{"cves":[{"id":"CVE-2008-5305","published":"2008-12-10T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nEval injection vulnerability in TWiki before 4.2.4 allows remote attackers\nto execute arbitrary Perl code via the %SEARCH{}% variable.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5305"],"bugs":[""],"patches":{"twiki":[]},"tags":{},"packages":[{"name":"twiki","source":"https://ubuntu.com/security/cve?package=twiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=twiki","debian":"https://tracker.debian.org/pkg/twiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5304","published":"2008-12-10T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows\nremote attackers to inject arbitrary web script or HTML via the\n%URLPARAM{}% variable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5304"],"bugs":[""],"patches":{"twiki":[]},"tags":{},"packages":[{"name":"twiki","source":"https://ubuntu.com/security/cve?package=twiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=twiki","debian":"https://tracker.debian.org/pkg/twiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4311","published":"2008-12-10T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of system.conf in D-Bus (aka DBus) before 1.2.6\nomits the send_type attribute in certain rules, which allows local users to\nbypass intended access restrictions by (1) sending messages, related to\nsend_requested_reply; and possibly (2) receiving messages, related to\nreceive_requested_reply.","ubuntu_description":"","notes":[{"author":"kees","note":"Ubuntu's dbus clients are not believed to be vulnerable."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4311"],"bugs":[""],"patches":{"dbus":[]},"tags":{},"packages":[{"name":"dbus","source":"https://ubuntu.com/security/cve?package=dbus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dbus","debian":"https://tracker.debian.org/pkg/dbus","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5398","published":"2008-12-09T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nTor before 0.2.0.32 does not properly process the\nClientDNSRejectInternalAddresses configuration option in situations where\nan exit relay issues a policy-based refusal of a stream, which allows\nremote exit relays to have an unknown impact by mapping an internal IP\naddress to the destination hostname of a refused stream.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5398"],"bugs":[""],"patches":{"tor":[]},"tags":{},"packages":[{"name":"tor","source":"https://ubuntu.com/security/cve?package=tor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tor","debian":"https://tracker.debian.org/pkg/tor","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2.0.32","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5397","published":"2008-12-09T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nTor before 0.2.0.32 does not properly process the (1) User and (2) Group\nconfiguration options, which might allow local users to gain privileges by\nleveraging unintended supplementary group memberships of the Tor process.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5397"],"bugs":[""],"patches":{"tor":[]},"tags":{},"packages":[{"name":"tor","source":"https://ubuntu.com/security/cve?package=tor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tor","debian":"https://tracker.debian.org/pkg/tor","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2.0.32","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5396","published":"2008-12-09T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nArray index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in\nZaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout\ngroup to overwrite an integer value in kernel memory by writing to\n/dev/zap/ctl, related to missing validation of the sync field associated\nwith the ZT_SPANCONFIG ioctl.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5396"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":[],"zaptel":[],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"zaptel","source":"https://ubuntu.com/security/cve?package=zaptel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zaptel","debian":"https://tracker.debian.org/pkg/zaptel","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.4.11~dfsg-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5395","published":"2008-12-09T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe parisc_show_stack function in arch/parisc/kernel/traps.c in the Linux\nkernel before 2.6.28-rc7 on PA-RISC allows local users to cause a denial of\nservice (system crash) via vectors associated with an attempt to unwind a\nstack that contains userspace addresses.","ubuntu_description":"\nHelge Deller discovered that PA-RISC stack unwinding was not handled correctly.\nA local attacker could exploit this to crash the system, leading do a denial of service.\nThis did not affect official Ubuntu kernels, but was fixed in the source for anyone\nperforming HPPA kernel builds.","notes":[{"author":"smb","note":"The call do dump_stack was not added before v2.6.25-rc6. So the resulting panic will not happen."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-715-1","https://www.cve.org/CVERecord?id=CVE-2008-5395"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-11.27","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.28-rc7","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-715-1"],"notices":[{"id":"USN-715-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2009-01-29T23:41:39.444876","description":"Hugo Dias discovered that the ATM subsystem did not correctly manage\nsocket counts. A local attacker could exploit this to cause a system hang,\nleading to a denial of service. (CVE-2008-5079)\n\nIt was discovered that the inotify subsystem contained watch removal\nrace conditions. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2008-5182)\n\nDann Frazier discovered that in certain situations sendmsg did not\ncorrectly release allocated memory. A local attacker could exploit\nthis to force the system to run out of free memory, leading to a denial\nof service. (CVE-2008-5300)\n\nHelge Deller discovered that PA-RISC stack unwinding was not handled\ncorrectly. A local attacker could exploit this to crash the system,\nleading do a denial of service. This did not affect official Ubuntu\nkernels, but was fixed in the source for anyone performing HPPA kernel\nbuilds. (CVE-2008-5395)\n\nIt was discovered that the ATA subsystem did not correctly set timeouts. A\nlocal attacker could exploit this to cause a system hang, leading to a\ndenial of service. (CVE-2008-5700)\n\nIt was discovered that the ib700 watchdog timer did not correctly check\nbuffer sizes. A local attacker could send a specially crafted ioctl\nto the device to cause a system crash, leading to a denial of service.\n(CVE-2008-5702)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"linux","version":"2.6.27-11.27","description":"","is_source":true},{"name":"linux-image-2.6.27-11-server","version":"2.6.27-11.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.27"},{"name":"linux-image-2.6.27-11-generic","version":"2.6.27-11.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.27"},{"name":"linux-image-2.6.27-11-virtual","version":"2.6.27-11.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.27"}]},"type":"USN","cves_ids":["CVE-2008-5182","CVE-2008-5702","CVE-2008-5700","CVE-2008-5300","CVE-2008-5079","CVE-2008-5395"]}]},{"id":"CVE-2008-5394","published":"2008-12-09T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\n/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux\ndistributions, allows local users in the utmp group to overwrite arbitrary\nfiles via a symlink attack on a temporary file referenced in a line (aka\nut_line) field in a utmp entry.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-695-1","https://www.cve.org/CVERecord?id=CVE-2008-5394"],"bugs":[""],"patches":{"shadow":[]},"tags":{},"packages":[{"name":"shadow","source":"https://ubuntu.com/security/cve?package=shadow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=shadow","debian":"https://tracker.debian.org/pkg/shadow","statuses":[{"release_codename":"dapper","status":"released","description":"1:4.0.13-7ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1:4.0.18.1-9ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:4.0.18.2-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:4.1.1-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:4.1.1-6","component":null,"pocket":"security"}]}],"notices_ids":["USN-695-1"],"notices":[{"id":"USN-695-1","title":"shadow vulnerability","summary":"shadow vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T01:18:43.192193","description":"Paul Szabo discovered a race condition in login. While setting up\ntty permissions, login did not correctly handle symlinks. If a local\nattacker were able to gain control of the system utmp file, they could\ncause login to change the ownership and permissions on arbitrary files,\nleading to a root privilege escalation.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"shadow","version":"1:4.0.18.1-9ubuntu0.2","description":"","is_source":true},{"name":"login","version":"1:4.0.18.1-9ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/shadow","version_link":"https://launchpad.net/ubuntu/+source/shadow/1:4.0.18.1-9ubuntu0.2"}],"dapper":[{"name":"shadow","version":"1:4.0.13-7ubuntu3.4","description":"","is_source":true},{"name":"login","version":"1:4.0.13-7ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/shadow","version_link":"https://launchpad.net/ubuntu/+source/shadow/1:4.0.13-7ubuntu3.4"}],"intrepid":[{"name":"shadow","version":"1:4.1.1-1ubuntu1.2","description":"","is_source":true},{"name":"login","version":"1:4.1.1-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/shadow","version_link":"https://launchpad.net/ubuntu/+source/shadow/1:4.1.1-1ubuntu1.2"}],"hardy":[{"name":"shadow","version":"1:4.0.18.2-1ubuntu2.2","description":"","is_source":true},{"name":"login","version":"1:4.0.18.2-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/shadow","version_link":"https://launchpad.net/ubuntu/+source/shadow/1:4.0.18.2-1ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2008-5394"]}]},{"id":"CVE-2008-5277","published":"2008-12-09T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPowerDNS before 2.9.21.2 allows remote attackers to cause a denial of\nservice (daemon crash) via a CH HINFO query.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5277"],"bugs":[""],"patches":{"pdns":[]},"tags":{},"packages":[{"name":"pdns","source":"https://ubuntu.com/security/cve?package=pdns","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdns","debian":"https://tracker.debian.org/pkg/pdns","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.21.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5079","published":"2008-12-09T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnet/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier\nallows local users to cause a denial of service (kernel infinite loop) by\nmaking two calls to svc_listen for the same socket, and then reading a\n/proc/net/atm/*vc file, related to corruption of the vcc table.","ubuntu_description":"\nHugo Dias discovered that the ATM subsystem did not correctly manage\nsocket counts. A local attacker could exploit this to cause a system\nhang, leading to a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-714-1","https://ubuntu.com/security/notices/USN-715-1","https://www.cve.org/CVERecord?id=CVE-2008-5079"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-23.48","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-11.27","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27.8","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-53.75","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-16.61","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-715-1","USN-714-1"],"notices":[{"id":"USN-715-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2009-01-29T23:41:39.444876","description":"Hugo Dias discovered that the ATM subsystem did not correctly manage\nsocket counts. A local attacker could exploit this to cause a system hang,\nleading to a denial of service. (CVE-2008-5079)\n\nIt was discovered that the inotify subsystem contained watch removal\nrace conditions. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2008-5182)\n\nDann Frazier discovered that in certain situations sendmsg did not\ncorrectly release allocated memory. A local attacker could exploit\nthis to force the system to run out of free memory, leading to a denial\nof service. (CVE-2008-5300)\n\nHelge Deller discovered that PA-RISC stack unwinding was not handled\ncorrectly. A local attacker could exploit this to crash the system,\nleading do a denial of service. This did not affect official Ubuntu\nkernels, but was fixed in the source for anyone performing HPPA kernel\nbuilds. (CVE-2008-5395)\n\nIt was discovered that the ATA subsystem did not correctly set timeouts. A\nlocal attacker could exploit this to cause a system hang, leading to a\ndenial of service. (CVE-2008-5700)\n\nIt was discovered that the ib700 watchdog timer did not correctly check\nbuffer sizes. A local attacker could send a specially crafted ioctl\nto the device to cause a system crash, leading to a denial of service.\n(CVE-2008-5702)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"linux","version":"2.6.27-11.27","description":"","is_source":true},{"name":"linux-image-2.6.27-11-server","version":"2.6.27-11.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.27"},{"name":"linux-image-2.6.27-11-generic","version":"2.6.27-11.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.27"},{"name":"linux-image-2.6.27-11-virtual","version":"2.6.27-11.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-11.27"}]},"type":"USN","cves_ids":["CVE-2008-5182","CVE-2008-5702","CVE-2008-5700","CVE-2008-5300","CVE-2008-5079","CVE-2008-5395"]},{"id":"USN-714-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2009-01-29T00:01:28.073955","description":"Hugo Dias discovered that the ATM subsystem did not correctly manage socket\ncounts. A local attacker could exploit this to cause a system hang, leading\nto a denial of service. (CVE-2008-5079)\n\nIt was discovered that the libertas wireless driver did not correctly\nhandle beacon and probe responses. A physically near-by attacker could\ngenerate specially crafted wireless network traffic and cause a denial of\nservice. Ubuntu 6.06 was not affected. (CVE-2008-5134)\n\nIt was discovered that the inotify subsystem contained watch removal race\nconditions. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2008-5182)\n\nDann Frazier discovered that in certain situations sendmsg did not\ncorrectly release allocated memory. A local attacker could exploit this to\nforce the system to run out of free memory, leading to a denial of service.\nUbuntu 6.06 was not affected. (CVE-2008-5300)\n\nIt was discovered that the ATA subsystem did not correctly set timeouts. A\nlocal attacker could exploit this to cause a system hang, leading to a\ndenial of service. (CVE-2008-5700)\n\nIt was discovered that the ib700 watchdog timer did not correctly check\nbuffer sizes. A local attacker could send a specially crafted ioctl to the\ndevice to cause a system crash, leading to a denial of service.\n(CVE-2008-5702)\n\nIt was discovered that in certain situations the network scheduler did not\ncorrectly handle very large levels of traffic. A local attacker could\nproduce a high volume of UDP traffic resulting in a system hang, leading to\na denial of service. Ubuntu 8.04 was not affected. (CVE-2008-5713)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-16.61","description":"","is_source":true},{"name":"linux-image-2.6.22-16-mckinley","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-powerpc64-smp","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-virtual","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-cell","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-hppa64","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-sparc64-smp","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-generic","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-lpia","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-powerpc-smp","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-386","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-hppa32","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-rt","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-xen","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-powerpc","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-itanium","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-lpiacompat","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-ume","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-sparc64","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"},{"name":"linux-image-2.6.22-16-server","version":"2.6.22-16.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.61"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-53.75","description":"","is_source":true},{"name":"linux-image-2.6.15-53-powerpc64-smp","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-powerpc","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-amd64-xeon","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-386","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-amd64-generic","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-686","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-hppa64","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-sparc64","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-amd64-server","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-amd64-k8","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-hppa64-smp","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-sparc64-smp","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-itanium-smp","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-hppa32","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-hppa32-smp","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-mckinley","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-powerpc-smp","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-server-bigiron","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-mckinley-smp","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-server","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-itanium","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"},{"name":"linux-image-2.6.15-53-k7","version":"2.6.15-53.75","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.75"}],"hardy":[{"name":"linux","version":"2.6.24-23.48","description":"","is_source":true},{"name":"linux-image-2.6.24-23-virtual","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-server","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-mckinley","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-sparc64-smp","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-xen","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-powerpc-smp","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-lpiacompat","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-sparc64","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-rt","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-openvz","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-lpia","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-hppa64","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-386","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-powerpc","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-powerpc64-smp","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-itanium","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-hppa32","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"},{"name":"linux-image-2.6.24-23-generic","version":"2.6.24-23.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-23.48"}]},"type":"USN","cves_ids":["CVE-2008-5134","CVE-2008-5713","CVE-2008-5079","CVE-2008-5182","CVE-2008-5300","CVE-2008-5700","CVE-2008-5702"]}]},{"id":"CVE-2008-5380","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ngpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite\narbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b)\n/tmp/geocaching.loc, a (c) /tmp/geo#####.*, or a (d) /tmp/geo.* temporary\nfile, related to the (1) geo-code and (2) geo-nearest scripts, different\nvectors than CVE-2008-4959.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5380"],"bugs":[""],"patches":{"gpsdrive":[]},"tags":{},"packages":[{"name":"gpsdrive","source":"https://ubuntu.com/security/cve?package=gpsdrive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpsdrive","debian":"https://tracker.debian.org/pkg/gpsdrive","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.10pre4-6.dfsg-3build1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.10pre4-6.dfsg-3build1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.10pre4-6.dfsg-3build1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.10pre4-6.dfsg-3build1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.10pre7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5379","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnetdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files\nvia a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file,\nrelated to the (1) netdisco-mibs-install and (2) netdisco-mibs-download\nscripts.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5379"],"bugs":[""],"patches":{"netdisco-mibs-installer":[]},"tags":{},"packages":[{"name":"netdisco-mibs-installer","source":"https://ubuntu.com/security/cve?package=netdisco-mibs-installer","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netdisco-mibs-installer","debian":"https://tracker.debian.org/pkg/netdisco-mibs-installer","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.4","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5378","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\narb-kill in arb 0.0.20071207.1 allows local users to overwrite arbitrary\nfiles via a symlink attack on a /tmp/arb_pids_*_* temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5378"],"bugs":[""],"patches":{"arb":[]},"tags":{},"packages":[{"name":"arb","source":"https://ubuntu.com/security/cve?package=arb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=arb","debian":"https://tracker.debian.org/pkg/arb","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.0.20071207.1-7","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.0.20071207.1-6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5377","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a\nsymlink attack on the /tmp/pstopdf.log temporary file, a different\nvulnerability than CVE-2001-1333.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-707-1","https://www.cve.org/CVERecord?id=CVE-2008-5377"],"bugs":[""],"patches":{"cups":[],"cupsys":[]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.3.9-2ubuntu6","component":null,"pocket":"security"}]},{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.2-0ubuntu0.6.06.12","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.3.2-1ubuntu7.9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.3.7-1ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-707-1"],"notices":[{"id":"USN-707-1","title":"CUPS vulnerabilities","summary":"CUPS vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-01-12T15:35:46.993925","description":"It was discovered that CUPS didn't properly handle adding a large number of RSS\nsubscriptions. A local user could exploit this and cause CUPS to crash, leading\nto a denial of service. This issue only applied to Ubuntu 7.10, 8.04 LTS and\n8.10. (CVE-2008-5183)\n\nIt was discovered that CUPS did not authenticate users when adding and\ncancelling RSS subscriptions. An unprivileged local user could bypass intended\nrestrictions and add a large number of RSS subscriptions. This issue only\napplied to Ubuntu 7.10 and 8.04 LTS. (CVE-2008-5184)\n\nIt was discovered that the PNG filter in CUPS did not properly handle certain\nmalformed images. If a user or automated system were tricked into opening a\ncrafted PNG image file, a remote attacker could cause a denial of service or\nexecute arbitrary code with user privileges. In Ubuntu 7.10, 8.04 LTS, and 8.10,\nattackers would be isolated by the AppArmor CUPS profile. (CVE-2008-5286)\n\nIt was discovered that the example pstopdf CUPS filter created log files in an\ninsecure way. Local users could exploit a race condition to create or overwrite\nfiles with the privileges of the user invoking the program. This issue only\napplied to Ubuntu 6.06 LTS, 7.10, and 8.04 LTS. (CVE-2008-5377)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"cupsys","version":"1.3.2-1ubuntu7.9","description":"","is_source":true},{"name":"cupsys","version":"1.3.2-1ubuntu7.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.2-1ubuntu7.9"}],"dapper":[{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.12","description":"","is_source":true},{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.2-0ubuntu0.6.06.12"}],"intrepid":[{"name":"cups","version":"1.3.9-2ubuntu6.1","description":"","is_source":true},{"name":"cups","version":"1.3.9-2ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.3.9-2ubuntu6.1"}],"hardy":[{"name":"cupsys","version":"1.3.7-1ubuntu3.3","description":"","is_source":true},{"name":"cupsys","version":"1.3.7-1ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.7-1ubuntu3.3"}]},"type":"USN","cves_ids":["CVE-2008-5183","CVE-2008-5184","CVE-2008-5286","CVE-2008-5377"]}]},{"id":"CVE-2008-5376","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\neditcomment in crip 3.7 allows local users to overwrite arbitrary files via\na symlink attack on a /tmp/*.tag.tmp temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5376"],"bugs":[""],"patches":{"crip":[]},"tags":{},"packages":[{"name":"crip","source":"https://ubuntu.com/security/cve?package=crip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=crip","debian":"https://tracker.debian.org/pkg/crip","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.7-6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.7-5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5375","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncmus-status-display in cmus 2.2.0 allows local users to overwrite arbitrary\nfiles via a symlink attack on the /tmp/cmus-status temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5375"],"bugs":[""],"patches":{"cmus":[]},"tags":{},"packages":[{"name":"cmus","source":"https://ubuntu.com/security/cve?package=cmus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cmus","debian":"https://tracker.debian.org/pkg/cmus","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.2.0-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.0-1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5374","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nbash-doc 3.2 allows local users to overwrite arbitrary files via a symlink\nattack on a /tmp/cb#####.? temporary file, related to the (1) aliasconv.sh,\n(2) aliasconv.bash, and (3) cshtobash scripts.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5374"],"bugs":[""],"patches":{"bash":["vendor: https://rhn.redhat.com/errata/RHSA-2011-1073.html"]},"tags":{},"packages":[{"name":"bash","source":"https://ubuntu.com/security/cve?package=bash","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bash","debian":"https://tracker.debian.org/pkg/bash","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"4.0-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5373","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to\noverwrite arbitrary files via a symlink attack on a /tmp/mtx.#####\ntemporary file, probably a related issue to CVE-2005-2995.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5373"],"bugs":[""],"patches":{"bacula":[]},"tags":{},"packages":[{"name":"bacula","source":"https://ubuntu.com/security/cve?package=bacula","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bacula","debian":"https://tracker.debian.org/pkg/bacula","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.4.2-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5372","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsdm-login in sdm-terminal 0.4.0b allows local users to overwrite arbitrary\nfiles via a symlink attack on the /tmp/sdm.autologin.once temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5372"],"bugs":[""],"patches":{"sdm":[]},"tags":{},"packages":[{"name":"sdm","source":"https://ubuntu.com/security/cve?package=sdm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sdm","debian":"https://tracker.debian.org/pkg/sdm","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.4.1-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.4.1-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.4.1-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.4.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.4.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5371","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nscreenie in screenie 1.30.0 allows local users to overwrite arbitrary files\nvia a symlink attack on a /tmp/.screenie.##### temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5371"],"bugs":[""],"patches":{"screenie":[]},"tags":{},"packages":[{"name":"screenie","source":"https://ubuntu.com/security/cve?package=screenie","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=screenie","debian":"https://tracker.debian.org/pkg/screenie","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.30.0-5.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.30.0-5.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":74620,"limit":20,"total_results":79316}