0363"],"bugs":["https://bugs.launchpad.net/bugs/329165"],"patches":{"barnowl":[],"owl":[]},"tags":{},"packages":[{"name":"barnowl","source":"https://ubuntu.com/security/cve?package=barnowl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=barnowl","debian":"https://tracker.debian.org/pkg/barnowl","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.0.5-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.5","component":null,"pocket":"security"}]},{"name":"owl","source":"https://ubuntu.com/security/cve?package=owl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=owl","debian":"https://tracker.debian.org/pkg/owl","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.1.11-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.11","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0359","published":"2009-02-17T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Samizdat before\n0.6.2 allow remote authenticated users to inject arbitrary web script or\nHTML via the (1) message title or (2) user full name.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0359"],"bugs":[""],"patches":{"samizdat":[]},"tags":{},"packages":[{"name":"samizdat","source":"https://ubuntu.com/security/cve?package=samizdat","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samizdat","debian":"https://tracker.debian.org/pkg/samizdat","statuses":[{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.6.2-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0601","published":"2009-02-16T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nFormat string vulnerability in Wireshark 0.99.8 through 1.0.5 on\nnon-Windows platforms allows local users to cause a denial of service\n(application crash) via format string specifiers in the HOME environment\nvariable.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0601"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0600","published":"2009-02-16T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to\ncause a denial of service (application crash) via a crafted Tektronix K12\ntext capture file, as demonstrated by a file with exactly one frame.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0600"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0599","published":"2009-02-16T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5\nallows user-assisted remote attackers to cause a denial of service\n(application crash) via a malformed NetScreen snoop file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0599"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0362","published":"2009-02-13T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfilter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression\nthat allows remote attackers to cause a denial of service (forced\nauthentication failures) via a crafted reverse-resolved DNS name (rhost)\nentry that contains a substring that is interpreted as an IP address, a\ndifferent vulnerability than CVE-2007-4321.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0362"],"bugs":[""],"patches":{"fail2ban":[]},"tags":{},"packages":[{"name":"fail2ban","source":"https://ubuntu.com/security/cve?package=fail2ban","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fail2ban","debian":"https://tracker.debian.org/pkg/fail2ban","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.8.3-6ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.3-5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6125","published":"2009-02-13T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the user editing interface in Moodle 1.5.x,\n1.6 before 1.6.6, and 1.7 before 1.7.3 allows remote authenticated users to\ngain privileges via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6125"],"bugs":[""],"patches":{"moodle":["vendor: http://www.debian.org/security/2008/dsa-1691"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0361","published":"2009-02-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRuss Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris\n10, and other software, does not properly handle calls to pam_setcred when\nrunning setuid, which allows local users to overwrite and change the\nownership of arbitrary files by setting the KRB5CCNAME environment\nvariable, and then launching a setuid application that performs certain\npam_setcred operations.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-719-1","https://www.cve.org/CVERecord?id=CVE-2009-0361"],"bugs":[""],"patches":{"libpam-heimdal":[],"libpam-krb5":[]},"tags":{},"packages":[{"name":"libpam-heimdal","source":"https://ubuntu.com/security/cve?package=libpam-heimdal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpam-heimdal","debian":"https://tracker.debian.org/pkg/libpam-heimdal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.10-2.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.10-2.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.15-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.15-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.15-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.10-2.1","component":null,"pocket":"security"}]},{"name":"libpam-krb5","source":"https://ubuntu.com/security/cve?package=libpam-krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpam-krb5","debian":"https://tracker.debian.org/pkg/libpam-krb5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.10-1ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.10-1ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.11-4","component":null,"pocket":"security"}]}],"notices_ids":["USN-719-1"],"notices":[{"id":"USN-719-1","title":"pam-krb5 vulnerabilities","summary":"pam-krb5 vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-02-12T19:12:40.422538","description":"It was discovered that pam_krb5 parsed environment variables when run with\nsetuid applications. A local attacker could exploit this flaw to bypass\nauthentication checks and gain root privileges. (CVE-2009-0360)\n\nDerek Chan discovered that pam_krb5 incorrectly handled refreshing existing\ncredentials when used with setuid applications. A local attacker could exploit\nthis to create or overwrite arbitrary files, and possibly gain root privileges.\n(CVE-2009-0361)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libpam-krb5","version":"3.10-1ubuntu0.8.04.1","description":"","is_source":true},{"name":"libpam-krb5","version":"3.10-1ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpam-krb5","version_link":"https://launchpad.net/ubuntu/+source/libpam-krb5/3.10-1ubuntu0.8.04.1"}],"intrepid":[{"name":"libpam-krb5","version":"3.10-1ubuntu0.8.10.1","description":"","is_source":true},{"name":"libpam-krb5","version":"3.10-1ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpam-krb5","version_link":"https://launchpad.net/ubuntu/+source/libpam-krb5/3.10-1ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2009-0360","CVE-2009-0361"]}]},{"id":"CVE-2009-0360","published":"2009-02-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRuss Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does\nnot properly initialize the Kerberos libraries for setuid use, which allows\nlocal users to gain privileges by pointing an environment variable to a\nmodified Kerberos configuration file, and then launching a PAM-based setuid\napplication.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-719-1","https://www.cve.org/CVERecord?id=CVE-2009-0360"],"bugs":[""],"patches":{"libpam-krb5":[]},"tags":{},"packages":[{"name":"libpam-krb5","source":"https://ubuntu.com/security/cve?package=libpam-krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpam-krb5","debian":"https://tracker.debian.org/pkg/libpam-krb5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.10-1ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.10-1ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.11-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.11-4","component":null,"pocket":"security"}]}],"notices_ids":["USN-719-1"],"notices":[{"id":"USN-719-1","title":"pam-krb5 vulnerabilities","summary":"pam-krb5 vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-02-12T19:12:40.422538","description":"It was discovered that pam_krb5 parsed environment variables when run with\nsetuid applications. A local attacker could exploit this flaw to bypass\nauthentication checks and gain root privileges. (CVE-2009-0360)\n\nDerek Chan discovered that pam_krb5 incorrectly handled refreshing existing\ncredentials when used with setuid applications. A local attacker could exploit\nthis to create or overwrite arbitrary files, and possibly gain root privileges.\n(CVE-2009-0361)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libpam-krb5","version":"3.10-1ubuntu0.8.04.1","description":"","is_source":true},{"name":"libpam-krb5","version":"3.10-1ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpam-krb5","version_link":"https://launchpad.net/ubuntu/+source/libpam-krb5/3.10-1ubuntu0.8.04.1"}],"intrepid":[{"name":"libpam-krb5","version":"3.10-1ubuntu0.8.10.1","description":"","is_source":true},{"name":"libpam-krb5","version":"3.10-1ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpam-krb5","version_link":"https://launchpad.net/ubuntu/+source/libpam-krb5/3.10-1ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2009-0360","CVE-2009-0361"]}]},{"id":"CVE-2009-0547","published":"2009-02-12T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nEvolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail\ntext within a signed-data blob, not the copy of the e-mail text displayed\nto the user, which allows remote attackers to spoof a signature by\nmodifying the latter copy, a different vulnerability than CVE-2008-5077.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Patch for CVE-2009-0547 introduces a regression. See links for\nfix."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0547"],"bugs":["http://bugzilla.gnome.org/show_bug.cgi?id=564465","http://bugs.gentoo.org/show_bug.cgi?id=258867","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-0547","https://bugzilla.redhat.com/show_bug.cgi?id=492852","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508479","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=533386"],"patches":{"evolution-data-server":["upstream: http://svn.gnome.org/viewvc/evolution-data-server?view=revision&revision=10106","upstream: http://svn.gnome.org/viewvc/evolution-data-server?view=revision&revision=10194"]},"tags":{},"packages":[{"name":"evolution-data-server","source":"https://ubuntu.com/security/cve?package=evolution-data-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=evolution-data-server","debian":"https://tracker.debian.org/pkg/evolution-data-server","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.26.1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.26.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0544","published":"2009-02-12T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers\nto cause a denial of service and possibly execute arbitrary code via a\nlarge ARC2 key length.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-729-1","https://www.cve.org/CVERecord?id=CVE-2009-0544"],"bugs":[""],"patches":{"python-crypto":[]},"tags":{},"packages":[{"name":"python-crypto","source":"https://ubuntu.com/security/cve?package=python-crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-crypto","debian":"https://tracker.debian.org/pkg/python-crypto","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.1+dfsg1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.1+dfsg1-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.1+dfsg1-2.1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.1+dfsg1-2.3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-729-1"],"notices":[{"id":"USN-729-1","title":"Python Crypto vulnerability","summary":"Python Crypto vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-03-05T22:52:43.706190","description":"Mike Wiacek discovered that the ARC2 implementation in Python Crypto\ndid not correctly check the key length. If a user or automated system\nwere tricked into processing a malicious ARC2 stream, a remote attacker\ncould execute arbitrary code or crash the application using Python Crypto,\nleading to a denial of service.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"python-crypto","version":"2.0.1+dfsg1-2ubuntu1.1","description":"","is_source":true},{"name":"python-crypto","version":"2.0.1+dfsg1-2ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-crypto","version_link":"https://launchpad.net/ubuntu/+source/python-crypto/2.0.1+dfsg1-2ubuntu1.1"}],"dapper":[{"name":"python-crypto","version":"2.0.1+dfsg1-1ubuntu1.1","description":"","is_source":true},{"name":"python2.4-crypto","version":"2.0.1+dfsg1-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-crypto","version_link":"https://launchpad.net/ubuntu/+source/python-crypto/2.0.1+dfsg1-1ubuntu1.1"}],"intrepid":[{"name":"python-crypto","version":"2.0.1+dfsg1-2.3ubuntu0.1","description":"","is_source":true},{"name":"python-crypto","version":"2.0.1+dfsg1-2.3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-crypto","version_link":"https://launchpad.net/ubuntu/+source/python-crypto/2.0.1+dfsg1-2.3ubuntu0.1"}],"hardy":[{"name":"python-crypto","version":"2.0.1+dfsg1-2.1ubuntu1.1","description":"","is_source":true},{"name":"python-crypto","version":"2.0.1+dfsg1-2.1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-crypto","version_link":"https://launchpad.net/ubuntu/+source/python-crypto/2.0.1+dfsg1-2.1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2009-0544"]}]},{"id":"CVE-2009-0543","published":"2009-02-12T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to\nbypass SQL injection protection mechanisms via invalid, encoded multibyte\ncharacters, which are not properly handled in (1) mod_sql_mysql and (2)\nmod_sql_postgres.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0543"],"bugs":[""],"patches":{"proftpd-dfsg":[]},"tags":{},"packages":[{"name":"proftpd-dfsg","source":"https://ubuntu.com/security/cve?package=proftpd-dfsg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=proftpd-dfsg","debian":"https://tracker.debian.org/pkg/proftpd-dfsg","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.3.2-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0542","published":"2009-02-12T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows\nremote attackers to execute arbitrary SQL commands via a \"%\" (percent)\ncharacter in the username, which introduces a \"'\" (single quote) character\nduring variable substitution by mod_sql.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0542"],"bugs":[""],"patches":{"proftpd-dfsg":[]},"tags":{},"packages":[{"name":"proftpd-dfsg","source":"https://ubuntu.com/security/cve?package=proftpd-dfsg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=proftpd-dfsg","debian":"https://tracker.debian.org/pkg/proftpd-dfsg","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.3.2-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.3.2c-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.3.2c-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.3.2c-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.3.2c-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6124","published":"2009-02-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in the hotpot_delete_selected_attempts function\nin report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before\n1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to\nexecute arbitrary SQL commands via a crafted selected attempt.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-791-1","https://www.cve.org/CVERecord?id=CVE-2008-6124"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.2-1.2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-791-1"],"notices":[{"id":"USN-791-1","title":"Moodle vulnerabilities","summary":"Moodle vulnerabilities","instructions":"After a standard system upgrade you need to access the Moodle instance\nand accept the database update to clear any invalid cached data.\n","references":[],"published":"2009-06-24T20:00:13.114186","description":"Thor Larholm discovered that PHPMailer, as used by Moodle, did not\ncorrectly escape email addresses. A local attacker with direct access\nto the Moodle database could exploit this to execute arbitrary commands\nas the web server user. (CVE-2007-3215)\n\nNigel McNie discovered that fetching https URLs did not correctly escape\nshell meta-characters. An authenticated remote attacker could execute\narbitrary commands as the web server user, if curl was installed and\nconfigured. (CVE-2008-4796, MSA-09-0003)\n\nIt was discovered that Smarty (also included in Moodle), did not\ncorrectly filter certain inputs. An authenticated remote attacker could\nexploit this to execute arbitrary PHP commands as the web server user.\n(CVE-2008-4810, CVE-2008-4811, CVE-2009-1669)\n\nIt was discovered that the unused SpellChecker extension in Moodle did not\ncorrectly handle temporary files. If the tool had been locally modified,\nit could be made to overwrite arbitrary local files via symlinks.\n(CVE-2008-5153)\n\nMike Churchward discovered that Moodle did not correctly filter Wiki page\ntitles in certain areas. An authenticated remote attacker could exploit\nthis to cause cross-site scripting (XSS), which could be used to modify\nor steal confidential data of other users within the same web domain.\n(CVE-2008-5432, MSA-08-0022)\n\nIt was discovered that the HTML sanitizer, \"Login as\" feature, and logging\nin Moodle did not correctly handle certain inputs. An authenticated\nremote attacker could exploit this to generate XSS, which could be used\nto modify or steal confidential data of other users within the same\nweb domain. (CVE-2008-5619, CVE-2009-0500, CVE-2009-0502, MSA-08-0026,\nMSA-09-0004, MSA-09-0007)\n\nIt was discovered that the HotPot module in Moodle did not correctly\nfilter SQL inputs. An authenticated remote attacker could execute\narbitrary SQL commands as the moodle database user, leading to a loss\nof privacy or denial of service. (CVE-2008-6124, MSA-08-0010)\n\nKevin Madura discovered that the forum actions and messaging settings\nin Moodle were not protected from cross-site request forgery (CSRF).\nIf an authenticated user were tricked into visiting a malicious\nwebsite while logged into Moodle, a remote attacker could change the\nuser's configurations or forum content. (CVE-2009-0499, MSA-09-0008,\nMSA-08-0023)\n\nDaniel Cabezas discovered that Moodle would leak usernames from the\nCalendar Export tool. A remote attacker could gather a list of users,\nleading to a loss of privacy. (CVE-2009-0501, MSA-09-0006)\n\nChristian Eibl discovered that the TeX filter in Moodle allowed any\nfunction to be used. An authenticated remote attacker could post\na specially crafted TeX formula to execute arbitrary TeX functions,\npotentially reading any file accessible to the web server user, leading\nto a loss of privacy. (CVE-2009-1171, MSA-09-0009)\n\nJohannes Kuhn discovered that Moodle did not correctly validate user\npermissions when attempting to switch user accounts. An authenticated\nremote attacker could switch to any other Moodle user, leading to a loss\nof privacy. (MSA-08-0003)\n\nHanno Boeck discovered that unconfigured Moodle instances contained\nXSS vulnerabilities. An unauthenticated remote attacker could exploit\nthis to modify or steal confidential data of other users within the same\nweb domain. (MSA-08-0004)\n\nDebbie McDonald, Mauno Korpelainen, Howard Miller, and Juan Segarra\nMontesinos discovered that when users were deleted from Moodle, their\nprofiles and avatars were still visible. An authenticated remote attacker\ncould exploit this to store information in profiles even after they were\nremoved, leading to spam traffic. (MSA-08-0015, MSA-09-0001, MSA-09-0002)\n\nLars Vogdt discovered that Moodle did not correctly filter certain inputs.\nAn authenticated remote attacker could exploit this to generate XSS from\nwhich they could modify or steal confidential data of other users within\nthe same web domain. (MSA-08-0021)\n\nIt was discovered that Moodle did not correctly filter inputs for group\ncreation, mnet, essay question, HOST param, wiki param, and others.\nAn authenticated remote attacker could exploit this to generate XSS\nfrom which they could modify or steal confidential data of other users\nwithin the same web domain. (MDL-9288, MDL-11759, MDL-12079, MDL-12793,\nMDL-14806)\n\nIt was discovered that Moodle did not correctly filter SQL inputs when\nperforming a restore. An attacker authenticated as a Moodle administrator\ncould execute arbitrary SQL commands as the moodle database user,\nleading to a loss of privacy or denial of service. (MDL-11857)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"moodle","version":"1.8.2-1ubuntu4.2","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1ubuntu4.2"}],"intrepid":[{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1.2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2009-0500","CVE-2007-3215","CVE-2008-5619","CVE-2009-0502","CVE-2008-5432","CVE-2008-5153","CVE-2009-0499","CVE-2008-4810","CVE-2009-0501","CVE-2008-6124","CVE-2008-4796","CVE-2008-4811","CVE-2009-1171","CVE-2009-1669"]}]},{"id":"CVE-2009-0036","published":"2009-02-11T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the proxyReadClientSocket function in\nproxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to\ngain privileges by sending a portion of the header of a virProxyPacket\npacket, and then sending the remainder of the packet with crafted values in\nthe header, related to use of uninitialized memory in a validation check.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"code exists but is not compiled on Ubuntu"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0036"],"bugs":[""],"patches":{"libvirt":[]},"tags":{},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.6.1-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6107","published":"2009-02-10T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) sys32_mremap function in arch/sparc64/kernel/sys_sparc32.c, the (2)\nsparc_mmap_check function in arch/sparc/kernel/sys_sparc.c, and the (3)\nsparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the\nLinux kernel before 2.6.25.4, omit some virtual-address range (aka span)\nchecks when the mremap MREMAP_FIXED bit is not set, which allows local\nusers to cause a denial of service (panic) via unspecified mremap calls, a\nrelated issue to CVE-2008-2137.","ubuntu_description":"\nSparc syscalls did not correctly check mmap regions. A local attacker\ncould cause a system panic, leading to a denial of service.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-751-1","https://ubuntu.com/security/notices/USN-752-1","https://www.cve.org/CVERecord?id=CVE-2008-6107"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-23.52","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-11.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.25.4","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-54.76","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-16.62","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-752-1","USN-751-1"],"notices":[{"id":"USN-752-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2009-04-07T15:53:43.401037","description":"NFS did not correctly handle races between fcntl and interrupts. A local\nattacker on an NFS mount could consume unlimited kernel memory, leading to\na denial of service. (CVE-2008-4307)\n\nSparc syscalls did not correctly check mmap regions. A local attacker could\ncause a system panic, leading to a denial of service. (CVE-2008-6107)\n\nIn certain situations, cloned processes were able to send signals to parent\nprocesses, crossing privilege boundaries. A local attacker could send\narbitrary signals to parent processes, leading to a denial of service.\n(CVE-2009-0028)\n\nThe 64-bit syscall interfaces did not correctly handle sign extension. A\nlocal attacker could make malicious syscalls, possibly gaining root\nprivileges. The x86_64 architecture was not affected. (CVE-2009-0029)\n\nThe SCTP stack did not correctly validate FORWARD-TSN packets. A remote\nattacker could send specially crafted SCTP traffic causing a system crash,\nleading to a denial of service. (CVE-2009-0065)\n\nThe Dell platform device did not correctly validate user parameters. A\nlocal attacker could perform specially crafted reads to crash the system,\nleading to a denial of service. (CVE-2009-0322)\n\nNetwork interfaces statistics for the SysKonnect FDDI driver did not check\ncapabilities. A local user could reset statistics, potentially interfering\nwith packet accounting systems. (CVE-2009-0675)\n\nThe getsockopt function did not correctly clear certain parameters. A local\nattacker could read leaked kernel memory, leading to a loss of privacy.\n(CVE-2009-0676)\n\nThe syscall interface did not correctly validate parameters when crossing\nthe 64-bit/32-bit boundary. A local attacker could bypass certain syscall\nrestricts via crafted syscalls. (CVE-2009-0834, CVE-2009-0835)\n\nThe shared memory subsystem did not correctly handle certain shmctl calls\nwhen CONFIG_SHMEM was disabled. Ubuntu kernels were not vulnerable, since\nCONFIG_SHMEM is enabled by default. (CVE-2009-0859)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-54.76","description":"","is_source":true},{"name":"linux-image-2.6.15-54-hppa64","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-hppa32-smp","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-server-bigiron","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-amd64-generic","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-itanium","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-k7","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-powerpc-smp","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-server","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-amd64-server","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-sparc64-smp","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-sparc64","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-mckinley-smp","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-amd64-k8","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-386","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-mckinley","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-hppa32","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-amd64-xeon","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-powerpc","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-powerpc64-smp","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-itanium-smp","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-686","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"},{"name":"linux-image-2.6.15-54-hppa64-smp","version":"2.6.15-54.76","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-54.76"}]},"type":"USN","cves_ids":["CVE-2009-0029","CVE-2008-4307","CVE-2008-6107","CVE-2009-0028","CVE-2009-0065","CVE-2009-0322","CVE-2009-0675","CVE-2009-0676","CVE-2009-0834","CVE-2009-0835","CVE-2009-0859"]},{"id":"USN-751-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2009-04-06T23:52:35.518644","description":"NFS did not correctly handle races between fcntl and interrupts. A local\nattacker on an NFS mount could consume unlimited kernel memory, leading to\na denial of service. Ubuntu 8.10 was not affected. (CVE-2008-4307)\n\nSparc syscalls did not correctly check mmap regions. A local attacker\ncould cause a system panic, leading to a denial of service. Ubuntu 8.10\nwas not affected. (CVE-2008-6107)\n\nIn certain situations, cloned processes were able to send signals to parent\nprocesses, crossing privilege boundaries. A local attacker could send\narbitrary signals to parent processes, leading to a denial of service.\n(CVE-2009-0028)\n\nThe kernel keyring did not free memory correctly. A local attacker could\nconsume unlimited kernel memory, leading to a denial of service.\n(CVE-2009-0031)\n\nThe SCTP stack did not correctly validate FORWARD-TSN packets. A remote\nattacker could send specially crafted SCTP traffic causing a system crash,\nleading to a denial of service. (CVE-2009-0065)\n\nThe eCryptfs filesystem did not correctly handle certain VFS return codes.\nA local attacker with write-access to an eCryptfs filesystem could cause a\nsystem crash, leading to a denial of service. (CVE-2009-0269)\n\nThe Dell platform device did not correctly validate user parameters. A\nlocal attacker could perform specially crafted reads to crash the system,\nleading to a denial of service. (CVE-2009-0322)\n\nThe page fault handler could consume stack memory. A local attacker could\nexploit this to crash the system or gain root privileges with a Kprobe\nregistered. Only Ubuntu 8.10 was affected. (CVE-2009-0605)\n\nNetwork interfaces statistics for the SysKonnect FDDI driver did not check\ncapabilities. A local user could reset statistics, potentially interfering\nwith packet accounting systems. (CVE-2009-0675)\n\nThe getsockopt function did not correctly clear certain parameters. A local\nattacker could read leaked kernel memory, leading to a loss of privacy.\n(CVE-2009-0676)\n\nThe ext4 filesystem did not correctly clear group descriptors when\nresizing. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2009-0745)\n\nThe ext4 filesystem did not correctly validate certain fields. A local\nattacker could mount a malicious ext4 filesystem, causing a system\ncrash, leading to a denial of service. (CVE-2009-0746, CVE-2009-0747,\nCVE-2009-0748)\n\nThe syscall interface did not correctly validate parameters when crossing\nthe 64-bit/32-bit boundary. A local attacker could bypass certain syscall\nrestricts via crafted syscalls. (CVE-2009-0834, CVE-2009-0835)\n\nThe shared memory subsystem did not correctly handle certain shmctl calls\nwhen CONFIG_SHMEM was disabled. Ubuntu kernels were not vulnerable, since\nCONFIG_SHMEM is enabled by default. (CVE-2009-0859)\n\nThe virtual consoles did not correctly handle certain UTF-8 sequences. A\nlocal attacker on the physical console could exploit this to cause a system\ncrash, leading to a denial of service. (CVE-2009-1046)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-16.62","description":"","is_source":true},{"name":"linux-image-2.6.22-16-mckinley","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-powerpc64-smp","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-virtual","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-cell","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-hppa64","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-sparc64-smp","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-generic","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-lpia","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-powerpc-smp","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-386","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-hppa32","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-rt","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-xen","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-powerpc","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-itanium","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-lpiacompat","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-ume","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-sparc64","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-server","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"}],"intrepid":[{"name":"linux","version":"2.6.27-11.31","description":"","is_source":true},{"name":"linux-image-2.6.27-11-server","version":"2.6.27-11.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.31"},{"name":"linux-image-2.6.27-11-generic","version":"2.6.27-11.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.31"},{"name":"linux-image-2.6.27-11-virtual","version":"2.6.27-11.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.31"}],"hardy":[{"name":"linux","version":"2.6.24-23.52","description":"","is_source":true},{"name":"linux-image-2.6.24-23-virtual","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-server","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-mckinley","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-sparc64-smp","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-xen","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-powerpc-smp","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-lpiacompat","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-sparc64","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-rt","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-openvz","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-lpia","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-hppa64","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-386","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-powerpc","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-powerpc64-smp","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-itanium","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-hppa32","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-generic","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"}]},"type":"USN","cves_ids":["CVE-2008-4307","CVE-2008-6107","CVE-2009-0028","CVE-2009-0031","CVE-2009-0065","CVE-2009-0269","CVE-2009-0322","CVE-2009-0605","CVE-2009-0675","CVE-2009-0676","CVE-2009-0745","CVE-2009-0746","CVE-2009-0747","CVE-2009-0748","CVE-2009-0834","CVE-2009-0835","CVE-2009-0859","CVE-2009-1046"]}]},{"id":"CVE-2008-6072","published":"2009-02-10T06:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and\n1.2.x before 1.2.3, allow remote attackers to cause a denial of service\n(crash) via unspecified vectors in (1) XCF and (2) CINEON images.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6072"],"bugs":[""],"patches":{"graphicsmagick":[]},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.11-3.2+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6071","published":"2009-02-10T06:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the DecodeImage function in coders/pict.c in\nGraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allows remote\nattackers to cause a denial of service (crash) or possibly execute\narbitrary code via a crafted PICT image. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6071"],"bugs":[""],"patches":{"graphicsmagick":[]},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.11-3.2+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6070","published":"2009-02-10T06:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple heap-based buffer underflows in the ReadPALMImage function in\ncoders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to\ncause a denial of service (crash) or possibly execute arbitrary code via a\ncrafted PALM image, a different vulnerability than CVE-2007-0770. NOTE:\nsome of these details are obtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6070"],"bugs":[""],"patches":{"graphicsmagick":[]},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.11-3.2+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.3.5-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":74400,"limit":20,"total_results":79316}