{"cves":[{"id":"CVE-2008-4359","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect\nand (2) url.rewrite configuration settings before performing URL decoding,\nwhich might allow remote attackers to bypass intended access restrictions,\nand obtain sensitive information or possibly modify data.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"according to http://redmine.lighttpd.net/issues/show/1720, the\nupstream patch has been reverted due to too many regressions. As such,\nfuture versions will need to be checked to ensure it is fixed"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4359"],"bugs":["https://bugs.launchpad.net/ubuntu/jaunty/+source/lighttpd/+bug/279490"],"patches":{"lighttpd":["debdiff: https://bugs.launchpad.net/ubuntu/jaunty/+source/lighttpd/+bug/279490"]},"tags":{},"packages":[{"name":"lighttpd","source":"https://ubuntu.com/security/cve?package=lighttpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lighttpd","debian":"https://tracker.debian.org/pkg/lighttpd","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.4.19-5ubuntu6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.4.19-5ubuntu6","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.4.19-5ubuntu6","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.4.19-5ubuntu6","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.4.19-5ubuntu6","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.4.19-5ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.19-5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3833","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe generic_file_splice_write function in fs/splice.c in the Linux kernel\nbefore 2.6.19 does not properly strip setuid and setgid bits when there is\na write to a file, which allows local users to gain the privileges of a\ndifferent group, and obtain sensitive information or possibly have\nunspecified other impact, by splicing into an inode in order to create an\nexecutable file in a setgid directory, a different vulnerability than\nCVE-2008-4210.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3833"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3832","published":"2008-10-03T17:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nA certain Fedora patch for the utrace subsystem in the Linux kernel before\n2.6.26.5-28 on Fedora 8, and before 2.6.26.5-45 on Fedora 9, allows local\nusers to cause a denial of service (NULL pointer dereference and system\ncrash or hang) via a call to the utrace_control function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3832"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3825","published":"2008-10-03T15:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the\nexisting_ticket option is enabled, uses incorrect privileges when reading a\nKerberos credential cache, which allows local users to gain privileges by\nsetting the KRB5CCNAME environment variable to an arbitrary cache filename\nand running the (1) su or (2) sudo program. NOTE: there may be a related\nvector involving sshd that has limited relevance.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3825"],"bugs":[""],"patches":{"libpam-krb5":[]},"tags":{},"packages":[{"name":"libpam-krb5","source":"https://ubuntu.com/security/cve?package=libpam-krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpam-krb5","debian":"https://tracker.debian.org/pkg/libpam-krb5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2236","published":"2008-10-03T15:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in blosxom.cgi in Blosxom before\n2.1.2 allows remote attackers to inject arbitrary web script or HTML via\nthe flav parameter (flavour variable). NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2236"],"bugs":[""],"patches":{"blosxom":[]},"tags":{},"packages":[{"name":"blosxom","source":"https://ubuntu.com/security/cve?package=blosxom","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=blosxom","debian":"https://tracker.debian.org/pkg/blosxom","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.1.2-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.1.2-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.1.2-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.1.2-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.1.2-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.1.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4382","published":"2008-10-02T18:18:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nKonqueror in KDE 3.5.9 allows remote attackers to cause a denial of service\n(application crash) via Javascript that calls the alert function with a\nURL-encoded string of a large number of invalid characters.","ubuntu_description":"","notes":[{"author":"kees","note":"Browser DoS is not strictly a security issue."},{"author":"mdeslaur","note":"as of 2009-08-21, no details, no fix\nbrowser DoS, no security issue, ignoring."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4382"],"bugs":[""],"patches":{"kdebase":[]},"tags":{},"packages":[{"name":"kdebase","source":"https://ubuntu.com/security/cve?package=kdebase","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdebase","debian":"https://tracker.debian.org/pkg/kdebase","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3522","published":"2008-10-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the jas_stream_printf function in\nlibjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent\nattackers to have an unknown impact via vectors related to the mif_hdr_put\nfunction and use of vsprintf.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-742-1","https://ubuntu.com/security/notices/USN-1317-1","https://www.cve.org/CVERecord?id=CVE-2008-3522"],"bugs":["http://bugs.gentoo.org/show_bug.cgi?id=222819","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-3522","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501021"],"patches":{"jasper":["vendor: https://bugzilla.redhat.com/attachment.cgi?id=316079","vendor: http://patch-tracking.debian.net/patch/series/view/jasper/1.900.1-5.1/02_security.dpatch"],"ghostscript":[]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"hardy","status":"released","description":"8.61.dfsg.1-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.71.dfsg.1-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.71.dfsg.2-0ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"uses system jasper","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"uses system jasper","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"dapper","status":"released","description":"1.701.0-2ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.900.1-3ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.900.1-3ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.900.1-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.900.1-5.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-742-1","USN-1317-1"],"notices":[{"id":"USN-742-1","title":"JasPer vulnerabilities","summary":"JasPer vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-03-19T17:09:50.144253","description":"It was discovered that JasPer did not correctly handle memory allocation\nwhen parsing certain malformed JPEG2000 images. If a user were tricked into\nopening a specially crafted image with an application that uses libjasper,\nan attacker could cause a denial of service and possibly execute arbitrary\ncode with the user's privileges. (CVE-2008-3520)\n\nIt was discovered that JasPer created temporary files in an insecure way.\nLocal users could exploit a race condition and cause a denial of service in\nlibjasper applications.\n(CVE-2008-3521)\n\nIt was discovered that JasPer did not correctly handle certain formatting\noperations. If a user were tricked into opening a specially crafted image\nwith an application that uses libjasper, an attacker could cause a denial\nof service and possibly execute arbitrary code with the user's privileges.\n(CVE-2008-3522)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"jasper","version":"1.900.1-3ubuntu0.7.10.1","description":"","is_source":true},{"name":"libjasper1","version":"1.900.1-3ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-3ubuntu0.7.10.1"}],"dapper":[{"name":"jasper","version":"1.701.0-2ubuntu0.6.06.1","description":"","is_source":true},{"name":"libjasper-1.701-1","version":"1.701.0-2ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.701.0-2ubuntu0.6.06.1"}],"intrepid":[{"name":"jasper","version":"1.900.1-5ubuntu0.1","description":"","is_source":true},{"name":"libjasper1","version":"1.900.1-5ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-5ubuntu0.1"}],"hardy":[{"name":"jasper","version":"1.900.1-3ubuntu0.8.04.1","description":"","is_source":true},{"name":"libjasper1","version":"1.900.1-3ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-3ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-3520","CVE-2008-3521","CVE-2008-3522"]},{"id":"USN-1317-1","title":"Ghostscript vulnerabilities","summary":"Ghostscript could be made to crash or run programs as your login if it\nopened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-01-04T14:29:33.662972","description":"It was discovered that Ghostscript did not correctly handle memory\nallocation when parsing certain malformed JPEG-2000 images. If a user or\nautomated system were tricked into opening a specially crafted image, an\nattacker could cause a denial of service and possibly execute arbitrary\ncode with user privileges. (CVE-2008-3520)\n\nIt was discovered that Ghostscript did not correctly handle certain\nformatting operations when parsing JPEG-2000 images. If a user or automated\nsystem were tricked into opening a specially crafted image, an attacker\ncould cause a denial of service and possibly execute arbitrary code with\nuser privileges. (CVE-2008-3522)\n\nIt was discovered that Ghostscript incorrectly handled certain malformed\nTrueType fonts. If a user or automated system were tricked into opening a\ndocument containing a specially crafted font, an attacker could cause a\ndenial of service and possibly execute arbitrary code with user privileges.\nThis issue only affected Ubuntu 8.04 LTS. (CVE-2009-3743)\n\nIt was discovered that Ghostscript incorrectly handled certain malformed\nType 2 fonts. If a user or automated system were tricked into opening a\ndocument containing a specially crafted font, an attacker could cause a\ndenial of service and possibly execute arbitrary code with user privileges.\nThis issue only affected Ubuntu 8.04 LTS. (CVE-2010-4054)\n\nJonathan Foote discovered that Ghostscript incorrectly handled certain\nmalformed JPEG-2000 image files. If a user or automated system were tricked\ninto opening a specially crafted JPEG-2000 image file, an attacker could\ncause Ghostscript to crash or possibly execute arbitrary code with user\nprivileges. (CVE-2011-4516, CVE-2011-4517)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"ghostscript","version":"8.61.dfsg.1-1ubuntu3.4","description":"The GPL Ghostscript PostScript/PDF interpreter","is_source":true},{"name":"libgs8","version":"8.61.dfsg.1-1ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.61.dfsg.1-1ubuntu3.4"}],"lucid":[{"name":"ghostscript","version":"8.71.dfsg.1-0ubuntu5.4","description":"The GPL Ghostscript PostScript/PDF interpreter","is_source":true},{"name":"libgs8","version":"8.71.dfsg.1-0ubuntu5.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.71.dfsg.1-0ubuntu5.4"}],"maverick":[{"name":"ghostscript","version":"8.71.dfsg.2-0ubuntu7.1","description":"The GPL Ghostscript PostScript/PDF interpreter","is_source":true},{"name":"libgs8","version":"8.71.dfsg.2-0ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.71.dfsg.2-0ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2008-3520","CVE-2008-3522","CVE-2009-3743","CVE-2010-4054","CVE-2011-4516","CVE-2011-4517"]}]},{"id":"CVE-2008-3521","published":"2008-10-02T00:00:00","updated_at":"2025-08-04T19:23:19.328030+00:00","description":"\nRace condition in the jas_stream_tmpfile function in\nlibjasper/base/jas_stream.c in JasPer 1.900.1 allows local users to cause a\ndenial of service (program exit) by creating the appropriate tmp.XXXXXXXXXX\ntemporary file, which causes Jasper to exit. NOTE: this was originally\nreported as a symlink issue, but this was incorrect. NOTE: some vendors\ndispute the severity of this issue, but it satisfies CVE's requirements for\ninclusion.","ubuntu_description":"","notes":[{"author":"kees","note":"opened with O_EXCL"},{"author":"mdeslaur","note":"ghostscript jasper already uses appropriate temp filename"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-742-1","https://www.cve.org/CVERecord?id=CVE-2008-3521"],"bugs":["http://bugs.gentoo.org/show_bug.cgi?id=222819","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-3521","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501021"],"patches":{"jasper":["vendor: http://patch-tracking.debian.net/patch/series/view/jasper/1.900.1-5.1/02_security.dpatch"],"ghostscript":[]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"uses system jasper","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"uses system jasper","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"dapper","status":"released","description":"1.701.0-2ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.900.1-3ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.900.1-3ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.900.1-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.900.1-5.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-742-1"],"notices":[{"id":"USN-742-1","title":"JasPer vulnerabilities","summary":"JasPer vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-03-19T17:09:50.144253","description":"It was discovered that JasPer did not correctly handle memory allocation\nwhen parsing certain malformed JPEG2000 images. If a user were tricked into\nopening a specially crafted image with an application that uses libjasper,\nan attacker could cause a denial of service and possibly execute arbitrary\ncode with the user's privileges. (CVE-2008-3520)\n\nIt was discovered that JasPer created temporary files in an insecure way.\nLocal users could exploit a race condition and cause a denial of service in\nlibjasper applications.\n(CVE-2008-3521)\n\nIt was discovered that JasPer did not correctly handle certain formatting\noperations. If a user were tricked into opening a specially crafted image\nwith an application that uses libjasper, an attacker could cause a denial\nof service and possibly execute arbitrary code with the user's privileges.\n(CVE-2008-3522)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"jasper","version":"1.900.1-3ubuntu0.7.10.1","description":"","is_source":true},{"name":"libjasper1","version":"1.900.1-3ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-3ubuntu0.7.10.1"}],"dapper":[{"name":"jasper","version":"1.701.0-2ubuntu0.6.06.1","description":"","is_source":true},{"name":"libjasper-1.701-1","version":"1.701.0-2ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.701.0-2ubuntu0.6.06.1"}],"intrepid":[{"name":"jasper","version":"1.900.1-5ubuntu0.1","description":"","is_source":true},{"name":"libjasper1","version":"1.900.1-5ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-5ubuntu0.1"}],"hardy":[{"name":"jasper","version":"1.900.1-3ubuntu0.8.04.1","description":"","is_source":true},{"name":"libjasper1","version":"1.900.1-3ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-3ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-3520","CVE-2008-3521","CVE-2008-3522"]}]},{"id":"CVE-2008-3520","published":"2008-10-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in JasPer 1.900.1 might allow context-dependent\nattackers to have an unknown impact via a crafted image file, related to\ninteger multiplication for memory allocation.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"RH released netpbm with this CVE, as it shared code with jasper\nour netpbm-free doesn't appear to."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-742-1","https://ubuntu.com/security/notices/USN-1317-1","https://www.cve.org/CVERecord?id=CVE-2008-3520"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-3520","http://bugs.gentoo.org/show_bug.cgi?id=222819","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501021"],"patches":{"jasper":["vendor: https://bugzilla.redhat.com/attachment.cgi?id=325790","vendor: http://patch-tracking.debian.net/patch/series/view/jasper/1.900.1-5.1/02_security.dpatch"],"ghostscript":[]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"hardy","status":"released","description":"8.61.dfsg.1-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.71.dfsg.1-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.71.dfsg.2-0ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"uses system jasper","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"uses system jasper","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"dapper","status":"released","description":"1.701.0-2ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.900.1-3ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.900.1-3ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.900.1-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.900.1-5.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-742-1","USN-1317-1"],"notices":[{"id":"USN-742-1","title":"JasPer vulnerabilities","summary":"JasPer vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-03-19T17:09:50.144253","description":"It was discovered that JasPer did not correctly handle memory allocation\nwhen parsing certain malformed JPEG2000 images. If a user were tricked into\nopening a specially crafted image with an application that uses libjasper,\nan attacker could cause a denial of service and possibly execute arbitrary\ncode with the user's privileges. (CVE-2008-3520)\n\nIt was discovered that JasPer created temporary files in an insecure way.\nLocal users could exploit a race condition and cause a denial of service in\nlibjasper applications.\n(CVE-2008-3521)\n\nIt was discovered that JasPer did not correctly handle certain formatting\noperations. If a user were tricked into opening a specially crafted image\nwith an application that uses libjasper, an attacker could cause a denial\nof service and possibly execute arbitrary code with the user's privileges.\n(CVE-2008-3522)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"jasper","version":"1.900.1-3ubuntu0.7.10.1","description":"","is_source":true},{"name":"libjasper1","version":"1.900.1-3ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-3ubuntu0.7.10.1"}],"dapper":[{"name":"jasper","version":"1.701.0-2ubuntu0.6.06.1","description":"","is_source":true},{"name":"libjasper-1.701-1","version":"1.701.0-2ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.701.0-2ubuntu0.6.06.1"}],"intrepid":[{"name":"jasper","version":"1.900.1-5ubuntu0.1","description":"","is_source":true},{"name":"libjasper1","version":"1.900.1-5ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-5ubuntu0.1"}],"hardy":[{"name":"jasper","version":"1.900.1-3ubuntu0.8.04.1","description":"","is_source":true},{"name":"libjasper1","version":"1.900.1-3ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-3ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-3520","CVE-2008-3521","CVE-2008-3522"]},{"id":"USN-1317-1","title":"Ghostscript vulnerabilities","summary":"Ghostscript could be made to crash or run programs as your login if it\nopened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-01-04T14:29:33.662972","description":"It was discovered that Ghostscript did not correctly handle memory\nallocation when parsing certain malformed JPEG-2000 images. If a user or\nautomated system were tricked into opening a specially crafted image, an\nattacker could cause a denial of service and possibly execute arbitrary\ncode with user privileges. (CVE-2008-3520)\n\nIt was discovered that Ghostscript did not correctly handle certain\nformatting operations when parsing JPEG-2000 images. If a user or automated\nsystem were tricked into opening a specially crafted image, an attacker\ncould cause a denial of service and possibly execute arbitrary code with\nuser privileges. (CVE-2008-3522)\n\nIt was discovered that Ghostscript incorrectly handled certain malformed\nTrueType fonts. If a user or automated system were tricked into opening a\ndocument containing a specially crafted font, an attacker could cause a\ndenial of service and possibly execute arbitrary code with user privileges.\nThis issue only affected Ubuntu 8.04 LTS. (CVE-2009-3743)\n\nIt was discovered that Ghostscript incorrectly handled certain malformed\nType 2 fonts. If a user or automated system were tricked into opening a\ndocument containing a specially crafted font, an attacker could cause a\ndenial of service and possibly execute arbitrary code with user privileges.\nThis issue only affected Ubuntu 8.04 LTS. (CVE-2010-4054)\n\nJonathan Foote discovered that Ghostscript incorrectly handled certain\nmalformed JPEG-2000 image files. If a user or automated system were tricked\ninto opening a specially crafted JPEG-2000 image file, an attacker could\ncause Ghostscript to crash or possibly execute arbitrary code with user\nprivileges. (CVE-2011-4516, CVE-2011-4517)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"ghostscript","version":"8.61.dfsg.1-1ubuntu3.4","description":"The GPL Ghostscript PostScript/PDF interpreter","is_source":true},{"name":"libgs8","version":"8.61.dfsg.1-1ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.61.dfsg.1-1ubuntu3.4"}],"lucid":[{"name":"ghostscript","version":"8.71.dfsg.1-0ubuntu5.4","description":"The GPL Ghostscript PostScript/PDF interpreter","is_source":true},{"name":"libgs8","version":"8.71.dfsg.1-0ubuntu5.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.71.dfsg.1-0ubuntu5.4"}],"maverick":[{"name":"ghostscript","version":"8.71.dfsg.2-0ubuntu7.1","description":"The GPL Ghostscript PostScript/PDF interpreter","is_source":true},{"name":"libgs8","version":"8.71.dfsg.2-0ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.71.dfsg.2-0ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2008-3520","CVE-2008-3522","CVE-2009-3743","CVE-2010-4054","CVE-2011-4516","CVE-2011-4517"]}]},{"id":"CVE-2008-4094","published":"2008-09-30T17:22:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow\nremote attackers to execute arbitrary SQL commands via the (1) :limit and\n(2) :offset parameters, related to ActiveRecord, ActiveSupport,\nActiveResource, ActionPack, and ActionMailer.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-4094"],"bugs":[""],"patches":{"rails":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.1.0-6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.1.0-6","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.1.0-6","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.1.0-6","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.1.0-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.0-4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-4326","published":"2008-09-30T16:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe PMA_escapeJsString function in libraries/js_escape.lib.php in\nphpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote\nattackers to bypass cross-site scripting (XSS) protection mechanisms and\nconduct XSS attacks via a NUL byte inside a \"