{"cves":[{"id":"CVE-2008-4577","published":"2008-10-15T20:08:00","updated_at":"2025-08-25T19:39:42.138477+00:00","description":"\nThe ACL plugin in Dovecot before 1.1.4 treats negative access rights as if\nthey are positive access rights, which allows attackers to bypass intended\naccess restrictions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-838-1","https://www.cve.org/CVERecord?id=CVE-2008-4577"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502967","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-4577"],"patches":{"dovecot":["other: http://hg.dovecot.org/dovecot-1.0/rev/2dc3a5678fe5"]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:1.0.10-1ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-838-1"],"notices":[{"id":"USN-838-1","title":"Dovecot vulnerabilities","summary":"Dovecot vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-09-28T12:44:52.125658","description":"It was discovered that the ACL plugin in Dovecot would incorrectly handle\nnegative access rights. An attacker could exploit this flaw to access the\nDovecot server, bypassing the intended access restrictions. This only\naffected Ubuntu 8.04 LTS. (CVE-2008-4577)\n\nIt was discovered that the ManageSieve service in Dovecot incorrectly\nhandled \"..\" in script names. A remote attacker could exploit this to read\nand modify arbitrary sieve files on the server. This only affected Ubuntu\n8.10. (CVE-2008-5301)\n\nIt was discovered that the Sieve plugin in Dovecot incorrectly handled\ncertain sieve scripts. An authenticated user could exploit this with a\ncrafted sieve script to cause a denial of service or possibly execute\narbitrary code. (CVE-2009-2632, CVE-2009-3235)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"dovecot","version":"1:1.0.10-1ubuntu5.2","description":"","is_source":true},{"name":"dovecot-common","version":"1:1.0.10-1ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dovecot","version_link":"https://launchpad.net/ubuntu/+source/dovecot/1:1.0.10-1ubuntu5.2"}],"intrepid":[{"name":"dovecot","version":"1:1.1.4-0ubuntu1.3","description":"","is_source":true},{"name":"dovecot-common","version":"1:1.1.4-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dovecot","version_link":"https://launchpad.net/ubuntu/+source/dovecot/1:1.1.4-0ubuntu1.3"}],"jaunty":[{"name":"dovecot","version":"1:1.1.11-0ubuntu4.1","description":"","is_source":true},{"name":"dovecot-common","version":"1:1.1.11-0ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dovecot","version_link":"https://launchpad.net/ubuntu/+source/dovecot/1:1.1.11-0ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2008-4577","CVE-2008-5301","CVE-2009-2632","CVE-2009-3235"]}]},{"id":"CVE-2008-4576","published":"2008-10-15T20:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a\ndenial of service (OOPS) via an INIT-ACK that states the peer does not\nsupport AUTH, which causes the sctp_process_init function to clean up\nactive transports and triggers the OOPS when the T1-Init timer expires.","ubuntu_description":"\nIt was discovered that the SCTP stack did not correctly handle INIT-ACK.\nA remote user could exploit this by sending specially crafted SCTP\ntraffic which would trigger a crash in the system, leading to a denial\nof service.  This issue did not affect Ubuntu 8.10.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-679-1","https://www.cve.org/CVERecord?id=CVE-2008-4576"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=add52379dde2e5300e2d574b172e62c6cf43b3d3"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-22.45","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc7","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-53.74","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc7","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-16.60","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc7","component":null,"pocket":"security"}]}],"notices_ids":["USN-679-1"],"notices":[{"id":"USN-679-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2008-11-27T17:43:01.542705","description":"It was discovered that the Xen hypervisor block driver did not correctly\nvalidate requests. A user with root privileges in a guest OS could make a\nmalicious IO request with a large number of blocks that would crash the\nhost OS, leading to a denial of service. This only affected Ubuntu 7.10.\n(CVE-2007-5498)\n\nIt was discovered the the i915 video driver did not correctly validate\nmemory addresses. A local attacker could exploit this to remap memory that\ncould cause a system crash, leading to a denial of service. This issue did\nnot affect Ubuntu 6.06 and was previous fixed for Ubuntu 7.10 and 8.04 in\nUSN-659-1. Ubuntu 8.10 has now been corrected as well. (CVE-2008-3831)\n\nDavid Watson discovered that the kernel did not correctly strip permissions\nwhen creating files in setgid directories. A local user could exploit this\nto gain additional group privileges. This issue only affected Ubuntu 6.06.\n(CVE-2008-4210)\n\nOlaf Kirch and Miklos Szeredi discovered that the Linux kernel did\nnot correctly reject the \"append\" flag when handling file splice\nrequests. A local attacker could bypass append mode and make changes to\narbitrary locations in a file. This issue only affected Ubuntu 7.10 and\n8.04. (CVE-2008-4554)\n\nIt was discovered that the SCTP stack did not correctly handle INIT-ACK. A\nremote user could exploit this by sending specially crafted SCTP traffic\nwhich would trigger a crash in the system, leading to a denial of service.\nThis issue did not affect Ubuntu 8.10. (CVE-2008-4576)\n\nIt was discovered that the SCTP stack did not correctly handle bad packet\nlengths. A remote user could exploit this by sending specially crafted SCTP\ntraffic which would trigger a crash in the system, leading to a denial of\nservice. This issue did not affect Ubuntu 8.10. (CVE-2008-4618)\n\nEric Sesterhenn discovered multiple flaws in the HFS+ filesystem. If a\nlocal user or automated system were tricked into mounting a malicious HFS+\nfilesystem, the system could crash, leading to a denial of service.\n(CVE-2008-4933, CVE-2008-4934, CVE-2008-5025)\n\nIt was discovered that the Unix Socket handler did not correctly process\nthe SCM_RIGHTS message. A local attacker could make a malicious socket\nrequest that would crash the system, leading to a denial of service.\n(CVE-2008-5029)\n\nIt was discovered that the driver for simple i2c audio interfaces did not\ncorrectly validate certain function pointers. A local user could exploit\nthis to gain root privileges or crash the system, leading to a denial of\nservice. (CVE-2008-5033)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-backports-modules-2.6.22","version":"2.6.22-16.17","description":"","is_source":true},{"name":"linux-ubuntu-modules-2.6.22","version":"2.6.22-16.41","description":"","is_source":true},{"name":"linux-restricted-modules-2.6.22","version":"2.6.22.4-16.12","description":"","is_source":true},{"name":"linux-source-2.6.22","version":"2.6.22-16.60","description":"","is_source":true},{"name":"linux-image-2.6.22-16-mckinley","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc64-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-virtual","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-cell","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-hppa64","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-sparc64-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-generic","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-lpia","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-386","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-hppa32","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-rt","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-xen","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-itanium","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-lpiacompat","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-ume","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-sparc64","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-server","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"}],"dapper":[{"name":"linux-restricted-modules-2.6.15","version":"2.6.15.12-53.4","description":"","is_source":true},{"name":"linux-source-2.6.15","version":"2.6.15-53.74","description":"","is_source":true},{"name":"linux-backports-modules-2.6.15","version":"2.6.15-53.11","description":"","is_source":true},{"name":"linux-image-2.6.15-53-powerpc64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-powerpc","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-xeon","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-386","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-generic","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-686","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa64","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-sparc64","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-server","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-k8","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-sparc64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-itanium-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa32","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa32-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-mckinley","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-powerpc-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-server-bigiron","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-mckinley-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-server","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-itanium","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-k7","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"}],"intrepid":[{"name":"linux-restricted-modules","version":"2.6.27-9.13","description":"","is_source":true},{"name":"linux-backports-modules-2.6.27","version":"2.6.27-9.5","description":"","is_source":true},{"name":"linux","version":"2.6.27-9.19","description":"","is_source":true},{"name":"linux-image-2.6.27-9-virtual","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"},{"name":"linux-image-2.6.27-9-generic","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"},{"name":"linux-image-2.6.27-9-server","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"}],"hardy":[{"name":"linux-restricted-modules-2.6.24","version":"2.6.24.14-22.53","description":"","is_source":true},{"name":"linux-ubuntu-modules-2.6.24","version":"2.6.24-22.35","description":"","is_source":true},{"name":"linux","version":"2.6.24-22.45","description":"","is_source":true},{"name":"linux-backports-modules-2.6.24","version":"2.6.24-22.29","description":"","is_source":true},{"name":"linux-image-2.6.24-22-powerpc","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-sparc64","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-virtual","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-server","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-lpia","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-hppa32","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-lpiacompat","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-rt","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-generic","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-hppa64","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-xen","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-mckinley","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-powerpc64-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-itanium","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-openvz","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-386","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-sparc64-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-powerpc-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"}]},"type":"USN","cves_ids":["CVE-2007-5498","CVE-2008-3831","CVE-2008-4210","CVE-2008-4554","CVE-2008-4576","CVE-2008-4618","CVE-2008-4933","CVE-2008-4934","CVE-2008-5025","CVE-2008-5029","CVE-2008-5033"]}]},{"id":"CVE-2008-4575","published":"2008-10-15T20:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the DoCommand function in jhead before 2.84 might allow\ncontext-dependent attackers to cause a denial of service (crash) via (1) a\nlong -cmd argument and (2) unspecified vectors related to \"a bunch of\npotential string overflows.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4575"],"bugs":[""],"patches":{"jhead":[]},"tags":{},"packages":[{"name":"jhead","source":"https://ubuntu.com/security/cve?package=jhead","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jhead","debian":"https://tracker.debian.org/pkg/jhead","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.84-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.84","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4554","published":"2008-10-15T20:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe do_splice_from function in fs/splice.c in the Linux kernel before\n2.6.27 does not reject file descriptors that have the O_APPEND flag set,\nwhich allows local users to bypass append mode and make arbitrary changes\nto other locations in the file.","ubuntu_description":"\nOlaf Kirch and Miklos Szeredi discovered that the Linux kernel did not\ncorrectly reject the \"append\" flag when handling file splice requests. A\nlocal attacker could bypass append mode and make changes to arbitrary\nlocations in a file. This issue only affected Ubuntu 7.10 and 8.04.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-679-1","https://www.cve.org/CVERecord?id=CVE-2008-4554"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.22":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commitdiff;h=efc968d450e013049a662d22727cf132618dcb2f"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-22.45","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-16.60","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27","component":null,"pocket":"security"}]}],"notices_ids":["USN-679-1"],"notices":[{"id":"USN-679-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2008-11-27T17:43:01.542705","description":"It was discovered that the Xen hypervisor block driver did not correctly\nvalidate requests. A user with root privileges in a guest OS could make a\nmalicious IO request with a large number of blocks that would crash the\nhost OS, leading to a denial of service. This only affected Ubuntu 7.10.\n(CVE-2007-5498)\n\nIt was discovered the the i915 video driver did not correctly validate\nmemory addresses. A local attacker could exploit this to remap memory that\ncould cause a system crash, leading to a denial of service. This issue did\nnot affect Ubuntu 6.06 and was previous fixed for Ubuntu 7.10 and 8.04 in\nUSN-659-1. Ubuntu 8.10 has now been corrected as well. (CVE-2008-3831)\n\nDavid Watson discovered that the kernel did not correctly strip permissions\nwhen creating files in setgid directories. A local user could exploit this\nto gain additional group privileges. This issue only affected Ubuntu 6.06.\n(CVE-2008-4210)\n\nOlaf Kirch and Miklos Szeredi discovered that the Linux kernel did\nnot correctly reject the \"append\" flag when handling file splice\nrequests. A local attacker could bypass append mode and make changes to\narbitrary locations in a file. This issue only affected Ubuntu 7.10 and\n8.04. (CVE-2008-4554)\n\nIt was discovered that the SCTP stack did not correctly handle INIT-ACK. A\nremote user could exploit this by sending specially crafted SCTP traffic\nwhich would trigger a crash in the system, leading to a denial of service.\nThis issue did not affect Ubuntu 8.10. (CVE-2008-4576)\n\nIt was discovered that the SCTP stack did not correctly handle bad packet\nlengths. A remote user could exploit this by sending specially crafted SCTP\ntraffic which would trigger a crash in the system, leading to a denial of\nservice. This issue did not affect Ubuntu 8.10. (CVE-2008-4618)\n\nEric Sesterhenn discovered multiple flaws in the HFS+ filesystem. If a\nlocal user or automated system were tricked into mounting a malicious HFS+\nfilesystem, the system could crash, leading to a denial of service.\n(CVE-2008-4933, CVE-2008-4934, CVE-2008-5025)\n\nIt was discovered that the Unix Socket handler did not correctly process\nthe SCM_RIGHTS message. A local attacker could make a malicious socket\nrequest that would crash the system, leading to a denial of service.\n(CVE-2008-5029)\n\nIt was discovered that the driver for simple i2c audio interfaces did not\ncorrectly validate certain function pointers. A local user could exploit\nthis to gain root privileges or crash the system, leading to a denial of\nservice. (CVE-2008-5033)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-backports-modules-2.6.22","version":"2.6.22-16.17","description":"","is_source":true},{"name":"linux-ubuntu-modules-2.6.22","version":"2.6.22-16.41","description":"","is_source":true},{"name":"linux-restricted-modules-2.6.22","version":"2.6.22.4-16.12","description":"","is_source":true},{"name":"linux-source-2.6.22","version":"2.6.22-16.60","description":"","is_source":true},{"name":"linux-image-2.6.22-16-mckinley","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc64-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-virtual","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-cell","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-hppa64","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-sparc64-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-generic","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-lpia","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc-smp","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-386","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-hppa32","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-rt","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-xen","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-powerpc","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-itanium","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-lpiacompat","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-ume","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-sparc64","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"},{"name":"linux-image-2.6.22-16-server","version":"2.6.22-16.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-16.60"}],"dapper":[{"name":"linux-restricted-modules-2.6.15","version":"2.6.15.12-53.4","description":"","is_source":true},{"name":"linux-source-2.6.15","version":"2.6.15-53.74","description":"","is_source":true},{"name":"linux-backports-modules-2.6.15","version":"2.6.15-53.11","description":"","is_source":true},{"name":"linux-image-2.6.15-53-powerpc64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-powerpc","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-xeon","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-386","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-generic","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-686","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa64","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-sparc64","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-server","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-amd64-k8","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-sparc64-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-itanium-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa32","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-hppa32-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-mckinley","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-powerpc-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-server-bigiron","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-mckinley-smp","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-server","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-itanium","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"},{"name":"linux-image-2.6.15-53-k7","version":"2.6.15-53.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-53.74"}],"intrepid":[{"name":"linux-restricted-modules","version":"2.6.27-9.13","description":"","is_source":true},{"name":"linux-backports-modules-2.6.27","version":"2.6.27-9.5","description":"","is_source":true},{"name":"linux","version":"2.6.27-9.19","description":"","is_source":true},{"name":"linux-image-2.6.27-9-virtual","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"},{"name":"linux-image-2.6.27-9-generic","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"},{"name":"linux-image-2.6.27-9-server","version":"2.6.27-9.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-9.19"}],"hardy":[{"name":"linux-restricted-modules-2.6.24","version":"2.6.24.14-22.53","description":"","is_source":true},{"name":"linux-ubuntu-modules-2.6.24","version":"2.6.24-22.35","description":"","is_source":true},{"name":"linux","version":"2.6.24-22.45","description":"","is_source":true},{"name":"linux-backports-modules-2.6.24","version":"2.6.24-22.29","description":"","is_source":true},{"name":"linux-image-2.6.24-22-powerpc","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-sparc64","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-virtual","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-server","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-lpia","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-hppa32","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-lpiacompat","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-rt","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-generic","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-hppa64","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-xen","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-mckinley","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-powerpc64-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-itanium","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-openvz","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-386","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-sparc64-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"},{"name":"linux-image-2.6.24-22-powerpc-smp","version":"2.6.24-22.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-22.45"}]},"type":"USN","cves_ids":["CVE-2007-5498","CVE-2008-3831","CVE-2008-4210","CVE-2008-4554","CVE-2008-4576","CVE-2008-4618","CVE-2008-4933","CVE-2008-4934","CVE-2008-5025","CVE-2008-5029","CVE-2008-5033"]}]},{"id":"CVE-2008-4553","published":"2008-10-15T20:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nqemu-make-debian-root in qemu 0.9.1-5 on Debian GNU/Linux allows local\nusers to overwrite arbitrary files via a symlink attack on temporary files\nand directories.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4553"],"bugs":[""],"patches":{"qemu":[],"qemu-kvm":[]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"0.9.1-5ubuntu3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.9.1-5ubuntu3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.1-5","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.9.1-5ubuntu3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.9.1-5ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.9.1-5ubuntu3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.9.1-5ubuntu3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.9.1-5ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4571","published":"2008-10-15T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the LiveSearch module in Plone\nbefore 3.0.4 allows remote attackers to inject arbitrary web script or HTML\nvia the Description field for search results, as demonstrated using the\nonerror Javascript even in an IMG tag.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4571"],"bugs":[""],"patches":{"plone3":[]},"tags":{},"packages":[{"name":"plone3","source":"https://ubuntu.com/security/cve?package=plone3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=plone3","debian":"https://tracker.debian.org/pkg/plone3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4582","published":"2008-10-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and\nSeaMonkey 1.x before 1.1.13, when running on Windows, do not properly\nidentify the context of Windows .url shortcut files, which allows\nuser-assisted remote attackers to bypass the Same Origin Policy and obtain\nsensitive information via an HTML document that is directly accessible\nthrough a filesystem, as demonstrated by documents in (1) local folders,\n(2) Windows share folders, and (3) RAR archives, and as demonstrated by\nIFRAMEs referencing shortcuts that point to (a) about:cache?device=memory\nand (b) about:cache?device=disk, a variant of CVE-2008-2810.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-667-1","https://ubuntu.com/security/notices/USN-668-1","https://www.cve.org/CVERecord?id=CVE-2008-4582"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"iceweasel":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614h-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.18+nobinonly-0ubuntu0.7.10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.4+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.4+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.4+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.4+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.4+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"iceweasel","source":"https://ubuntu.com/security/cve?package=iceweasel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceweasel","debian":"https://tracker.debian.org/pkg/iceweasel","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.04.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.4+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.4+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-667-1"],"notices":[{"id":"USN-667-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplication that use xulrunner, such as Epiphany, to effect the\nnecessary changes.\n","references":[],"published":"2008-11-17T21:26:06.479740","description":"Liu Die Yu discovered an information disclosure vulnerability in Firefox\nwhen using saved .url shortcut files. If a user were tricked into\ndownloading a crafted .url file and a crafted HTML file, an attacker\ncould steal information from the user's cache. (CVE-2008-4582)\n\nGeorgi Guninski, Michal Zalewsk and Chris Evans discovered that the\nsame-origin check in Firefox could be bypassed. If a user were tricked\ninto opening a malicious website, an attacker could obtain private\ninformation from data stored in the images, or discover information\nabout software on the user's computer. This issue only affects Firefox 2.\n(CVE-2008-5012)\n\nIt was discovered that Firefox did not properly check if the Flash\nmodule was properly unloaded. By tricking a user into opening a crafted\nSWF file, an attacker could cause Firefox to crash and possibly execute\narbitrary code with user privileges. This issue only affects Firefox 2.\n(CVE-2008-5013)\n\nJesse Ruderman discovered that Firefox did not properly guard locks on\nnon-native objects. If a user were tricked into opening a malicious\nwebsite, an attacker could cause a browser crash and possibly execute\narbitrary code with user privileges. This issue only affects Firefox 2.\n(CVE-2008-5014)\n\nLuke Bryan discovered that Firefox sometimes opened file URIs with\nchrome privileges. If a user saved malicious code locally, then opened\nthe file in the same tab as a privileged document, an attacker could\nrun arbitrary JavaScript code with chrome privileges. This issue only\naffects Firefox 3.0. (CVE-2008-5015)\n\nSeveral problems were discovered in the browser, layout and JavaScript\nengines. These problems could allow an attacker to crash the browser\nand possibly execute arbitrary code with user privileges.\n(CVE-2008-5016, CVE-2008-5017, CVE-2008-5018)\n\nDavid Bloom discovered that the same-origin check in Firefox could be\nbypassed by utilizing the session restore feature. An attacker could\nexploit this to run JavaScript in the context of another site or\nexecute arbitrary JavaScript code with chrome privileges.\n(CVE-2008-5019)\n\nJustin Schuh discovered a flaw in Firefox's mime-type parsing. If a\nuser were tricked into opening a malicious website, an attacker could\nsend a crafted header in the HTTP index response, causing a browser\ncrash and execute arbitrary code with user privileges. (CVE-2008-0017)\n\nA flaw was discovered in Firefox's DOM constructing code. If a user\nwere tricked into opening a malicious website, an attacker could\ncause the browser to crash and potentially execute arbitrary code with\nuser privileges. (CVE-2008-5021)\n\nIt was discovered that the same-origin check in Firefox could be\nbypassed. If a user were tricked into opening a malicious website, an\nattacker could execute JavaScript in the context of a different website.\n(CVE-2008-5022)\n\nCollin Jackson discovered various flaws in Firefox when processing\nstylesheets which allowed JavaScript to be injected into signed JAR\nfiles. If a user were tricked into opening malicious web content, an\nattacker could execute arbitrary code with the privileges of the\nsigned JAR or of a different website. (CVE-2008-5023)\n\nChris Evans discovered that Firefox did not properly parse E4X\ndocuments, leading to quote characters in the namespace not being\nproperly escaped. (CVE-2008-5024)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.18+nobinonly-0ubuntu0.7.10","description":"","is_source":true},{"name":"firefox","version":"2.0.0.18+nobinonly-0ubuntu0.7.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.18+nobinonly-0ubuntu0.7.10"}],"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614h-0ubuntu1","description":"","is_source":true},{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614h-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/1.5.dfsg+1.5.0.15~prepatch080614h-0ubuntu1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.4+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.4+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.4+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.4+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.4+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.4+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.4+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.4+nobinonly-0ubuntu0.8.10.1"}],"hardy":[{"name":"firefox-3.0","version":"3.0.4+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.4+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.4+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.4+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.4+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.4+nobinonly-0ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-4582","CVE-2008-5012","CVE-2008-5013","CVE-2008-5014","CVE-2008-5015","CVE-2008-5016","CVE-2008-5017","CVE-2008-5018","CVE-2008-5019","CVE-2008-0017","CVE-2008-5021","CVE-2008-5022","CVE-2008-5023","CVE-2008-5024"]}]},{"id":"CVE-2008-4580","published":"2008-10-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local\nusers to modify arbitrary files via a symlink attack on the\nfence_manual.fifo temporary file.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"code not present in 7.10, 8.04 LTS and 8.10"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-875-1","https://www.cve.org/CVERecord?id=CVE-2008-4580"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496410"],"patches":{"redhat-cluster-suite":[],"redhat-cluster":[]},"tags":{},"packages":[{"name":"redhat-cluster","source":"https://ubuntu.com/security/cve?package=redhat-cluster","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=redhat-cluster","debian":"https://tracker.debian.org/pkg/redhat-cluster","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.20081102-1","component":null,"pocket":"security"}]},{"name":"redhat-cluster-suite","source":"https://ubuntu.com/security/cve?package=redhat-cluster-suite","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=redhat-cluster-suite","debian":"https://tracker.debian.org/pkg/redhat-cluster-suite","statuses":[{"release_codename":"dapper","status":"released","description":"1.20060222-0ubuntu6.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-875-1"],"notices":[{"id":"USN-875-1","title":"Red Hat Cluster Suite vulnerabilities","summary":"Red Hat Cluster Suite vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-12-18T16:23:20.591158","description":"Multiple insecure temporary file handling vulnerabilities were discovered\nin Red Hat Cluster. A local attacker could exploit these to overwrite\narbitrary local files via symlinks. (CVE-2008-4192, CVE-2008-4579,\nCVE-2008-4580, CVE-2008-6552)\n\nIt was discovered that CMAN did not properly handle malformed configuration\nfiles. An attacker could cause a denial of service (via CPU consumption and\nmemory corruption) in a node if the attacker were able to modify the\ncluster configuration for the node. (CVE-2008-6560)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"redhat-cluster","version":"2.20080227-0ubuntu1.3","description":"","is_source":true},{"name":"gfs2-tools","version":"2.20080227-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080227-0ubuntu1.3"},{"name":"cman","version":"2.20080227-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080227-0ubuntu1.3"},{"name":"rgmanager","version":"2.20080227-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080227-0ubuntu1.3"}],"dapper":[{"name":"redhat-cluster-suite","version":"1.20060222-0ubuntu6.3","description":"","is_source":true},{"name":"libcman1","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"},{"name":"ccs","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"},{"name":"cman","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"},{"name":"fence","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"},{"name":"rgmanager","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"}],"intrepid":[{"name":"redhat-cluster","version":"2.20080826-0ubuntu1.3","description":"","is_source":true},{"name":"gfs2-tools","version":"2.20080826-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080826-0ubuntu1.3"},{"name":"cman","version":"2.20080826-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080826-0ubuntu1.3"},{"name":"rgmanager","version":"2.20080826-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080826-0ubuntu1.3"}]},"type":"USN","cves_ids":["CVE-2008-4192","CVE-2008-4579","CVE-2008-4580","CVE-2008-6552","CVE-2008-6560"]}]},{"id":"CVE-2008-4579","published":"2008-10-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence\n2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows\nlocal users to append to arbitrary files via a symlink attack on the apclog\ntemporary file.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu 8.10 and 9.04 already includes the upstream patches"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-875-1","https://www.cve.org/CVERecord?id=CVE-2008-4579"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496410"],"patches":{"redhat-cluster-suite":[],"redhat-cluster":[]},"tags":{},"packages":[{"name":"redhat-cluster","source":"https://ubuntu.com/security/cve?package=redhat-cluster","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=redhat-cluster","debian":"https://tracker.debian.org/pkg/redhat-cluster","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.20080227-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.20081102-1","component":null,"pocket":"security"}]},{"name":"redhat-cluster-suite","source":"https://ubuntu.com/security/cve?package=redhat-cluster-suite","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=redhat-cluster-suite","debian":"https://tracker.debian.org/pkg/redhat-cluster-suite","statuses":[{"release_codename":"dapper","status":"released","description":"1.20060222-0ubuntu6.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-875-1"],"notices":[{"id":"USN-875-1","title":"Red Hat Cluster Suite vulnerabilities","summary":"Red Hat Cluster Suite vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-12-18T16:23:20.591158","description":"Multiple insecure temporary file handling vulnerabilities were discovered\nin Red Hat Cluster. A local attacker could exploit these to overwrite\narbitrary local files via symlinks. (CVE-2008-4192, CVE-2008-4579,\nCVE-2008-4580, CVE-2008-6552)\n\nIt was discovered that CMAN did not properly handle malformed configuration\nfiles. An attacker could cause a denial of service (via CPU consumption and\nmemory corruption) in a node if the attacker were able to modify the\ncluster configuration for the node. (CVE-2008-6560)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"redhat-cluster","version":"2.20080227-0ubuntu1.3","description":"","is_source":true},{"name":"gfs2-tools","version":"2.20080227-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080227-0ubuntu1.3"},{"name":"cman","version":"2.20080227-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080227-0ubuntu1.3"},{"name":"rgmanager","version":"2.20080227-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080227-0ubuntu1.3"}],"dapper":[{"name":"redhat-cluster-suite","version":"1.20060222-0ubuntu6.3","description":"","is_source":true},{"name":"libcman1","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"},{"name":"ccs","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"},{"name":"cman","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"},{"name":"fence","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"},{"name":"rgmanager","version":"1.20060222-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster-suite/1.20060222-0ubuntu6.3"}],"intrepid":[{"name":"redhat-cluster","version":"2.20080826-0ubuntu1.3","description":"","is_source":true},{"name":"gfs2-tools","version":"2.20080826-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080826-0ubuntu1.3"},{"name":"cman","version":"2.20080826-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080826-0ubuntu1.3"},{"name":"rgmanager","version":"2.20080826-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/redhat-cluster","version_link":"https://launchpad.net/ubuntu/+source/redhat-cluster/2.20080826-0ubuntu1.3"}]},"type":"USN","cves_ids":["CVE-2008-4192","CVE-2008-4579","CVE-2008-4580","CVE-2008-6552","CVE-2008-6560"]}]},{"id":"CVE-2008-4558","published":"2008-10-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nArray index error in VLC media player 0.9.2 allows remote attackers to\noverwrite arbitrary memory and execute arbitrary code via an XSPF playlist\nfile with a negative identifier tag, which passes a signed comparison.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"PoC: http://www.coresecurity.com/content/vlc-xspf-memory-corruption"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.coresecurity.com/content/vlc-xspf-memory-corruption","https://www.cve.org/CVERecord?id=CVE-2008-4558"],"bugs":[""],"patches":{"vlc":["upstream: http://git.videolan.org/?p=vlc.git;a=commit;h=6d3c22f29e650b0d10b2116fe3145194d20b8b56"]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"0.9.4-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.9.9a-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.0.0~rc2-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4555","published":"2008-10-14T21:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the push_subg function in parser.y\n(lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions,\nallows user-assisted remote attackers to cause a denial of service (memory\ncorruption) or execute arbitrary code via a DOT file with a large number of\nAgraph_t elements.","ubuntu_description":"","notes":[{"author":"kees","note":"http://roeehay.blogspot.com/2008/10/graphviz-buffer-overflow-code-execution.html"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4555"],"bugs":["https://launchpad.net/bugs/532060"],"patches":{"graphviz":[]},"tags":{},"packages":[{"name":"graphviz","source":"https://ubuntu.com/security/cve?package=graphviz","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=graphviz","debian":"https://tracker.debian.org/pkg/graphviz","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.20.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3640","published":"2008-10-14T21:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the WriteProlog function in texttops in CUPS before\n1.3.9 allows remote attackers to execute arbitrary code via a crafted\nPostScript file that triggers a heap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-656-1","https://www.cve.org/CVERecord?id=CVE-2008-3640"],"bugs":[""],"patches":{"cups":[],"cupsys":[]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9-1","component":null,"pocket":"security"}]},{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.2-0ubuntu0.6.06.11","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.8-0ubuntu8.6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.3.2-1ubuntu7.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.3.7-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-656-1"],"notices":[{"id":"USN-656-1","title":"CUPS vulnerabilities","summary":"CUPS vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-10-15T21:47:00.580440","description":"It was discovered that the SGI image filter in CUPS did not perform\nproper bounds checking. If a user or automated system were tricked\ninto opening a crafted SGI image, an attacker could cause a denial\nof service. (CVE-2008-3639)\n\nIt was discovered that the texttops filter in CUPS did not properly\nvalidate page metrics. If a user or automated system were tricked into\nopening a crafted text file, an attacker could cause a denial of\nservice. (CVE-2008-3640)\n\nIt was discovered that the HP-GL filter in CUPS did not properly check\nfor invalid pen parameters. If a user or automated system were tricked\ninto opening a crafted HP-GL or HP-GL/2 file, a remote attacker could\ncause a denial of service or execute arbitrary code with user\nprivileges. In Ubuntu 7.10 and 8.04 LTS, attackers would be isolated by\nthe AppArmor CUPS profile. (CVE-2008-3641)\n\nNOTE: The previous update for CUPS on Ubuntu 6.06 LTS did not have the\nthe fix for CVE-2008-1722 applied. This update includes fixes for the\nproblem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"cupsys","version":"1.3.2-1ubuntu7.8","description":"","is_source":true},{"name":"cupsys","version":"1.3.2-1ubuntu7.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.2-1ubuntu7.8"}],"dapper":[{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.11","description":"","is_source":true},{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.2-0ubuntu0.6.06.11"}],"feisty":[{"name":"cupsys","version":"1.2.8-0ubuntu8.6","description":"","is_source":true},{"name":"cupsys","version":"1.2.8-0ubuntu8.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.8-0ubuntu8.6"}],"hardy":[{"name":"cupsys","version":"1.3.7-1ubuntu3.1","description":"","is_source":true},{"name":"cupsys","version":"1.3.7-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.7-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2008-1722","CVE-2008-3639","CVE-2008-3640","CVE-2008-3641"]}]},{"id":"CVE-2008-3639","published":"2008-10-14T21:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the read_rle16 function in imagetops in CUPS\nbefore 1.3.9 allows remote attackers to execute arbitrary code via an SGI\nimage with malformed Run Length Encoded (RLE) data containing a small image\nand a large row count.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-656-1","https://www.cve.org/CVERecord?id=CVE-2008-3639"],"bugs":[""],"patches":{"cups":[],"cupsys":[]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9-1","component":null,"pocket":"security"}]},{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.2-0ubuntu0.6.06.11","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.8-0ubuntu8.6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.3.2-1ubuntu7.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.3.7-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-656-1"],"notices":[{"id":"USN-656-1","title":"CUPS vulnerabilities","summary":"CUPS vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-10-15T21:47:00.580440","description":"It was discovered that the SGI image filter in CUPS did not perform\nproper bounds checking. If a user or automated system were tricked\ninto opening a crafted SGI image, an attacker could cause a denial\nof service. (CVE-2008-3639)\n\nIt was discovered that the texttops filter in CUPS did not properly\nvalidate page metrics. If a user or automated system were tricked into\nopening a crafted text file, an attacker could cause a denial of\nservice. (CVE-2008-3640)\n\nIt was discovered that the HP-GL filter in CUPS did not properly check\nfor invalid pen parameters. If a user or automated system were tricked\ninto opening a crafted HP-GL or HP-GL/2 file, a remote attacker could\ncause a denial of service or execute arbitrary code with user\nprivileges. In Ubuntu 7.10 and 8.04 LTS, attackers would be isolated by\nthe AppArmor CUPS profile. (CVE-2008-3641)\n\nNOTE: The previous update for CUPS on Ubuntu 6.06 LTS did not have the\nthe fix for CVE-2008-1722 applied. This update includes fixes for the\nproblem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"cupsys","version":"1.3.2-1ubuntu7.8","description":"","is_source":true},{"name":"cupsys","version":"1.3.2-1ubuntu7.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.2-1ubuntu7.8"}],"dapper":[{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.11","description":"","is_source":true},{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.2-0ubuntu0.6.06.11"}],"feisty":[{"name":"cupsys","version":"1.2.8-0ubuntu8.6","description":"","is_source":true},{"name":"cupsys","version":"1.2.8-0ubuntu8.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.8-0ubuntu8.6"}],"hardy":[{"name":"cupsys","version":"1.3.7-1ubuntu3.1","description":"","is_source":true},{"name":"cupsys","version":"1.3.7-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.7-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2008-1722","CVE-2008-3639","CVE-2008-3640","CVE-2008-3641"]}]},{"id":"CVE-2008-4552","published":"2008-10-14T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe good_client function in nfs-utils 1.0.9, and possibly other versions\nbefore 1.1.3, invokes the hosts_ctl function with the wrong order of\narguments, which causes TCP Wrappers to ignore netgroups and allows remote\nattackers to bypass intended access restrictions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-687-1","https://www.cve.org/CVERecord?id=CVE-2008-4552"],"bugs":[""],"patches":{"nfs-utils":[]},"tags":{},"packages":[{"name":"nfs-utils","source":"https://ubuntu.com/security/cve?package=nfs-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nfs-utils","debian":"https://tracker.debian.org/pkg/nfs-utils","statuses":[{"release_codename":"dapper","status":"released","description":"1:1.0.7-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1:1.1.1~git-20070709-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:1.1.2-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:1.1.2-4ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-687-1"],"notices":[{"id":"USN-687-1","title":"nfs-utils vulnerability","summary":"nfs-utils vulnerability","instructions":"After a standard system upgrade you need to restart nfs services to effect\nthe necessary changes.\n","references":[],"published":"2008-12-04T20:58:21.953027","description":"It was discovered that nfs-utils did not properly enforce netgroup\nrestrictions when using TCP Wrappers. Remote attackers could bypass the\nnetgroup restrictions enabled by the administrator and possibly gain\naccess to sensitive information.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"nfs-utils","version":"1:1.1.1~git-20070709-3ubuntu1.1","description":"","is_source":true},{"name":"nfs-kernel-server","version":"1:1.1.1~git-20070709-3ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nfs-utils","version_link":"https://launchpad.net/ubuntu/+source/nfs-utils/1:1.1.1~git-20070709-3ubuntu1.1"}],"dapper":[{"name":"nfs-utils","version":"1:1.0.7-3ubuntu2.1","description":"","is_source":true},{"name":"nfs-kernel-server","version":"1:1.0.7-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nfs-utils","version_link":"https://launchpad.net/ubuntu/+source/nfs-utils/1:1.0.7-3ubuntu2.1"}],"intrepid":[{"name":"nfs-utils","version":"1:1.1.2-4ubuntu1.1","description":"","is_source":true},{"name":"nfs-kernel-server","version":"1:1.1.2-4ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nfs-utils","version_link":"https://launchpad.net/ubuntu/+source/nfs-utils/1:1.1.2-4ubuntu1.1"}],"hardy":[{"name":"nfs-utils","version":"1:1.1.2-2ubuntu2.2","description":"","is_source":true},{"name":"nfs-kernel-server","version":"1:1.1.2-2ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nfs-utils","version_link":"https://launchpad.net/ubuntu/+source/nfs-utils/1:1.1.2-2ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2008-4552"]}]},{"id":"CVE-2008-4551","published":"2008-10-14T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nstrongSwan 4.2.6 and earlier allows remote attackers to cause a denial of\nservice (daemon crash) via an IKE_SA_INIT message with a large number of\nNULL values in a Key Exchange payload, which triggers a NULL pointer\ndereference for the return value of the mpz_export function in the GNU\nMultiprecision Library (GMP).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4551"],"bugs":[""],"patches":{"strongswan":[]},"tags":{},"packages":[{"name":"strongswan","source":"https://ubuntu.com/security/cve?package=strongswan","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=strongswan","debian":"https://tracker.debian.org/pkg/strongswan","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"4.2.4-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.4-5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4546","published":"2008-10-14T15:28:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe\nAIR before 2.0.2.12610, allows remote web servers to cause a denial of\nservice (NULL pointer dereference and browser crash) by returning a\ndifferent response when an HTTP request is sent a second time, as\ndemonstrated by two responses that provide SWF files with different SWF\nversion numbers.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.adobe.com/support/security/bulletins/apsb10-14.html","https://www.cve.org/CVERecord?id=CVE-2008-4546"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.1.53.64-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.53.64-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.53.64-1karmic1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.53.64-1lucid1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.53.64","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.0.1.218+really9.0.277.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.53.64ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.53.64ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.53.64ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.227.0,10.1.53.64","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3271","published":"2008-10-13T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to\nbypass an IP address restriction and obtain sensitive information via a\nrequest that is processed concurrently with another request but in a\ndifferent thread, leading to an instance-variable overwrite associated with\na \"synchronization problem\" and lack of thread safety, and related to\nRemoteFilterValve, RemoteAddrValve, and RemoteHostValve.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3271"],"bugs":[""],"patches":{"tomcat4":[],"tomcat5":[],"tomcat5.5":[]},"tags":{},"packages":[{"name":"tomcat4","source":"https://ubuntu.com/security/cve?package=tomcat4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat4","debian":"https://tracker.debian.org/pkg/tomcat4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat5","source":"https://ubuntu.com/security/cve?package=tomcat5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5","debian":"https://tracker.debian.org/pkg/tomcat5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.5.25-5ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3641","published":"2008-10-10T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9\nallows remote attackers to execute arbitrary code via crafted pen width and\npen color opcodes that overwrite arbitrary memory.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"shellcode in the wild"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-656-1","https://www.cve.org/CVERecord?id=CVE-2008-3641"],"bugs":[""],"patches":{"cups":[],"cupsys":[]},"tags":{"cupsys":["apparmor"],"cupsys_gutsy":["apparmor"],"cupsys_hardy":["apparmor"]},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9","component":null,"pocket":"security"}]},{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.2-0ubuntu0.6.06.11","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.8-0ubuntu8.6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.3.2-1ubuntu7.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.3.7-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-656-1"],"notices":[{"id":"USN-656-1","title":"CUPS vulnerabilities","summary":"CUPS vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-10-15T21:47:00.580440","description":"It was discovered that the SGI image filter in CUPS did not perform\nproper bounds checking. If a user or automated system were tricked\ninto opening a crafted SGI image, an attacker could cause a denial\nof service. (CVE-2008-3639)\n\nIt was discovered that the texttops filter in CUPS did not properly\nvalidate page metrics. If a user or automated system were tricked into\nopening a crafted text file, an attacker could cause a denial of\nservice. (CVE-2008-3640)\n\nIt was discovered that the HP-GL filter in CUPS did not properly check\nfor invalid pen parameters. If a user or automated system were tricked\ninto opening a crafted HP-GL or HP-GL/2 file, a remote attacker could\ncause a denial of service or execute arbitrary code with user\nprivileges. In Ubuntu 7.10 and 8.04 LTS, attackers would be isolated by\nthe AppArmor CUPS profile. (CVE-2008-3641)\n\nNOTE: The previous update for CUPS on Ubuntu 6.06 LTS did not have the\nthe fix for CVE-2008-1722 applied. This update includes fixes for the\nproblem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"cupsys","version":"1.3.2-1ubuntu7.8","description":"","is_source":true},{"name":"cupsys","version":"1.3.2-1ubuntu7.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.2-1ubuntu7.8"}],"dapper":[{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.11","description":"","is_source":true},{"name":"cupsys","version":"1.2.2-0ubuntu0.6.06.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.2-0ubuntu0.6.06.11"}],"feisty":[{"name":"cupsys","version":"1.2.8-0ubuntu8.6","description":"","is_source":true},{"name":"cupsys","version":"1.2.8-0ubuntu8.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.2.8-0ubuntu8.6"}],"hardy":[{"name":"cupsys","version":"1.3.7-1ubuntu3.1","description":"","is_source":true},{"name":"cupsys","version":"1.3.7-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cupsys","version_link":"https://launchpad.net/ubuntu/+source/cupsys/1.3.7-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2008-1722","CVE-2008-3639","CVE-2008-3640","CVE-2008-3641"]}]},{"id":"CVE-2008-3432","published":"2008-10-10T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the mch_expand_wildcards function in\nos_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute\narbitrary code via shell metacharacters in filenames, as demonstrated by\nthe netrw.v3 test case.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3432"],"bugs":[""],"patches":{"vim":[]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4514","published":"2008-10-09T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a\ndenial of service (application crash) via a font tag with a long color\nvalue, which triggers an assertion error.","ubuntu_description":"","notes":[{"author":"kees","note":"not considered a security issue: browser crash-only."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4514"],"bugs":[""],"patches":{"kdebase":[]},"tags":{},"packages":[{"name":"kdebase","source":"https://ubuntu.com/security/cve?package=kdebase","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kdebase","debian":"https://tracker.debian.org/pkg/kdebase","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":74920,"limit":20,"total_results":79316}