{"cves":[{"id":"CVE-2009-0316","published":"2009-01-28T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in src/if_python.c in the Python\ninterface in Vim before 7.2.045 allows local users to execute arbitrary\ncode via a Trojan horse Python file in the current working directory,\nrelated to a vulnerability in the PySys_SetArgv function (CVE-2008-5983),\nas demonstrated by an erroneous search path for plugin/bike.vim in\nbicyclerepair.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0316"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/vim/+bug/322196","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937"],"patches":{"vim":["upstream: ftp://ftp.vim.org/pub/vim/patches/7.2/7.2.045"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2:7.2.079-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:7.2.025-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0315","published":"2009-01-28T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in the Python module in xchat allows\nlocal users to execute arbitrary code via a Trojan horse Python file in the\ncurrent working directory, related to a vulnerability in the PySys_SetArgv\nfunction (CVE-2008-5983).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0315"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/xchat/+bug/322196"],"patches":{"xchat":[]},"tags":{},"packages":[{"name":"xchat","source":"https://ubuntu.com/security/cve?package=xchat","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xchat","debian":"https://tracker.debian.org/pkg/xchat","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.8.4-0ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.8.6-2.1ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.8.6-2.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0314","published":"2009-01-28T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in the Python module in gedit allows\nlocal users to execute arbitrary code via a Trojan horse Python file in the\ncurrent working directory, related to a vulnerability in the PySys_SetArgv\nfunction (CVE-2008-5983).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0314"],"bugs":["http://bugzilla.gnome.org/show_bug.cgi?id=569214"],"patches":{"gedit":["upstream: http://git.gnome.org/browse/libpeas/commit/?id=664d5e2ad22ac1acc39bdcf9186dc8ce734c0fcf"]},"tags":{},"packages":[{"name":"gedit","source":"https://ubuntu.com/security/cve?package=gedit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gedit","debian":"https://tracker.debian.org/pkg/gedit","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.24.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5987","published":"2009-01-28T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in the Python interface in Eye of GNOME\n(eog) 2.22.3, and possibly other versions, allows local users to execute\narbitrary code via a Trojan horse Python file in the current working\ndirectory, related to a vulnerability in the PySys_SetArgv function\n(CVE-2008-5983).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5987"],"bugs":[""],"patches":{"eog":[]},"tags":{},"packages":[{"name":"eog","source":"https://ubuntu.com/security/cve?package=eog","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eog","debian":"https://tracker.debian.org/pkg/eog","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.24.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22.3-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5986","published":"2009-01-28T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in the (1) \"VST plugin with Python\nscripting\" and (2) \"VST plugin for writing score generators in Python\" in\nCsound 5.08.2, and possibly other versions, allows local users to execute\narbitrary code via a Trojan horse Python file in the current working\ndirectory, related to a vulnerability in the PySys_SetArgv function\n(CVE-2008-5983).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5986"],"bugs":[""],"patches":{"csound":[]},"tags":{},"packages":[{"name":"csound","source":"https://ubuntu.com/security/cve?package=csound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=csound","debian":"https://tracker.debian.org/pkg/csound","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1:5.08.2~dfsg-1.1ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:5.08.2~dfsg-1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5985","published":"2009-01-28T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in the Python interface in Epiphany\n2.22.3, and possibly other versions, allows local users to execute\narbitrary code via a Trojan horse Python file in the current working\ndirectory, related to a vulnerability in the PySys_SetArgv function\n(CVE-2008-5983).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5985"],"bugs":["https://bugs.launchpad.net/bugs/322196"],"patches":{"epiphany-browser":[]},"tags":{},"packages":[{"name":"epiphany-browser","source":"https://ubuntu.com/security/cve?package=epiphany-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=epiphany-browser","debian":"https://tracker.debian.org/pkg/epiphany-browser","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.24.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22.3-7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5984","published":"2009-01-28T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in the Python plugin in Dia 0.96.1, and\npossibly other versions, allows local users to execute arbitrary code via a\nTrojan horse Python file in the current working directory, related to a\nvulnerability in the PySys_SetArgv function (CVE-2008-5983).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5984"],"bugs":["https://bugs.launchpad.net/bugs/322196"],"patches":{"dia":[]},"tags":{},"packages":[{"name":"dia","source":"https://ubuntu.com/security/cve?package=dia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dia","debian":"https://tracker.debian.org/pkg/dia","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.96.1-7.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.96.1-7.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0312","published":"2009-01-28T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the antispam feature\n(security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to\ninject arbitrary web script or HTML via crafted, disallowed content.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"XSS issue in antispam.py"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-716-1","https://www.cve.org/CVERecord?id=CVE-2009-0312"],"bugs":[""],"patches":{"moin":["other: http://hg.moinmo.in/moin/1.7/rev/89b91bf87dad"]},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.2-1ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.5.7-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.8-5.1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.7.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.1-1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-716-1"],"notices":[{"id":"USN-716-1","title":"MoinMoin vulnerabilities","summary":"MoinMoin vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-01-30T02:21:53.757794","description":"Fernando Quintero discovered than MoinMoin did not properly sanitize its\ninput when processing login requests, resulting in cross-site scripting (XSS)\nvulnerabilities. With cross-site scripting vulnerabilities, if a user were\ntricked into viewing server output during a crafted server request, a remote\nattacker could exploit this to modify the contents, or steal confidential data,\nwithin the same domain. This issue affected Ubuntu 7.10 and 8.04 LTS.\n(CVE-2008-0780)\n\nFernando Quintero discovered that MoinMoin did not properly sanitize its input\nwhen attaching files, resulting in cross-site scripting vulnerabilities. This\nissue affected Ubuntu 6.06 LTS, 7.10 and 8.04 LTS. (CVE-2008-0781)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\nprocessing user forms. A remote attacker could submit crafted cookie values and\noverwrite arbitrary files via directory traversal. This issue affected Ubuntu\n6.06 LTS, 7.10 and 8.04 LTS. (CVE-2008-0782)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\nediting pages, resulting in cross-site scripting vulnerabilities. This issue\nonly affected Ubuntu 6.06 LTS and 7.10. (CVE-2008-1098)\n\nIt was discovered that MoinMoin did not properly enforce access controls,\nwhich could allow a remoter attacker to view private pages. This issue only\naffected Ubuntu 6.06 LTS and 7.10. (CVE-2008-1099)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\nattaching files and using the rename parameter, resulting in cross-site\nscripting vulnerabilities. (CVE-2009-0260)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\ndisplaying error messages after processing spam, resulting in cross-site\nscripting vulnerabilities. (CVE-2009-0312)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"moin","version":"1.5.7-3ubuntu2.1","description":"","is_source":true},{"name":"python-moinmoin","version":"1.5.7-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.7-3ubuntu2.1"}],"dapper":[{"name":"moin","version":"1.5.2-1ubuntu2.4","description":"","is_source":true},{"name":"python2.4-moinmoin","version":"1.5.2-1ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.2-1ubuntu2.4"}],"intrepid":[{"name":"moin","version":"1.7.1-1ubuntu1.1","description":"","is_source":true},{"name":"python-moinmoin","version":"1.7.1-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.7.1-1ubuntu1.1"}],"hardy":[{"name":"moin","version":"1.5.8-5.1ubuntu2.2","description":"","is_source":true},{"name":"python-moinmoin","version":"1.5.8-5.1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.8-5.1ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2008-1098","CVE-2008-0782","CVE-2008-0780","CVE-2009-0260","CVE-2008-0781","CVE-2008-1099","CVE-2009-0312"]}]},{"id":"CVE-2009-0032","published":"2009-01-27T20:30:00","updated_at":"2025-07-17T16:42:26.795874+00:00","description":"\nCUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0\nand 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to\noverwrite arbitrary files via a symlink attack on the /tmp/pdf.log\ntemporary file.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Mandriva specific, issue affects pdfdistiller"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0032"],"bugs":[""],"patches":{"cups":[],"cupsys":[]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0282","published":"2009-01-27T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for\nWindows, and other wireless card drivers including rt2400, rt2500, rt2570,\nand rt61, allows remote attackers to cause a denial of service (crash) and\npossibly execute arbitrary code via a Probe Request packet with a long\nSSID, possibly related to an integer signedness error.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0282"],"bugs":[""],"patches":{"rt2570":[],"rt73":[],"rt2400":[],"rt2500":[]},"tags":{},"packages":[{"name":"rt2400","source":"https://ubuntu.com/security/cve?package=rt2400","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rt2400","debian":"https://tracker.debian.org/pkg/rt2400","statuses":[{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.2.2+cvs20080623-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.2+cvs20080623-3","component":null,"pocket":"security"}]},{"name":"rt2500","source":"https://ubuntu.com/security/cve?package=rt2500","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rt2500","debian":"https://tracker.debian.org/pkg/rt2500","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1:1.1.0-b4+cvs20080623-3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.1.0-b4+cvs20080623-3","component":null,"pocket":"security"}]},{"name":"rt2570","source":"https://ubuntu.com/security/cve?package=rt2570","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rt2570","debian":"https://tracker.debian.org/pkg/rt2570","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.1.0+cvs20080623-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"pulled 2010-07-27","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.0+cvs20080623-2","component":null,"pocket":"security"}]},{"name":"rt73","source":"https://ubuntu.com/security/cve?package=rt73","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rt73","debian":"https://tracker.debian.org/pkg/rt73","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.0.3.6-cvs20080623-dfsg1-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5983","published":"2009-01-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in the PySys_SetArgv API function in\nPython 2.6 and earlier, and possibly later versions, prepends an empty\nstring to sys.path when the argv[0] argument does not contain a path\nseparator, which might allow local users to execute arbitrary code via a\nTrojan horse Python file in the current working directory.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"upstream added new C API function, PySys_SetArgvEx, which can\nbe used to set sys.argv without also modifying sys.path. The default\nbehavior for PySys_SetArgv does not change."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1596-1","https://ubuntu.com/security/notices/USN-1613-1","https://ubuntu.com/security/notices/USN-1613-2","https://ubuntu.com/security/notices/USN-1616-1","https://www.cve.org/CVERecord?id=CVE-2008-5983"],"bugs":["https://bugs.launchpad.net/bugs/322196","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937","http://bugs.python.org/issue5753","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=572010"],"patches":{"python2.4":[],"python2.5":[],"python2.6":["upstream: http://hg.python.org/cpython/rev/3f08d98c8fa5/"],"python2.7":[],"python3.1":["upstream: http://hg.python.org/cpython/rev/9db8c414921f/"],"python3.2":[]},"tags":{},"packages":[{"name":"python2.4","source":"https://ubuntu.com/security/cve?package=python2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.4","debian":"https://tracker.debian.org/pkg/python2.4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.4.5-1ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python2.5","source":"https://ubuntu.com/security/cve?package=python2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.5","debian":"https://tracker.debian.org/pkg/python2.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.5.2-2ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python2.6","source":"https://ubuntu.com/security/cve?package=python2.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.6","debian":"https://tracker.debian.org/pkg/python2.6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.5-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.6.6-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.5+20100529-1","component":null,"pocket":"security"}]},{"name":"python2.7","source":"https://ubuntu.com/security/cve?package=python2.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.7","debian":"https://tracker.debian.org/pkg/python2.7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.7-6","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7-1","component":null,"pocket":"security"}]},{"name":"python3.1","source":"https://ubuntu.com/security/cve?package=python3.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.1","debian":"https://tracker.debian.org/pkg/python3.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.1.2-0ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.1.3-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.3-1","component":null,"pocket":"security"}]},{"name":"python3.2","source":"https://ubuntu.com/security/cve?package=python3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.2","debian":"https://tracker.debian.org/pkg/python3.2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1613-1","USN-1613-2","USN-1616-1","USN-1596-1"],"notices":[{"id":"USN-1613-1","title":"Python 2.5 vulnerabilities","summary":"Several security issues were fixed in Python 2.5.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-10-17T13:09:19.200949","description":"It was discovered that Python would prepend an empty string to sys.path\nunder certain circumstances. A local attacker with write access to the\ncurrent working directory could exploit this to execute arbitrary code.\n(CVE-2008-5983)\n\nIt was discovered that the audioop module did not correctly perform input\nvalidation. If a user or automatated system were tricked into opening a\ncrafted audio file, an attacker could cause a denial of service via\napplication crash. (CVE-2010-1634, CVE-2010-2089)\n\nGiampaolo Rodola discovered several race conditions in the smtpd module.\nA remote attacker could exploit this to cause a denial of service via\ndaemon outage. (CVE-2010-3493)\n\nIt was discovered that the CGIHTTPServer module did not properly perform\ninput validation on certain HTTP GET requests. A remote attacker could\npotentially obtain access to CGI script source files. (CVE-2011-1015)\n\nNiels Heinen discovered that the urllib and urllib2 modules would process\nLocation headers that specify a redirection to file: URLs. A remote\nattacker could exploit this to obtain sensitive information or cause a\ndenial of service. (CVE-2011-1521)\n\nIt was discovered that SimpleHTTPServer did not use a charset parameter in\nthe Content-Type HTTP header. An attacker could potentially exploit this\nto conduct cross-site scripting (XSS) attacks against Internet Explorer 7\nusers. (CVE-2011-4940)\n\nIt was discovered that Python distutils contained a race condition when\ncreating the ~/.pypirc file. A local attacker could exploit this to obtain\nsensitive information. (CVE-2011-4944)\n\nIt was discovered that SimpleXMLRPCServer did not properly validate its\ninput when handling HTTP POST requests. A remote attacker could exploit\nthis to cause a denial of service via excessive CPU utilization.\n(CVE-2012-0845)\n\nIt was discovered that the Expat module in Python 2.5 computed hash values\nwithout restricting the ability to trigger hash collisions predictably. If\na user or application using pyexpat were tricked into opening a crafted XML\nfile, an attacker could cause a denial of service by consuming excessive\nCPU resources. (CVE-2012-0876)\n\nTim Boddy discovered that the Expat module in Python 2.5 did not properly\nhandle memory reallocation when processing XML files. If a user or\napplication using pyexpat were tricked into opening a crafted XML file, an\nattacker could cause a denial of service by consuming excessive memory\nresources. (CVE-2012-1148)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"python2.5","version":"2.5.2-2ubuntu6.2","description":"An interactive high-level object-oriented language (version 2.5)","is_source":true},{"name":"python2.5-minimal","version":"2.5.2-2ubuntu6.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.5","version_link":"https://launchpad.net/ubuntu/+source/python2.5/2.5.2-2ubuntu6.2"},{"name":"python2.5","version":"2.5.2-2ubuntu6.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.5","version_link":"https://launchpad.net/ubuntu/+source/python2.5/2.5.2-2ubuntu6.2"}]},"type":"USN","cves_ids":["CVE-2008-5983","CVE-2010-1634","CVE-2010-2089","CVE-2010-3493","CVE-2011-1015","CVE-2011-1521","CVE-2011-4940","CVE-2011-4944","CVE-2012-0845","CVE-2012-0876","CVE-2012-1148"]},{"id":"USN-1613-2","title":"Python 2.4 vulnerabilities","summary":"Several security issues were fixed in Python 2.4.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-10-17T20:04:18.574469","description":"USN-1613-1 fixed vulnerabilities in Python 2.5. This update provides the\ncorresponding updates for Python 2.4.\n\nOriginal advisory details:\n\n It was discovered that Python would prepend an empty string to sys.path\n under certain circumstances. A local attacker with write access to the\n current working directory could exploit this to execute arbitrary code.\n (CVE-2008-5983)\n \n It was discovered that the audioop module did not correctly perform input\n validation. If a user or automatated system were tricked into opening a\n crafted audio file, an attacker could cause a denial of service via\n application crash. (CVE-2010-1634, CVE-2010-2089)\n \n Giampaolo Rodola discovered several race conditions in the smtpd module.\n A remote attacker could exploit this to cause a denial of service via\n daemon outage. (CVE-2010-3493)\n \n It was discovered that the CGIHTTPServer module did not properly perform\n input validation on certain HTTP GET requests. A remote attacker could\n potentially obtain access to CGI script source files. (CVE-2011-1015)\n \n Niels Heinen discovered that the urllib and urllib2 modules would process\n Location headers that specify a redirection to file: URLs. A remote\n attacker could exploit this to obtain sensitive information or cause a\n denial of service. (CVE-2011-1521)\n \n It was discovered that SimpleHTTPServer did not use a charset parameter in\n the Content-Type HTTP header. An attacker could potentially exploit this\n to conduct cross-site scripting (XSS) attacks against Internet Explorer 7\n users. (CVE-2011-4940)\n \n It was discovered that Python distutils contained a race condition when\n creating the ~/.pypirc file. A local attacker could exploit this to obtain\n sensitive information. (CVE-2011-4944)\n \n It was discovered that SimpleXMLRPCServer did not properly validate its\n input when handling HTTP POST requests. A remote attacker could exploit\n this to cause a denial of service via excessive CPU utilization.\n (CVE-2012-0845)\n \n It was discovered that the Expat module in Python 2.5 computed hash values\n without restricting the ability to trigger hash collisions predictably. If\n a user or application using pyexpat were tricked into opening a crafted XML\n file, an attacker could cause a denial of service by consuming excessive\n CPU resources. (CVE-2012-0876)\n \n Tim Boddy discovered that the Expat module in Python 2.5 did not properly\n handle memory reallocation when processing XML files. If a user or\n application using pyexpat were tricked into opening a crafted XML file, an\n attacker could cause a denial of service by consuming excessive memory\n resources. (CVE-2012-1148)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"python2.4","version":"2.4.5-1ubuntu4.4","description":"An interactive high-level object-oriented language (version 2.4)","is_source":true},{"name":"python2.4-minimal","version":"2.4.5-1ubuntu4.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.4","version_link":"https://launchpad.net/ubuntu/+source/python2.4/2.4.5-1ubuntu4.4"},{"name":"python2.4","version":"2.4.5-1ubuntu4.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.4","version_link":"https://launchpad.net/ubuntu/+source/python2.4/2.4.5-1ubuntu4.4"}]},"type":"USN","cves_ids":["CVE-2010-2089","CVE-2011-1015","CVE-2008-5983","CVE-2010-1634","CVE-2010-3493","CVE-2011-1521","CVE-2011-4940","CVE-2011-4944","CVE-2012-0845","CVE-2012-0876","CVE-2012-1148"]},{"id":"USN-1616-1","title":"Python 3.1 vulnerabilities","summary":"Several security issues were fixed in Python 3.1.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-10-24T15:51:47.087706","description":"It was discovered that Python would prepend an empty string to sys.path\nunder certain circumstances. A local attacker with write access to the\ncurrent working directory could exploit this to execute arbitrary code.\nThis issue only affected Ubuntu 10.04 LTS. (CVE-2008-5983)\n\nIt was discovered that the audioop module did not correctly perform input\nvalidation. If a user or automatated system were tricked into opening a\ncrafted audio file, an attacker could cause a denial of service via\napplication crash. These issues only affected Ubuntu 10.04 LTS.\n(CVE-2010-1634, CVE-2010-2089)\n\nIt was discovered that Python distutils contained a race condition when\ncreating the ~/.pypirc file. A local attacker could exploit this to obtain\nsensitive information. (CVE-2011-4944)\n\nIt was discovered that SimpleXMLRPCServer did not properly validate its\ninput when handling HTTP POST requests. A remote attacker could exploit\nthis to cause a denial of service via excessive CPU utilization.\n(CVE-2012-0845)\n\nIt was discovered that Python was susceptible to hash algorithm attacks.\nAn attacker could cause a denial of service under certian circumstances.\nThis update adds the '-R' command line option and honors setting the\nPYTHONHASHSEED environment variable to 'random' to salt str and datetime\nobjects with an unpredictable value. (CVE-2012-1150)\n\nSerhiy Storchaka discovered that the UTF16 decoder in Python did not\nproperly reset internal variables after error handling. An attacker could\nexploit this to cause a denial of service via memory corruption.\n(CVE-2012-2135)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"python3.1","version":"3.1.2-0ubuntu3.2","description":"An interactive high-level object-oriented language (version 3.1)","is_source":true},{"name":"python3.1-minimal","version":"3.1.2-0ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.1","version_link":"https://launchpad.net/ubuntu/+source/python3.1/3.1.2-0ubuntu3.2"},{"name":"python3.1","version":"3.1.2-0ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.1","version_link":"https://launchpad.net/ubuntu/+source/python3.1/3.1.2-0ubuntu3.2"}],"natty":[{"name":"python3.1","version":"3.1.3-1ubuntu1.2","description":"An interactive high-level object-oriented language (version 3.1)","is_source":true},{"name":"python3.1-minimal","version":"3.1.3-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.1","version_link":"https://launchpad.net/ubuntu/+source/python3.1/3.1.3-1ubuntu1.2"},{"name":"python3.1","version":"3.1.3-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.1","version_link":"https://launchpad.net/ubuntu/+source/python3.1/3.1.3-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2008-5983","CVE-2010-1634","CVE-2010-2089","CVE-2011-4944","CVE-2012-0845","CVE-2012-1150","CVE-2012-2135"]},{"id":"USN-1596-1","title":"Python 2.6 vulnerabilities","summary":"Several security issues were fixed in Python 2.6.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-10-04T21:40:32.857994","description":"It was discovered that Python would prepend an empty string to sys.path\nunder certain circumstances. A local attacker with write access to the\ncurrent working directory could exploit this to execute arbitrary code.\n(CVE-2008-5983)\n\nIt was discovered that the audioop module did not correctly perform input\nvalidation. If a user or automatated system were tricked into opening a\ncrafted audio file, an attacker could cause a denial of service via\napplication crash. (CVE-2010-1634, CVE-2010-2089)\n\nGiampaolo Rodola discovered several race conditions in the smtpd module.\nA remote attacker could exploit this to cause a denial of service via\ndaemon outage. (CVE-2010-3493)\n\nIt was discovered that the CGIHTTPServer module did not properly perform\ninput validation on certain HTTP GET requests. A remote attacker could\npotentially obtain access to CGI script source files. (CVE-2011-1015)\n\nNiels Heinen discovered that the urllib and urllib2 modules would process\nLocation headers that specify a redirection to file: URLs. A remote\nattacker could exploit this to obtain sensitive information or cause a\ndenial of service. This issue only affected Ubuntu 11.04. (CVE-2011-1521)\n\nIt was discovered that SimpleHTTPServer did not use a charset parameter in\nthe Content-Type HTTP header. An attacker could potentially exploit this\nto conduct cross-site scripting (XSS) attacks against Internet Explorer 7\nusers. This issue only affected Ubuntu 11.04. (CVE-2011-4940)\n\nIt was discovered that Python distutils contained a race condition when\ncreating the ~/.pypirc file. A local attacker could exploit this to obtain\nsensitive information. (CVE-2011-4944)\n\nIt was discovered that SimpleXMLRPCServer did not properly validate its\ninput when handling HTTP POST requests. A remote attacker could exploit\nthis to cause a denial of service via excessive CPU utilization.\n(CVE-2012-0845)\n\nIt was discovered that Python was susceptible to hash algorithm attacks.\nAn attacker could cause a denial of service under certian circumstances.\nThis update adds the '-R' command line option and honors setting the\nPYTHONHASHSEED environment variable to 'random' to salt str and datetime\nobjects with an unpredictable value. (CVE-2012-1150)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"python2.6","version":"2.6.5-1ubuntu6.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.6-minimal","version":"2.6.5-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.5-1ubuntu6.1"},{"name":"python2.6","version":"2.6.5-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.5-1ubuntu6.1"}],"natty":[{"name":"python2.6","version":"2.6.6-6ubuntu7.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.6-minimal","version":"2.6.6-6ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.6-6ubuntu7.1"},{"name":"python2.6","version":"2.6.6-6ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.6-6ubuntu7.1"}],"oneiric":[{"name":"python2.6","version":"2.6.7-4ubuntu1.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.6-minimal","version":"2.6.7-4ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.7-4ubuntu1.1"},{"name":"python2.6","version":"2.6.7-4ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.7-4ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2008-5983","CVE-2010-1634","CVE-2010-2089","CVE-2010-3493","CVE-2011-1015","CVE-2011-1521","CVE-2011-4940","CVE-2011-4944","CVE-2012-0845","CVE-2012-1150"]}]},{"id":"CVE-2008-5968","published":"2009-01-26T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in print.php in PHP iCalendar 2.24 and\nearlier allows remote attackers to include and execute arbitrary local\nfiles via a .. (dot dot) in the cookie_language parameter in a\nphpicalendar_* cookie, a different vector than CVE-2006-1292.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5968"],"bugs":[""],"patches":{"phpicalendar":[]},"tags":{},"packages":[{"name":"phpicalendar","source":"https://ubuntu.com/security/cve?package=phpicalendar","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpicalendar","debian":"https://tracker.debian.org/pkg/phpicalendar","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5967","published":"2009-01-26T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nadmin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require\nadministrative authentication for an addupdate action, which allows remote\nattackers to upload a calendar (aka .ics) file with arbitrary content to\nthe calendars/ directory outside the web root.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5967"],"bugs":[""],"patches":{"phpicalendar":[]},"tags":{},"packages":[{"name":"phpicalendar","source":"https://ubuntu.com/security/cve?package=phpicalendar","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpicalendar","debian":"https://tracker.debian.org/pkg/phpicalendar","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0269","published":"2009-01-26T15:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before\n2.6.28.1 allows local users to cause a denial of service (fault or memory\ncorruption), or possibly have unspecified other impact, via a readlink call\nthat results in an error, leading to use of a -1 return value as an array\nindex.","ubuntu_description":"\nThe eCryptfs filesystem did not correctly handle certain VFS return codes.\nA local attacker with write-access to an eCryptfs filesystem could cause\na system crash, leading to a denial of service.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-751-1","https://www.cve.org/CVERecord?id=CVE-2009-0269"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-23.52","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-11.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-16.62","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-751-1"],"notices":[{"id":"USN-751-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2009-04-06T23:52:35.518644","description":"NFS did not correctly handle races between fcntl and interrupts. A local\nattacker on an NFS mount could consume unlimited kernel memory, leading to\na denial of service. Ubuntu 8.10 was not affected. (CVE-2008-4307)\n\nSparc syscalls did not correctly check mmap regions. A local attacker\ncould cause a system panic, leading to a denial of service. Ubuntu 8.10\nwas not affected. (CVE-2008-6107)\n\nIn certain situations, cloned processes were able to send signals to parent\nprocesses, crossing privilege boundaries. A local attacker could send\narbitrary signals to parent processes, leading to a denial of service.\n(CVE-2009-0028)\n\nThe kernel keyring did not free memory correctly. A local attacker could\nconsume unlimited kernel memory, leading to a denial of service.\n(CVE-2009-0031)\n\nThe SCTP stack did not correctly validate FORWARD-TSN packets. A remote\nattacker could send specially crafted SCTP traffic causing a system crash,\nleading to a denial of service. (CVE-2009-0065)\n\nThe eCryptfs filesystem did not correctly handle certain VFS return codes.\nA local attacker with write-access to an eCryptfs filesystem could cause a\nsystem crash, leading to a denial of service. (CVE-2009-0269)\n\nThe Dell platform device did not correctly validate user parameters. A\nlocal attacker could perform specially crafted reads to crash the system,\nleading to a denial of service. (CVE-2009-0322)\n\nThe page fault handler could consume stack memory. A local attacker could\nexploit this to crash the system or gain root privileges with a Kprobe\nregistered. Only Ubuntu 8.10 was affected. (CVE-2009-0605)\n\nNetwork interfaces statistics for the SysKonnect FDDI driver did not check\ncapabilities. A local user could reset statistics, potentially interfering\nwith packet accounting systems. (CVE-2009-0675)\n\nThe getsockopt function did not correctly clear certain parameters. A local\nattacker could read leaked kernel memory, leading to a loss of privacy.\n(CVE-2009-0676)\n\nThe ext4 filesystem did not correctly clear group descriptors when\nresizing. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2009-0745)\n\nThe ext4 filesystem did not correctly validate certain fields. A local\nattacker could mount a malicious ext4 filesystem, causing a system\ncrash, leading to a denial of service. (CVE-2009-0746, CVE-2009-0747,\nCVE-2009-0748)\n\nThe syscall interface did not correctly validate parameters when crossing\nthe 64-bit/32-bit boundary. A local attacker could bypass certain syscall\nrestricts via crafted syscalls. (CVE-2009-0834, CVE-2009-0835)\n\nThe shared memory subsystem did not correctly handle certain shmctl calls\nwhen CONFIG_SHMEM was disabled. Ubuntu kernels were not vulnerable, since\nCONFIG_SHMEM is enabled by default. (CVE-2009-0859)\n\nThe virtual consoles did not correctly handle certain UTF-8 sequences. A\nlocal attacker on the physical console could exploit this to cause a system\ncrash, leading to a denial of service. (CVE-2009-1046)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-16.62","description":"","is_source":true},{"name":"linux-image-2.6.22-16-mckinley","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-powerpc64-smp","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-virtual","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-cell","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-hppa64","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-sparc64-smp","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-generic","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-lpia","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-powerpc-smp","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-386","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-hppa32","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-rt","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-xen","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-powerpc","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-itanium","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-lpiacompat","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-ume","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-sparc64","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"},{"name":"linux-image-2.6.22-16-server","version":"2.6.22-16.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.62"}],"intrepid":[{"name":"linux","version":"2.6.27-11.31","description":"","is_source":true},{"name":"linux-image-2.6.27-11-server","version":"2.6.27-11.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.31"},{"name":"linux-image-2.6.27-11-generic","version":"2.6.27-11.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.31"},{"name":"linux-image-2.6.27-11-virtual","version":"2.6.27-11.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.31"}],"hardy":[{"name":"linux","version":"2.6.24-23.52","description":"","is_source":true},{"name":"linux-image-2.6.24-23-virtual","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-server","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-mckinley","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-sparc64-smp","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-xen","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-powerpc-smp","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-lpiacompat","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-sparc64","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-rt","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-openvz","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-lpia","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-hppa64","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-386","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-powerpc","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-powerpc64-smp","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-itanium","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-hppa32","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"},{"name":"linux-image-2.6.24-23-generic","version":"2.6.24-23.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.52"}]},"type":"USN","cves_ids":["CVE-2008-4307","CVE-2008-6107","CVE-2009-0028","CVE-2009-0031","CVE-2009-0065","CVE-2009-0269","CVE-2009-0322","CVE-2009-0605","CVE-2009-0675","CVE-2009-0676","CVE-2009-0745","CVE-2009-0746","CVE-2009-0747","CVE-2009-0748","CVE-2009-0834","CVE-2009-0835","CVE-2009-0859","CVE-2009-1046"]}]},{"id":"CVE-2009-0265","published":"2009-01-26T15:30:00","updated_at":"2025-08-25T19:44:19.684432+00:00","description":"\nInternet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly\ncheck the return value from the OpenSSL EVP_VerifyFinal function, which\nallows remote attackers to bypass validation of the certificate chain via a\nmalformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and\nCVE-2009-0025.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Only affects Bind 9.6.0. 9.5 and earlier does not have\nEVP_VerifyFinal()."}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0265"],"bugs":[""],"patches":{"bind9":[]},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"dapper","status":"not-affected","description":"1:9.3.2-2ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"1:9.4.1-P1-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1:9.4.2.dfsg.P2-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1:9.5.0.dfsg.P2-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.6.0-P1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0260","published":"2009-01-23T19:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py\nin MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web\nscript or HTML via an AttachFile action to the WikiSandBox component with\n(1) the rename parameter or (2) the drawing parameter (aka the basename\nvariable).","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian, version 1.8.1-1 vulnerable despite the CVE description"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-716-1","https://www.cve.org/CVERecord?id=CVE-2009-0260"],"bugs":[""],"patches":{"moin":["other: http://hg.moinmo.in/moin/1.7/rev/8cb4d34ccbc1"]},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.2-1ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.5.7-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.8-5.1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.1-1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.7.1-1ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-716-1"],"notices":[{"id":"USN-716-1","title":"MoinMoin vulnerabilities","summary":"MoinMoin vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-01-30T02:21:53.757794","description":"Fernando Quintero discovered than MoinMoin did not properly sanitize its\ninput when processing login requests, resulting in cross-site scripting (XSS)\nvulnerabilities. With cross-site scripting vulnerabilities, if a user were\ntricked into viewing server output during a crafted server request, a remote\nattacker could exploit this to modify the contents, or steal confidential data,\nwithin the same domain. This issue affected Ubuntu 7.10 and 8.04 LTS.\n(CVE-2008-0780)\n\nFernando Quintero discovered that MoinMoin did not properly sanitize its input\nwhen attaching files, resulting in cross-site scripting vulnerabilities. This\nissue affected Ubuntu 6.06 LTS, 7.10 and 8.04 LTS. (CVE-2008-0781)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\nprocessing user forms. A remote attacker could submit crafted cookie values and\noverwrite arbitrary files via directory traversal. This issue affected Ubuntu\n6.06 LTS, 7.10 and 8.04 LTS. (CVE-2008-0782)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\nediting pages, resulting in cross-site scripting vulnerabilities. This issue\nonly affected Ubuntu 6.06 LTS and 7.10. (CVE-2008-1098)\n\nIt was discovered that MoinMoin did not properly enforce access controls,\nwhich could allow a remoter attacker to view private pages. This issue only\naffected Ubuntu 6.06 LTS and 7.10. (CVE-2008-1099)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\nattaching files and using the rename parameter, resulting in cross-site\nscripting vulnerabilities. (CVE-2009-0260)\n\nIt was discovered that MoinMoin did not properly sanitize its input when\ndisplaying error messages after processing spam, resulting in cross-site\nscripting vulnerabilities. (CVE-2009-0312)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"moin","version":"1.5.7-3ubuntu2.1","description":"","is_source":true},{"name":"python-moinmoin","version":"1.5.7-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.7-3ubuntu2.1"}],"dapper":[{"name":"moin","version":"1.5.2-1ubuntu2.4","description":"","is_source":true},{"name":"python2.4-moinmoin","version":"1.5.2-1ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.2-1ubuntu2.4"}],"intrepid":[{"name":"moin","version":"1.7.1-1ubuntu1.1","description":"","is_source":true},{"name":"python-moinmoin","version":"1.7.1-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.7.1-1ubuntu1.1"}],"hardy":[{"name":"moin","version":"1.5.8-5.1ubuntu2.2","description":"","is_source":true},{"name":"python-moinmoin","version":"1.5.8-5.1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.5.8-5.1ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2008-1098","CVE-2008-0782","CVE-2008-0780","CVE-2009-0260","CVE-2008-0781","CVE-2008-1099","CVE-2009-0312"]}]},{"id":"CVE-2009-0259","published":"2009-01-22T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote\nattackers to cause a denial of service (crash) and possibly execute\narbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file\nthat triggers memory corruption, as exploited in the wild in December 2008,\nas demonstrated by 2008-crash.doc.rar, and a similar issue to\nCVE-2008-4841.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0259"],"bugs":[""],"patches":{"openoffice.org":[]},"tags":{},"packages":[{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"not-affected","description":"2.0.2-2ubuntu12","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0258","published":"2009-01-22T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0\nthrough 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote\nattackers to execute arbitrary commands via a crafted filename containing\nshell metacharacters, which is not properly handled by the command-line\nindexer.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0258"],"bugs":["https://bugs.launchpad.net/bugs/327342"],"patches":{"typo3-src":["vendor: http://www.debian.org/security/2009/dsa-1711"]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"4.2.6-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.10, 4.1.8, 4.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0257","published":"2009-01-22T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through\n4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers\nto inject arbitrary web script or HTML via the (1) name and (2) content of\nindexed files to the (a) Indexed Search Engine (indexed_search) system\nextension; (b) unspecified test scripts in the ADOdb system extension; and\n(c) unspecified vectors in the Workspace module.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0257"],"bugs":[""],"patches":{"typo3-src":["vendor: http://www.debian.org/security/2009/dsa-1711"]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"4.2.6-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.10, 4.1.8, 4.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0256","published":"2009-01-22T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSession fixation vulnerability in the authentication library in TYPO3 4.0.0\nthrough 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote\nattackers to hijack web sessions via unspecified vectors related to (1)\nfrontend and (2) backend authentication.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0256"],"bugs":[""],"patches":{"typo3-src":["vendor: http://www.debian.org/security/2009/dsa-1711"]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"4.2.6-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.10, 4.1.8, 4.2.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":74460,"limit":20,"total_results":79316}