{"cves":[{"id":"CVE-2008-4685","published":"2008-10-22T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the dissect_q931_cause_ie function in\npacket-q931.c in the Q.931 dissector in Wireshark 0.10.3 through 1.0.3\nallows remote attackers to cause a denial of service (application crash or\nabort) via certain packets that trigger an exception.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4685"],"bugs":[""],"patches":{"wireshark":[],"ethereal":[]},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.99.6rel-3ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.0.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0.3-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.0.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4684","published":"2008-10-22T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npacket-frame in Wireshark 0.99.2 through 1.0.3 does not properly handle\nexceptions thrown by post dissectors, which allows remote attackers to\ncause a denial of service (application crash) via a certain series of\npackets, as demonstrated by enabling the (1) PRP or (2) MATE post\ndissector.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4684"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.99.6rel-3ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.0.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0.3-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4683","published":"2008-10-22T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL\ndissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to\ncause a denial of service (application crash or abort) via a packet with an\ninvalid length, related to an erroneous tvb_memcpy call.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4683"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.99.6rel-3ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.0.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0.3-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4682","published":"2008-10-22T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nwtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a\ndenial of service (application abort) via a malformed Tamos CommView\ncapture file (aka .ncf file) with an \"unknown/unexpected packet type\" that\ntriggers a failed assertion.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4682"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.0.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0.3-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4681","published":"2008-10-22T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Bluetooth RFCOMM dissector in Wireshark\n0.99.7 through 1.0.3 allows remote attackers to cause a denial of service\n(application crash or abort) via unknown packets.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4681"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.0.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0.3-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4680","published":"2008-10-22T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npacket-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows\nremote attackers to cause a denial of service (application crash or abort)\nvia a malformed USB Request Block (URB).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4680"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.0.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0.3-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4677","published":"2008-10-22T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nautoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions\nbefore 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials\nfor an FTP session, and sends those credentials when attempting to\nestablish subsequent FTP sessions to servers on different hosts, which\nallows remote FTP servers to obtain sensitive information in opportunistic\ncircumstances by logging usernames and passwords. NOTE: the upstream\nvendor disputes a vector involving different ports on the same host,\nstating \"I'm assuming that they're using the same id and password on that\nunchanged hostname, deliberately.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream author disputes this, let's ignore"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4677"],"bugs":[""],"patches":{"vim":[]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4671","published":"2008-10-22T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in\nWordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary\nweb script or HTML via the (1) s and (2) ip_address parameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4671"],"bugs":[""],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"not-affected","description":"Debian wordpress installs not vulnerable","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"Debian wordpress installs not vulnerable","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"Debian wordpress installs not vulnerable","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4654","published":"2008-10-22T00:11:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the parse_master function in the Ty demux\nplugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows\nremote attackers to execute arbitrary code via a TiVo TY media file with a\nheader containing a crafted size value.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.videolan.org/security/sa0809.html","https://www.cve.org/CVERecord?id=CVE-2008-4654"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/285922","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502726"],"patches":{"vlc":["upstream: http://git.videolan.org/?p=vlc.git;a=commit;h=26d92b87bba99b5ea2e17b7eaa39c462d65e9133"]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.9.4-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.9.9a-2ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4641","published":"2008-10-21T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier\nallows attackers to execute arbitrary commands via shell metacharacters in\nunspecified input.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4641"],"bugs":[""],"patches":{"jhead":[]},"tags":{},"packages":[{"name":"jhead","source":"https://ubuntu.com/security/cve?package=jhead","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jhead","debian":"https://tracker.debian.org/pkg/jhead","statuses":[{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.86-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.84-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4640","published":"2008-10-21T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier\nallows local users to delete arbitrary files via vectors involving a\nmodified input filename in which (1) a final \"z\" character is replaced by a\n\"t\" character or (2) a final \"t\" character is replaced by a \"z\" character.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4640"],"bugs":[""],"patches":{"jhead":[]},"tags":{},"packages":[{"name":"jhead","source":"https://ubuntu.com/security/cve?package=jhead","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jhead","debian":"https://tracker.debian.org/pkg/jhead","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.86-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.84-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4639","published":"2008-10-21T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\njhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to\noverwrite arbitrary files via a symlink attack on a temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4639"],"bugs":[""],"patches":{"jhead":[]},"tags":{},"packages":[{"name":"jhead","source":"https://ubuntu.com/security/cve?package=jhead","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jhead","debian":"https://tracker.debian.org/pkg/jhead","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.84","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4634","published":"2008-10-21T01:18:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Movable Type 4 through 4.21\nallows remote attackers to inject arbitrary web script or HTML via unknown\nvectors related to the administrative page, a different vulnerability than\nCVE-2008-4079.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4634"],"bugs":[""],"patches":{"movabletype-opensource":[]},"tags":{},"packages":[{"name":"movabletype-opensource","source":"https://ubuntu.com/security/cve?package=movabletype-opensource","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=movabletype-opensource","debian":"https://tracker.debian.org/pkg/movabletype-opensource","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"4.2.3-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.1-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4618","published":"2008-10-21T00:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Stream Control Transmission Protocol (sctp) implementation in the Linux\nkernel before 2.6.27 does not properly handle a protocol violation in which\na parameter has an invalid length, which allows attackers to cause a denial\nof service (panic) via unspecified vectors, related to\nsctp_sf_violation_paramlen, sctp_sf_abort_violation,\nsctp_make_abort_violation, and incorrect data types in function calls.","ubuntu_description":"\nIt was discovered that the SCTP stack did not correctly handle bad\npacket lengths. A remote user could exploit this by sending specially\ncrafted SCTP traffic which would trigger a crash in the system, leading\nto a denial of service. This issue did not affect Ubuntu 8.10.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-679-1","https://www.cve.org/CVERecord?id=CVE-2008-4618"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=ba0166708ef4da7eeb61dd92bbba4d5a749d6561"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-22.45","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc9","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-53.74","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc9","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-16.60","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc9","component":null,"pocket":"security"}]}],"notices_ids":["USN-679-1"],"notices":[{"id":"USN-679-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2008-11-27T17:43:01.542705","description":"It was discovered that the Xen hypervisor block driver did not correctly\nvalidate requests. A user with root privileges in a guest OS could make a\nmalicious IO request with a large number of blocks that would crash the\nhost OS, leading to a denial of service. This only affected Ubuntu 7.10.\n(CVE-2007-5498)\n\nIt was discovered the the i915 video driver did not correctly validate\nmemory addresses. A local attacker could exploit this to remap memory that\ncould cause a system crash, leading to a denial of service. This issue did\nnot affect Ubuntu 6.06 and was previous fixed for Ubuntu 7.10 and 8.04 in\nUSN-659-1. Ubuntu 8.10 has now been corrected as well. (CVE-2008-3831)\n\nDavid Watson discovered that the kernel did not correctly strip permissions\nwhen creating files in setgid directories. A local user could exploit this\nto gain additional group privileges. This issue only affected Ubuntu 6.06.\n(CVE-2008-4210)\n\nOlaf Kirch and Miklos Szeredi discovered that the Linux kernel did\nnot correctly reject the \"append\" flag when handling file splice\nrequests. A local attacker could bypass append mode and make changes to\narbitrary locations in a file. This issue only affected Ubuntu 7.10 and\n8.04. (CVE-2008-4554)\n\nIt was discovered that the SCTP stack did not correctly handle INIT-ACK. A\nremote user could exploit this by sending specially crafted SCTP traffic\nwhich would trigger a crash in the system, leading to a denial of service.\nThis issue did not affect Ubuntu 8.10. (CVE-2008-4576)\n\nIt was discovered that the SCTP stack did not correctly handle bad packet\nlengths. A remote user could exploit this by sending specially crafted SCTP\ntraffic which would trigger a crash in the system, leading to a denial of\nservice. This issue did not affect Ubuntu 8.10. (CVE-2008-4618)\n\nEric Sesterhenn discovered multiple flaws in the HFS+ filesystem. If a\nlocal user or automated system were tricked into mounting a malicious HFS+\nfilesystem, the system could crash, leading to a denial of service.\n(CVE-2008-4933, CVE-2008-4934, CVE-2008-5025)\n\nIt was discovered that the Unix Socket handler did not correctly process\nthe SCM_RIGHTS message. A local attacker could make a malicious socket\nrequest that would crash the system, leading to a denial of service.\n(CVE-2008-5029)\n\nIt was discovered that the driver for simple i2c audio interfaces did not\ncorrectly validate certain function pointers. A local user could exploit\nthis to gain root privileges or crash the system, leading to a denial of\nservice. (CVE-2008-5033)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-backports-modules-2.6.22","version":"2.6.22-16.17","description":"","is_source":true},{"name":"linux-ubuntu-modules-2.6.22","version":"2.6.22-16.41","description":"","is_source":true},{"name":"linux-restricted-modules-2.6.22","version":"2.6.22.4-16.12","description":"","is_source":true},{"name":"linux-source-2.6.22","version":"2.6.22-16.60","description":"","is_source":true},{"name":"linux-image-2.6.22-16-mckinley","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc64-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-virtual","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-cell","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-hppa64","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-sparc64-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-generic","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-lpia","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-386","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-hppa32","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-rt","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-xen","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-itanium","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-lpiacompat","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-ume","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-sparc64","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-server","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"}],"dapper":[{"name":"linux-restricted-modules-2.6.15","version":"2.6.15.12-53.4","description":"","is_source":true},{"name":"linux-source-2.6.15","version":"2.6.15-53.74","description":"","is_source":true},{"name":"linux-backports-modules-2.6.15","version":"2.6.15-53.11","description":"","is_source":true},{"name":"linux-image-2.6.15-53-powerpc64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-powerpc","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-xeon","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-386","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-generic","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-686","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa64","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-sparc64","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-server","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-k8","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-sparc64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-itanium-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa32","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa32-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-mckinley","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-powerpc-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-server-bigiron","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-mckinley-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-server","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-itanium","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-k7","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"}],"intrepid":[{"name":"linux-restricted-modules","version":"2.6.27-9.13","description":"","is_source":true},{"name":"linux-backports-modules-2.6.27","version":"2.6.27-9.5","description":"","is_source":true},{"name":"linux","version":"2.6.27-9.19","description":"","is_source":true},{"name":"linux-image-2.6.27-9-virtual","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"},{"name":"linux-image-2.6.27-9-generic","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"},{"name":"linux-image-2.6.27-9-server","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"}],"hardy":[{"name":"linux-restricted-modules-2.6.24","version":"2.6.24.14-22.53","description":"","is_source":true},{"name":"linux-ubuntu-modules-2.6.24","version":"2.6.24-22.35","description":"","is_source":true},{"name":"linux","version":"2.6.24-22.45","description":"","is_source":true},{"name":"linux-backports-modules-2.6.24","version":"2.6.24-22.29","description":"","is_source":true},{"name":"linux-image-2.6.24-22-powerpc","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-sparc64","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-virtual","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-server","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-lpia","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-hppa32","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-lpiacompat","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-rt","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-generic","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-hppa64","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-xen","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-mckinley","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-powerpc64-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-itanium","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-openvz","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-386","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-sparc64-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-powerpc-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"}]},"type":"USN","cves_ids":["CVE-2007-5498","CVE-2008-3831","CVE-2008-4210","CVE-2008-4554","CVE-2008-4576","CVE-2008-4618","CVE-2008-4933","CVE-2008-4934","CVE-2008-5025","CVE-2008-5029","CVE-2008-5033"]}]},{"id":"CVE-2008-4609","published":"2008-10-20T17:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3)\nMicrosoft Windows, (4) Cisco products, and probably other operating systems\nallows remote attackers to cause a denial of service (connection queue\nexhaustion) via multiple vectors that manipulate information in the TCP\nstate table, as demonstrated by sockstress.","ubuntu_description":"","notes":[{"author":"kees","note":"negligible priority because there is no actual information yet."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4609"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3831","published":"2008-10-20T17:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel\n2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD\ndoes not restrict the DRM_I915_HWS_ADDR ioctl to the Direct Rendering\nManager (DRM) master, which allows local users to cause a denial of service\n(memory corruption) via a crafted ioctl call, related to absence of the\nDRM_MASTER and DRM_ROOT_ONLY flags in the ioctl's configuration.","ubuntu_description":"\nIt was discovered the the i915 video driver did not correctly validate\nmemory addresses. A local attacker could exploit this to remap memory\nthat could cause a system crash, leading to a denial of service.\nThis issue did not affect Ubuntu 6.06 and was previous fixed for Ubuntu\n7.10 and 8.04 in USN-659-1. Ubuntu 8.10 has now been corrected as well.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-659-1","https://ubuntu.com/security/notices/USN-679-1","https://www.cve.org/CVERecord?id=CVE-2008-3831"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-21.43","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-9.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27.3","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-15.59","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-659-1","USN-679-1"],"notices":[{"id":"USN-659-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: For systems without the hardy-updates pocket enabled, the 8.04\nkernel update will include an unavoidable ABI change. The kernel update\nhas been given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2008-10-27T20:22:50.932571","description":"It was discovered that the direct-IO subsystem did not correctly validate\ncertain structures. A local attacker could exploit this to cause a system\ncrash, leading to a denial of service. (CVE-2007-6716)\n\nIt was discovered that the disabling of the ZERO_PAGE optimization could\nlead to large memory consumption. A local attacker could exploit this to\nallocate all available memory, leading to a denial of service.\n(CVE-2008-2372)\n\nIt was discovered that the Datagram Congestion Control Protocol (DCCP) did\nnot correctly validate its arguments. If DCCP was in use, a remote attacker\ncould send specially crafted network traffic and cause a system crash,\nleading to a denial of service. (CVE-2008-3276)\n\nIt was discovered that the SBNI WAN driver did not correctly check for the\nNET_ADMIN capability. A malicious local root user lacking CAP_NET_ADMIN\nwould be able to change the WAN device configuration, leading to a denial\nof service. (CVE-2008-3525)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP) did\nnot correctly validate the key length in the SCTP_AUTH_KEY option. If SCTP\nis in use, a remote attacker could send specially crafted network traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2008-3526)\n\nIt was discovered that the tmpfs implementation did not correctly handle\ncertain sequences of inode operations. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-3534)\n\nIt was discovered that the readv/writev functions did not correctly handle\ncertain sequences of file operations. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-3535)\n\nIt was discovered that SCTP did not correctly validate its userspace\narguments. A local attacker could call certain sctp_* functions with\nmalicious options and cause a system crash, leading to a denial of service.\n(CVE-2008-3792, CVE-2008-4113, CVE-2008-4445)\n\nIt was discovered the the i915 video driver did not correctly validate\nmemory addresses. A local attacker could exploit this to remap memory\nthat could cause a system crash, leading to a denial of service.\n(CVE-2008-3831)\n\nJohann Dahm and David Richter discovered that NFSv4 did not correctly\nhandle certain file ACLs. If NFSv4 is in use, a local attacker could create\na malicious ACL that could cause a system crash, leading to a denial of\nservice. (CVE-2008-3915)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-15.59","description":"","is_source":true},{"name":"linux-image-2.6.22-15-mckinley","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-generic","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-hppa32","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-xen","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-sparc64-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-itanium","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-lpiacompat","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-386","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-lpia","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-sparc64","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-rt","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-virtual","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-server","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc64-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-hppa64","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-cell","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-ume","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-52.73","description":"","is_source":true},{"name":"linux-image-2.6.15-52-386","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-mckinley","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-server","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa32","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-k7","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-686","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-k8","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-server-bigiron","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-sparc64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-itanium","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-server","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa32-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-xeon","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-mckinley-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa64","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-generic","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-itanium-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-sparc64","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"}],"hardy":[{"name":"linux","version":"2.6.24-21.43","description":"","is_source":true},{"name":"linux-image-2.6.24-21-powerpc","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-powerpc64-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-sparc64","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-server","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-openvz","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-itanium","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-lpiacompat","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-386","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-generic","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-lpia","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-xen","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-hppa64","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-powerpc-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-mckinley","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-hppa32","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-rt","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-virtual","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-sparc64-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"}]},"type":"USN","cves_ids":["CVE-2007-6716","CVE-2008-2372","CVE-2008-3276","CVE-2008-3525","CVE-2008-3526","CVE-2008-3534","CVE-2008-3535","CVE-2008-3792","CVE-2008-3831","CVE-2008-3915","CVE-2008-4113","CVE-2008-4445"]},{"id":"USN-679-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2008-11-27T17:43:01.542705","description":"It was discovered that the Xen hypervisor block driver did not correctly\nvalidate requests. A user with root privileges in a guest OS could make a\nmalicious IO request with a large number of blocks that would crash the\nhost OS, leading to a denial of service. This only affected Ubuntu 7.10.\n(CVE-2007-5498)\n\nIt was discovered the the i915 video driver did not correctly validate\nmemory addresses. A local attacker could exploit this to remap memory that\ncould cause a system crash, leading to a denial of service. This issue did\nnot affect Ubuntu 6.06 and was previous fixed for Ubuntu 7.10 and 8.04 in\nUSN-659-1. Ubuntu 8.10 has now been corrected as well. (CVE-2008-3831)\n\nDavid Watson discovered that the kernel did not correctly strip permissions\nwhen creating files in setgid directories. A local user could exploit this\nto gain additional group privileges. This issue only affected Ubuntu 6.06.\n(CVE-2008-4210)\n\nOlaf Kirch and Miklos Szeredi discovered that the Linux kernel did\nnot correctly reject the \"append\" flag when handling file splice\nrequests. A local attacker could bypass append mode and make changes to\narbitrary locations in a file. This issue only affected Ubuntu 7.10 and\n8.04. (CVE-2008-4554)\n\nIt was discovered that the SCTP stack did not correctly handle INIT-ACK. A\nremote user could exploit this by sending specially crafted SCTP traffic\nwhich would trigger a crash in the system, leading to a denial of service.\nThis issue did not affect Ubuntu 8.10. (CVE-2008-4576)\n\nIt was discovered that the SCTP stack did not correctly handle bad packet\nlengths. A remote user could exploit this by sending specially crafted SCTP\ntraffic which would trigger a crash in the system, leading to a denial of\nservice. This issue did not affect Ubuntu 8.10. (CVE-2008-4618)\n\nEric Sesterhenn discovered multiple flaws in the HFS+ filesystem. If a\nlocal user or automated system were tricked into mounting a malicious HFS+\nfilesystem, the system could crash, leading to a denial of service.\n(CVE-2008-4933, CVE-2008-4934, CVE-2008-5025)\n\nIt was discovered that the Unix Socket handler did not correctly process\nthe SCM_RIGHTS message. A local attacker could make a malicious socket\nrequest that would crash the system, leading to a denial of service.\n(CVE-2008-5029)\n\nIt was discovered that the driver for simple i2c audio interfaces did not\ncorrectly validate certain function pointers. A local user could exploit\nthis to gain root privileges or crash the system, leading to a denial of\nservice. (CVE-2008-5033)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-backports-modules-2.6.22","version":"2.6.22-16.17","description":"","is_source":true},{"name":"linux-ubuntu-modules-2.6.22","version":"2.6.22-16.41","description":"","is_source":true},{"name":"linux-restricted-modules-2.6.22","version":"2.6.22.4-16.12","description":"","is_source":true},{"name":"linux-source-2.6.22","version":"2.6.22-16.60","description":"","is_source":true},{"name":"linux-image-2.6.22-16-mckinley","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc64-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-virtual","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-cell","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-hppa64","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-sparc64-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-generic","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-lpia","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-386","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-hppa32","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-rt","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-xen","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-itanium","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-lpiacompat","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-ume","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-sparc64","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-server","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"}],"dapper":[{"name":"linux-restricted-modules-2.6.15","version":"2.6.15.12-53.4","description":"","is_source":true},{"name":"linux-source-2.6.15","version":"2.6.15-53.74","description":"","is_source":true},{"name":"linux-backports-modules-2.6.15","version":"2.6.15-53.11","description":"","is_source":true},{"name":"linux-image-2.6.15-53-powerpc64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-powerpc","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-xeon","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-386","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-generic","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-686","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa64","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-sparc64","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-server","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-k8","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-sparc64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-itanium-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa32","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa32-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-mckinley","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-powerpc-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-server-bigiron","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-mckinley-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-server","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-itanium","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-k7","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"}],"intrepid":[{"name":"linux-restricted-modules","version":"2.6.27-9.13","description":"","is_source":true},{"name":"linux-backports-modules-2.6.27","version":"2.6.27-9.5","description":"","is_source":true},{"name":"linux","version":"2.6.27-9.19","description":"","is_source":true},{"name":"linux-image-2.6.27-9-virtual","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"},{"name":"linux-image-2.6.27-9-generic","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"},{"name":"linux-image-2.6.27-9-server","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"}],"hardy":[{"name":"linux-restricted-modules-2.6.24","version":"2.6.24.14-22.53","description":"","is_source":true},{"name":"linux-ubuntu-modules-2.6.24","version":"2.6.24-22.35","description":"","is_source":true},{"name":"linux","version":"2.6.24-22.45","description":"","is_source":true},{"name":"linux-backports-modules-2.6.24","version":"2.6.24-22.29","description":"","is_source":true},{"name":"linux-image-2.6.24-22-powerpc","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-sparc64","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-virtual","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-server","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-lpia","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-hppa32","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-lpiacompat","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-rt","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-generic","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-hppa64","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-xen","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-mckinley","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-powerpc64-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-itanium","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-openvz","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-386","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-sparc64-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-powerpc-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"}]},"type":"USN","cves_ids":["CVE-2007-5498","CVE-2008-3831","CVE-2008-4210","CVE-2008-4554","CVE-2008-4576","CVE-2008-4618","CVE-2008-4933","CVE-2008-4934","CVE-2008-5025","CVE-2008-5029","CVE-2008-5033"]}]},{"id":"CVE-2007-6718","published":"2008-10-20T17:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of\nservice (SIGSEGV and application crash) via (1) a malformed MP3 file, as\ndemonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vorbis file, as\ndemonstrated by lol-mplayer.ogg; (3) a malformed MPEG-1 file, as\ndemonstrated by lol-mplayer.mpg; (4) a malformed MPEG-2 file, as\ndemonstrated by lol-mplayer.m2v; (5) a malformed MPEG-4 AVI file, as\ndemonstrated by lol-mplayer.avi; (6) a malformed FLAC file, as demonstrated\nby lol-mplayer.flac; (7) a malformed Ogg Theora file, as demonstrated by\nlol-mplayer.ogm; (8) a malformed WMV file, as demonstrated by\nlol-mplayer.wmv; or (9) a malformed AAC file, as demonstrated by\nlol-mplayer.aac. NOTE: vector 5 might overlap CVE-2007-4938, and vector 6\nmight overlap CVE-2008-0486.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-6718"],"bugs":[""],"patches":{"mplayer":[]},"tags":{},"packages":[{"name":"mplayer","source":"https://ubuntu.com/security/cve?package=mplayer","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mplayer","debian":"https://tracker.debian.org/pkg/mplayer","statuses":[{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2:1.0rc4.dfsg1+svn34540-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:1.0rc4.dfsg1+svn34540-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected [2:1.0rc4.dfsg1+svn34540-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4610","published":"2008-10-20T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMPlayer allows remote attackers to cause a denial of service (application\ncrash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2)\na malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm,\ndifferent vectors than CVE-2007-6718.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"First issue is the same as CVE-2008-5244, but for mplayer\nThe ogm issue is a ffmpeg problem. Just a crasher."},{"author":"sbeattie","note":"according to debian, first issue is actually a crash in\nlibfaad2, though earlier mplayer didn't link against system libfaad2\nexamining packages, 2:1.0~rc4.dfsg1+svn33713-1 appears to\nbe the first one that links against system libfaad"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://security-tracker.debian.net/tracker/CVE-2008-4610","https://ubuntu.com/security/notices/USN-734-1","https://www.cve.org/CVERecord?id=CVE-2008-4610"],"bugs":[""],"patches":{"mplayer":[],"ffmpeg":["vendor: http://patch-tracking.debian.net/patch/series/view/ffmpeg-debian/0.svn20080206-17/050_CVE-2008-4610.patch"],"ffmpeg-debian":["vendor: http://patch-tracking.debian.net/patch/series/view/ffmpeg-debian/0.svn20080206-17/050_CVE-2008-4610.patch"]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"3:0.cvs20070307-5ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3:0.cvs20070307-5ubuntu7.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3:0.svn20090303-1ubuntu2+unstripped1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3:0.svn20090303-1ubuntu2+unstripped1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3:0.svn20090303-1ubuntu2+unstripped1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3:0.svn20090303-1ubuntu2+unstripped1","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ffmpeg-debian","source":"https://ubuntu.com/security/cve?package=ffmpeg-debian","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg-debian","debian":"https://tracker.debian.org/pkg/ffmpeg-debian","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3:0.svn20080206-12ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3:0.svn20090303-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mplayer","source":"https://ubuntu.com/security/cve?package=mplayer","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mplayer","debian":"https://tracker.debian.org/pkg/mplayer","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2:1.0~rc4.dfsg1+svn33713-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2:1.0~rc4.dfsg1+svn33713-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2:1.0~rc4.dfsg1+svn33713-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2:1.0~rc4.dfsg1+svn33713-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2:1.0~rc4.dfsg1+svn33713-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-734-1"],"notices":[{"id":"USN-734-1","title":"FFmpeg vulnerabilities","summary":"FFmpeg vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-03-16T22:45:49.392631","description":"It was discovered that FFmpeg did not correctly handle certain malformed\nOgg Media (OGM) files. If a user were tricked into opening a crafted Ogg\nMedia file, an attacker could cause the application using FFmpeg to crash,\nleading to a denial of service. (CVE-2008-4610)\n\nIt was discovered that FFmpeg did not correctly handle certain parameters\nwhen creating DTS streams. If a user were tricked into processing certain\ncommands, an attacker could cause a denial of service via application\ncrash, or possibly execute arbitrary code with the privileges of the user\ninvoking the program. This issue only affected Ubuntu 8.10. (CVE-2008-4866)\n\nIt was discovered that FFmpeg did not correctly handle certain malformed\nDTS Coherent Acoustics (DCA) files. If a user were tricked into opening a\ncrafted DCA file, an attacker could cause a denial of service via\napplication crash, or possibly execute arbitrary code with the privileges\nof the user invoking the program. (CVE-2008-4867)\n\nIt was discovered that FFmpeg did not correctly handle certain malformed 4X\nmovie (4xm) files. If a user were tricked into opening a crafted 4xm file,\nan attacker could execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2009-0385)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"ffmpeg","version":"3:0.cvs20070307-5ubuntu4.2","description":"","is_source":true},{"name":"libavformat1d","version":"3:0.cvs20070307-5ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg/3:0.cvs20070307-5ubuntu4.2"},{"name":"libavcodec1d","version":"3:0.cvs20070307-5ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg/3:0.cvs20070307-5ubuntu4.2"}],"intrepid":[{"name":"ffmpeg-debian","version":"3:0.svn20080206-12ubuntu3.1","description":"","is_source":true},{"name":"libavformat52","version":"3:0.svn20080206-12ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg-debian","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg-debian/3:0.svn20080206-12ubuntu3.1"},{"name":"libavcodec51","version":"3:0.svn20080206-12ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg-debian","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg-debian/3:0.svn20080206-12ubuntu3.1"}],"hardy":[{"name":"ffmpeg","version":"3:0.cvs20070307-5ubuntu7.3","description":"","is_source":true},{"name":"libavformat1d","version":"3:0.cvs20070307-5ubuntu7.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg/3:0.cvs20070307-5ubuntu7.3"},{"name":"libavcodec1d","version":"3:0.cvs20070307-5ubuntu7.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ffmpeg","version_link":"https://launchpad.net/ubuntu/+source/ffmpeg/3:0.cvs20070307-5ubuntu7.3"}]},"type":"USN","cves_ids":["CVE-2008-4610","CVE-2008-4867","CVE-2009-0385","CVE-2008-4866"]}]},{"id":"CVE-2008-4401","published":"2008-10-17T19:31:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require\nuser interaction in conjunction with (1) the FileReference.browse operation\nin the FileReference upload API or (2) the FileReference.download operation\nin the FileReference download API, which allows remote attackers to create\na browse dialog box, and possibly have unspecified other impact, via an SWF\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4401"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.0.246.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"10.0.12.36ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"10.0.12.36ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"10.0.12.36ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.12.36","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4578","published":"2008-10-15T20:08:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended\naccess restrictions by using the \"k\" right to create unauthorized\n\"parent/child/child\" mailboxes.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"patch seems intrusive"},{"author":"mdeslaur","note":"Red Hat and Debian aren't going to fix this in 1.0.x as patch is\ntoo intrusive to backport for a minor issue.\nLet's ignore this also."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4578"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502967","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-4578"],"patches":{"dovecot":["other: http://hg.dovecot.org/dovecot-1.1/rev/d2657188377b"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":74900,"limit":20,"total_results":79316}