{"cves":[{"id":"CVE-2008-4503","published":"2008-10-09T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows\nremote attackers to cause victims to unknowingly click on a link or dialog\nvia access control dialogs disguised as normal graphical elements, as\ndemonstrated by hijacking the camera or microphone, and related to\n\"clickjacking.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4503"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.0.246.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"10.0.12.36ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"10.0.12.36ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"10.0.12.36ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.12.36","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4482","published":"2008-10-08T02:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe XML parser in Xerces-C++ before 3.0.0 allows context-dependent\nattackers to cause a denial of service (stack consumption and crash) via an\nXML schema definition with a large maxOccurs value, which triggers\nexcessive memory consumption during validation of an XML file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"debian is not fixing this, let's ignore it also"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4482"],"bugs":[""],"patches":{"xerces-c2":[]},"tags":{},"packages":[{"name":"xerces-c2","source":"https://ubuntu.com/security/cve?package=xerces-c2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xerces-c2","debian":"https://tracker.debian.org/pkg/xerces-c2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4477","published":"2008-10-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nalert.d/test.alert in mon 0.99.2 allows local users to overwrite arbitrary\nfiles via a symlink attack on the test.alert.log temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4477"],"bugs":[""],"patches":{"mon":["debdiff: http://launchpad.net/bugs/285100"]},"tags":{},"packages":[{"name":"mon","source":"https://ubuntu.com/security/cve?package=mon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mon","debian":"https://tracker.debian.org/pkg/mon","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.2-9ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.99.2-11ubuntu1.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.99.2-11ubuntu1.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.99.2-13","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4476","published":"2008-10-07T21:11:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via\na symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE:\nwwsympa.fcgi was also reported, but the issue occurred in a dead function,\nso it is not a vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4476"],"bugs":[""],"patches":{"sympa":[]},"tags":{},"packages":[{"name":"sympa","source":"https://ubuntu.com/security/cve?package=sympa","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sympa","debian":"https://tracker.debian.org/pkg/sympa","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.4-5.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4475","published":"2008-10-07T21:11:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nibackup 2.27 allows local users to overwrite arbitrary files via a symlink\nattack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4475"],"bugs":[""],"patches":{"ibackup":[]},"tags":{},"packages":[{"name":"ibackup","source":"https://ubuntu.com/security/cve?package=ibackup","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ibackup","debian":"https://tracker.debian.org/pkg/ibackup","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4474","published":"2008-10-07T21:11:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfreeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite\narbitrary files via a symlink attack on temporary files in (1)\nbackup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4) tot_stats,\nand (5) truncate_radacct.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"freeradius-dialupadmin is in universe"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4474"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496389"],"patches":{"freeradius":["vendor: http://patch-tracking.debian.net/patch/misc/dl/freeradius/2.0.4+dfsg-6/dialup_admin/bin/backup_radacct"]},"tags":{"freeradius":["universe-binary"]},"packages":[{"name":"freeradius","source":"https://ubuntu.com/security/cve?package=freeradius","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freeradius","debian":"https://tracker.debian.org/pkg/freeradius","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.1.0+dfsg-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.1.0+dfsg-0ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.1.0+dfsg-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.1.0+dfsg-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.1.0+dfsg-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.1.0+dfsg-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3834","published":"2008-10-07T21:01:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dbus_signature_validate function in the D-bus library (libdbus) before\n1.2.4 allows remote attackers to cause a denial of service (application\nabort) via a message containing a malformed signature, which triggers a\nfailed assertion error.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-653-1","https://www.cve.org/CVERecord?id=CVE-2008-3834"],"bugs":[""],"patches":{"dbus":[]},"tags":{},"packages":[{"name":"dbus","source":"https://ubuntu.com/security/cve?package=dbus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dbus","debian":"https://tracker.debian.org/pkg/dbus","statuses":[{"release_codename":"dapper","status":"released","description":"0.60-6ubuntu8.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.0.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.1-3ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.20-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-653-1"],"notices":[{"id":"USN-653-1","title":"D-Bus vulnerabilities","summary":"D-Bus vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-10-14T16:58:40.445391","description":"Havoc Pennington discovered that the D-Bus daemon did not correctly\nvalidate certain security policies. If a local user sent a specially\ncrafted D-Bus request, they could bypass security policies that had a\n\"send_interface\" defined. (CVE-2008-0595)\n\nIt was discovered that the D-Bus library did not correctly validate\ncertain corrupted signatures. If a local user sent a specially crafted\nD-Bus request, they could crash applications linked against the D-Bus\nlibrary, leading to a denial of service. (CVE-2008-3834)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"dbus","version":"1.1.1-3ubuntu4.2","description":"","is_source":true},{"name":"libdbus-1-3","version":"1.1.1-3ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.1.1-3ubuntu4.2"}],"dapper":[{"name":"dbus","version":"0.60-6ubuntu8.3","description":"","is_source":true},{"name":"libdbus-1-2","version":"0.60-6ubuntu8.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/0.60-6ubuntu8.3"}],"feisty":[{"name":"dbus","version":"1.0.2-1ubuntu4.2","description":"","is_source":true},{"name":"libdbus-1-3","version":"1.0.2-1ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.0.2-1ubuntu4.2"}],"hardy":[{"name":"dbus","version":"1.1.20-1ubuntu3.1","description":"","is_source":true},{"name":"libdbus-1-3","version":"1.1.20-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.1.20-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2008-0595","CVE-2008-3834"]}]},{"id":"CVE-2008-4445","published":"2008-10-06T19:54:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream\nControl Transmission Protocol (sctp) implementation in the Linux kernel\nbefore 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify\nthat the identifier index is within the bounds established by\nSCTP_AUTH_HMAC_ID_MAX, which allows local users to obtain sensitive\ninformation via a crafted SCTP_HMAC_IDENT IOCTL request involving the\nsctp_getsockopt function, a different vulnerability than CVE-2008-4113.","ubuntu_description":"","notes":[{"author":"kees","note":"The linked patch fixes this and CVE-2008-4113"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-659-1","https://www.cve.org/CVERecord?id=CVE-2008-4445"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-21.43","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-659-1"],"notices":[{"id":"USN-659-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: For systems without the hardy-updates pocket enabled, the 8.04\nkernel update will include an unavoidable ABI change. The kernel update\nhas been given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2008-10-27T20:22:50.932571","description":"It was discovered that the direct-IO subsystem did not correctly validate\ncertain structures. A local attacker could exploit this to cause a system\ncrash, leading to a denial of service. (CVE-2007-6716)\n\nIt was discovered that the disabling of the ZERO_PAGE optimization could\nlead to large memory consumption. A local attacker could exploit this to\nallocate all available memory, leading to a denial of service.\n(CVE-2008-2372)\n\nIt was discovered that the Datagram Congestion Control Protocol (DCCP) did\nnot correctly validate its arguments. If DCCP was in use, a remote attacker\ncould send specially crafted network traffic and cause a system crash,\nleading to a denial of service. (CVE-2008-3276)\n\nIt was discovered that the SBNI WAN driver did not correctly check for the\nNET_ADMIN capability. A malicious local root user lacking CAP_NET_ADMIN\nwould be able to change the WAN device configuration, leading to a denial\nof service. (CVE-2008-3525)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP) did\nnot correctly validate the key length in the SCTP_AUTH_KEY option. If SCTP\nis in use, a remote attacker could send specially crafted network traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2008-3526)\n\nIt was discovered that the tmpfs implementation did not correctly handle\ncertain sequences of inode operations. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-3534)\n\nIt was discovered that the readv/writev functions did not correctly handle\ncertain sequences of file operations. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-3535)\n\nIt was discovered that SCTP did not correctly validate its userspace\narguments. A local attacker could call certain sctp_* functions with\nmalicious options and cause a system crash, leading to a denial of service.\n(CVE-2008-3792, CVE-2008-4113, CVE-2008-4445)\n\nIt was discovered the the i915 video driver did not correctly validate\nmemory addresses. A local attacker could exploit this to remap memory\nthat could cause a system crash, leading to a denial of service.\n(CVE-2008-3831)\n\nJohann Dahm and David Richter discovered that NFSv4 did not correctly\nhandle certain file ACLs. If NFSv4 is in use, a local attacker could create\na malicious ACL that could cause a system crash, leading to a denial of\nservice. (CVE-2008-3915)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-15.59","description":"","is_source":true},{"name":"linux-image-2.6.22-15-mckinley","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-generic","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-hppa32","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-xen","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-sparc64-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-itanium","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-lpiacompat","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-386","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-lpia","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-sparc64","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-rt","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-virtual","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-server","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc64-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-hppa64","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-cell","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-ume","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-52.73","description":"","is_source":true},{"name":"linux-image-2.6.15-52-386","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-mckinley","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-server","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa32","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-k7","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-686","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-k8","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-server-bigiron","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-sparc64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-itanium","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-server","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa32-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-xeon","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-mckinley-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa64","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-generic","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-itanium-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-sparc64","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"}],"hardy":[{"name":"linux","version":"2.6.24-21.43","description":"","is_source":true},{"name":"linux-image-2.6.24-21-powerpc","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-powerpc64-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-sparc64","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-server","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-openvz","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-itanium","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-lpiacompat","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-386","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-generic","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-lpia","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-xen","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-hppa64","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-powerpc-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-mckinley","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-hppa32","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-rt","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-virtual","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-sparc64-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"}]},"type":"USN","cves_ids":["CVE-2007-6716","CVE-2008-2372","CVE-2008-3276","CVE-2008-3525","CVE-2008-3526","CVE-2008-3534","CVE-2008-3535","CVE-2008-3792","CVE-2008-3831","CVE-2008-3915","CVE-2008-4113","CVE-2008-4445"]}]},{"id":"CVE-2008-4279","published":"2008-10-06T19:54:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe CPU hardware emulation for 64-bit guest operating systems in VMware\nWorkstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build\n108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server\n1.x before 1.0.7 build 108231; and ESX 2.5.4 through 3.5 allows\nauthenticated guest OS users to gain additional guest OS privileges by\ntriggering an exception that causes the virtual CPU to perform an indirect\njump to a non-canonical address.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4279"],"bugs":[""],"patches":{"vmware-player":[],"vmware-server":[]},"tags":{},"packages":[{"name":"vmware-player","source":"https://ubuntu.com/security/cve?package=vmware-player","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vmware-player","debian":"https://tracker.debian.org/pkg/vmware-player","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.5","component":null,"pocket":"security"}]},{"name":"vmware-server","source":"https://ubuntu.com/security/cve?package=vmware-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vmware-server","debian":"https://tracker.debian.org/pkg/vmware-server","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3872","published":"2008-10-06T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows\nremote attackers to bypass the allowScriptAccess parameter setting via a\ncrafted SWF file with unspecified \"Filter evasion\" manipulations.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3872"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.116","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4456","published":"2008-10-06T00:00:00","updated_at":"2025-05-26T12:47:06.895653+00:00","description":"\nCross-site scripting (XSS) vulnerability in the command-line client in\nMySQL 5.0.26 through 5.0.45, and other versions including versions later\nthan 5.0.45, when the --html option is enabled, allows attackers to inject\narbitrary web script or HTML by placing it in a database cell, which might\nbe accessed by this client when composing an HTML document. NOTE: as of\n20081031, the issue has not been fixed in MySQL 5.0.67.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"PoC: http://seclists.org/bugtraq/2008/Oct/0059.html\nfixed in 5.0.89 and 5.1.42"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.henlich.de/it-security/mysql-command-line-client-html-injection-vulnerability/","https://ubuntu.com/security/notices/USN-897-1","https://www.cve.org/CVERecord?id=CVE-2008-4456","https://ubuntu.com/security/notices/USN-1397-1"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-4456","http://bugs.mysql.com/bug.php?id=27884","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526254"],"patches":{"mysql-dfsg-5.0":["vendor: http://patch-tracker.debian.org/patch/series/view/mysql-dfsg-5.0/5.0.51a-24+lenny2/94_SECURITY_CVE-2008-4456.dpatch","upstream: http://lists.mysql.com/commits/91358","upstream: http://lists.mysql.com/commits/91917"],"mysql-dfsg-5.1":["upstream: http://lists.mysql.com/commits/72932"]},"tags":{"mysql-dfsg-5.0_hardy":["apparmor"],"mysql-dfsg-5.0_intrepid":["apparmor"],"mysql-dfsg-5.0_jaunty":["apparmor"],"mysql-dfsg-5.1_karmic":["apparmor"]},"packages":[{"name":"mysql-5.1","source":"https://ubuntu.com/security/cve?package=mysql-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.1","debian":"https://tracker.debian.org/pkg/mysql-5.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"5.1.41-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"5.1.41-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"dapper","status":"released","description":"5.0.22-0ubuntu6.06.12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.0.51a-3ubuntu5.5","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.0.67-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.1.30really5.0.75-0ubuntu10.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.1.37-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"5.1.41-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-897-1","USN-1397-1"],"notices":[{"id":"USN-897-1","title":"MySQL vulnerabilities","summary":"MySQL vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-02-10T14:56:22.337606","description":"It was discovered that MySQL could be made to overwrite existing table\nfiles in the data directory. An authenticated user could use the DATA\nDIRECTORY and INDEX DIRECTORY options to possibly bypass privilege checks.\nThis update alters table creation behaviour by disallowing the use of the\nMySQL data directory in DATA DIRECTORY and INDEX DIRECTORY options. This\nissue only affected Ubuntu 8.10. (CVE-2008-4098) \n\nIt was discovered that MySQL contained a cross-site scripting vulnerability\nin the command-line client when the --html option is enabled. An attacker\ncould place arbitrary web script or html in a database cell, which would\nthen get placed in the html document output by the command-line tool. This\nissue only affected Ubuntu 6.06 LTS, 8.04 LTS, 8.10 and 9.04.\n(CVE-2008-4456)\n\nIt was discovered that MySQL could be made to overwrite existing table\nfiles in the data directory. An authenticated user could use symlinks\ncombined with the DATA DIRECTORY and INDEX DIRECTORY options to possibly\nbypass privilege checks. This issue only affected Ubuntu 9.10.\n(CVE-2008-7247)\n\nIt was discovered that MySQL contained multiple format string flaws when\nlogging database creation and deletion. An authenticated user could use\nspecially crafted database names to make MySQL crash, causing a denial of\nservice. This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 8.10 and 9.04.\n(CVE-2009-2446)\n\nIt was discovered that MySQL incorrectly handled errors when performing\ncertain SELECT statements, and did not preserve correct flags when\nperforming statements that use the GeomFromWKB function. An authenticated\nuser could exploit this to make MySQL crash, causing a denial of service.\n(CVE-2009-4019)\n\nIt was discovered that MySQL incorrectly checked symlinks when using the\nDATA DIRECTORY and INDEX DIRECTORY options. A local user could use symlinks\nto create tables that pointed to tables known to be created at a later\ntime, bypassing access restrictions. (CVE-2009-4030)\n\nIt was discovered that MySQL contained a buffer overflow when parsing\nssl certificates. A remote attacker could send crafted requests and cause a\ndenial of service or possibly execute arbitrary code. This issue did not\naffect Ubuntu 6.06 LTS and the default compiler options for affected\nreleases should reduce the vulnerability to a denial of service. In the\ndefault installation, attackers would also be isolated by the AppArmor\nMySQL profile. (CVE-2009-4484)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"mysql-dfsg-5.0","version":"5.0.51a-3ubuntu5.5","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.0.51a-3ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.51a-3ubuntu5.5"}],"dapper":[{"name":"mysql-dfsg-5.0","version":"5.0.22-0ubuntu6.06.12","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.0.22-0ubuntu6.06.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.22-0ubuntu6.06.12"}],"intrepid":[{"name":"mysql-dfsg-5.0","version":"5.0.67-0ubuntu6.1","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.0.67-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.67-0ubuntu6.1"}],"jaunty":[{"name":"mysql-dfsg-5.0","version":"5.1.30really5.0.75-0ubuntu10.3","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.1.30really5.0.75-0ubuntu10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.1.30really5.0.75-0ubuntu10.3"}],"karmic":[{"name":"mysql-dfsg-5.1","version":"5.1.37-1ubuntu5.1","description":"","is_source":true},{"name":"mysql-server-5.1","version":"5.1.37-1ubuntu5.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.37-1ubuntu5.1"}]},"type":"USN","cves_ids":["CVE-2008-7247","CVE-2009-4019","CVE-2009-4030","CVE-2009-4484","CVE-2008-4456","CVE-2008-4098","CVE-2009-2446"]},{"id":"USN-1397-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-03-12T14:37:53.714964","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10,\nUbuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to\nMySQL 5.0.95.\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\n\nhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-x.html\nhttp://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html\n","is_hidden":false,"release_packages":{"hardy":[{"name":"mysql-dfsg-5.0","version":"5.0.95-0ubuntu1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.0","version":"5.0.95-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.95-0ubuntu1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.61-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.61-0ubuntu0.10.04.1"}],"maverick":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.10.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.10.10.1"}],"natty":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.04.1"}],"oneiric":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2007-5925","CVE-2008-3963","CVE-2008-4098","CVE-2008-4456","CVE-2008-7247","CVE-2009-2446","CVE-2009-4019","CVE-2009-4030","CVE-2009-4484","CVE-2010-1621","CVE-2010-1626","CVE-2010-1848","CVE-2010-1849","CVE-2010-1850","CVE-2010-2008","CVE-2010-3677","CVE-2010-3678","CVE-2010-3679","CVE-2010-3680","CVE-2010-3681","CVE-2010-3682","CVE-2010-3683","CVE-2010-3833","CVE-2010-3834","CVE-2010-3835","CVE-2010-3836","CVE-2010-3837","CVE-2010-3838","CVE-2010-3839","CVE-2010-3840","CVE-2011-2262","CVE-2012-0075","CVE-2012-0087","CVE-2012-0101","CVE-2012-0102","CVE-2012-0112","CVE-2012-0113","CVE-2012-0114","CVE-2012-0115","CVE-2012-0116","CVE-2012-0117","CVE-2012-0118","CVE-2012-0119","CVE-2012-0120","CVE-2012-0484","CVE-2012-0485","CVE-2012-0486","CVE-2012-0487","CVE-2012-0488","CVE-2012-0489","CVE-2012-0490","CVE-2012-0491","CVE-2012-0492","CVE-2012-0493","CVE-2012-0494","CVE-2012-0495","CVE-2012-0496"]}]},{"id":"CVE-2008-4440","published":"2008-10-03T22:22:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe to-upgrade plugin in feta 1.4.16 allows local users to overwrite\narbitrary files via a symlink on the (1) /tmp/feta.install.$USER and (2)\n/tmp/feta.avail.$USER temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4440"],"bugs":[""],"patches":{"feta":[]},"tags":{},"packages":[{"name":"feta","source":"https://ubuntu.com/security/cve?package=feta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=feta","debian":"https://tracker.debian.org/pkg/feta","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4437","published":"2008-10-03T22:22:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in importxml.pl in Bugzilla before\n2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote\nattackers to read arbitrary files via an XML file with a .. (dot dot) in\nthe data element.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per stefanlsd, Dapper not affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4437"],"bugs":[""],"patches":{"bugzilla":["other: https://bugzilla.mozilla.org/show_bug.cgi?id=437169","debdiff: http://launchpad.net/bugs/281915"]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.22.1-2.2ubuntu1.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.22.1-2.2ubuntu1.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.4.1-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4410","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe vmi_write_ldt_entry function in arch/x86/kernel/vmi_32.c in the Virtual\nMachine Interface (VMI) in the Linux kernel 2.6.26.5 invokes\nwrite_idt_entry where write_ldt_entry was intended, which allows local\nusers to cause a denial of service (persistent application failure) via\ncrafted function calls, related to the Java Runtime Environment (JRE)\nexperiencing improper LDT selector state, a different vulnerability than\nCVE-2008-3247.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4410"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4409","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibxml2 2.7.0 and 2.7.1 does not properly handle \"predefined entities\ndefinitions\" in entities, which allows context-dependent attackers to cause\na denial of service (memory consumption and application crash), as\ndemonstrated by use of xmllint on a certain XML document, a different\nvulnerability than CVE-2003-1564 and CVE-2008-3281.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4409"],"bugs":[""],"patches":{"libxml2":[]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4408","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0, and\npossibly other versions before 1.13.2 allows remote attackers to inject\narbitrary web script or HTML via the useskin parameter to an unspecified\ncomponent.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per laney, Dapper and Gutsy have different code"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4408"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/mediawiki/+bug/290015"],"patches":{"mediawiki":["debdiff: https://bugs.launchpad.net/ubuntu/+source/mediawiki/+bug/290015"]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:1.11.2-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:1.12.0-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.13.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4407","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nXRunSabre in sabre (aka xsabre) 0.2.4b relies on the ability to create\n/tmp/sabre.log, which allows local users to cause a denial of service\n(application unavailability) by creating a /tmp/sabre.log file that cannot\nbe overwritten.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4407"],"bugs":[""],"patches":{"sabre":["debdiff: http://launchpad.net/bugs/283446"]},"tags":{},"packages":[{"name":"sabre","source":"https://ubuntu.com/security/cve?package=sabre","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sabre","debian":"https://tracker.debian.org/pkg/sabre","statuses":[{"release_codename":"dapper","status":"released","description":"0.2.4b-21ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.2.4b-23ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.2.4b-23ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"0.2.4b-25","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2.4b-25","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4406","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nA certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b\nallows local users to delete or overwrite arbitrary files via a symlink\nattack on unspecified .tmp files.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4406"],"bugs":[""],"patches":{"sabre":["debdiff: http://launchpad.net/bugs/283446"]},"tags":{},"packages":[{"name":"sabre","source":"https://ubuntu.com/security/cve?package=sabre","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sabre","debian":"https://tracker.debian.org/pkg/sabre","statuses":[{"release_codename":"dapper","status":"released","description":"0.2.4b-21ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.2.4b-23ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.2.4b-23ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"0.2.4b-25","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2.4b-25","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4405","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nxend in Xen 3.0.3 does not properly limit the contents of the /local/domain\nxenstore directory tree, and does not properly restrict a guest VM's write\naccess within this tree, which allows guest OS users to cause a denial of\nservice and possibly have unspecified other impact by writing to (1)\nconsole/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this\nissue was originally reported as an issue in libvirt 0.3.3 and xenstore,\nbut CVE is considering the core issue to be related to Xen.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per berrange@redhat.com on oss-security, this is a Xen issue, and\nlibvirt, while affected, is fixed via the Xen patches"},{"author":"kees","note":"this only affects xen-utils-3.X, which is in universe"},{"author":"jdstrand","note":"original patch for CVE-2008-4405 introduced CVE-2008-5716"},{"author":"mdeslaur","note":"xen-xenstore-permissions.patch in RHEL5"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5716","https://www.cve.org/CVERecord?id=CVE-2008-4405"],"bugs":[""],"patches":{"xen-3.0":[],"xen-3.1":["upstream: http://xenbits.xensource.com/staging/xen-3.3-testing.hg?rev/e0e17216ba70"],"xen-3.2":["upstream: http://xenbits.xensource.com/staging/xen-3.3-testing.hg?rev/e0e17216ba70"],"xen-3.3":["upstream: http://xenbits.xensource.com/staging/xen-3.3-testing.hg?rev/e0e17216ba70"],"xen":[]},"tags":{"xen-3.1":["universe-binary"],"xen-3.2":["universe-binary"],"xen-3.3":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.0","source":"https://ubuntu.com/security/cve?package=xen-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.0","debian":"https://tracker.debian.org/pkg/xen-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.1","source":"https://ubuntu.com/security/cve?package=xen-3.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.1","debian":"https://tracker.debian.org/pkg/xen-3.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.2","source":"https://ubuntu.com/security/cve?package=xen-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.2","debian":"https://tracker.debian.org/pkg/xen-3.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.3","source":"https://ubuntu.com/security/cve?package=xen-3.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.3","debian":"https://tracker.debian.org/pkg/xen-3.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4360","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmod_userdir in lighttpd before 1.4.20, when a case-insensitive operating\nsystem or filesystem is used, performs case-sensitive comparisons on\nfilename components in configuration options, which might allow remote\nattackers to bypass intended access restrictions, as demonstrated by a\nrequest for a .PHP file when there is a configuration rule for .php files.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4360"],"bugs":["https://bugs.launchpad.net/ubuntu/jaunty/+source/lighttpd/+bug/279490"],"patches":{"lighttpd":["debdiff: https://bugs.launchpad.net/ubuntu/jaunty/+source/lighttpd/+bug/279490"]},"tags":{},"packages":[{"name":"lighttpd","source":"https://ubuntu.com/security/cve?package=lighttpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lighttpd","debian":"https://tracker.debian.org/pkg/lighttpd","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.4.19-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.4.19-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.4.19-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.4.19-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.19-5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":74940,"limit":20,"total_results":79316}