{"cves":[{"id":"CVE-2008-3273","published":"2008-08-10T20:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nJBoss Enterprise Application Platform (aka JBossEAP or EAP) before\n4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain\nsensitive information about \"deployed web contexts\" via a request to the\nstatus servlet, as demonstrated by a full=true query string.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3273"],"bugs":[""],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3535","published":"2008-08-08T19:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the iov_iter_advance function in mm/filemap.c in the\nLinux kernel before 2.6.27-rc2 allows local users to cause a denial of\nservice (system crash) via a certain sequence of file I/O operations with\nreadv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from\nthe Linux Test Project.","ubuntu_description":"\nIt was discovered that the readv/writev functions did not correctly\nhandle certain sequences of file operations.  A local attacker could\nexploit this to crash the system, leading to a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-659-1","https://www.cve.org/CVERecord?id=CVE-2008-3535"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":["upstream: 94ad374a0751f40d25e22e036c37f7263569d24c"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-21.43","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-659-1"],"notices":[{"id":"USN-659-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: For systems without the hardy-updates pocket enabled, the 8.04\nkernel update will include an unavoidable ABI change. The kernel update\nhas been given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2008-10-27T20:22:50.932571","description":"It was discovered that the direct-IO subsystem did not correctly validate\ncertain structures. A local attacker could exploit this to cause a system\ncrash, leading to a denial of service. (CVE-2007-6716)\n\nIt was discovered that the disabling of the ZERO_PAGE optimization could\nlead to large memory consumption. A local attacker could exploit this to\nallocate all available memory, leading to a denial of service.\n(CVE-2008-2372)\n\nIt was discovered that the Datagram Congestion Control Protocol (DCCP) did\nnot correctly validate its arguments. If DCCP was in use, a remote attacker\ncould send specially crafted network traffic and cause a system crash,\nleading to a denial of service. (CVE-2008-3276)\n\nIt was discovered that the SBNI WAN driver did not correctly check for the\nNET_ADMIN capability. A malicious local root user lacking CAP_NET_ADMIN\nwould be able to change the WAN device configuration, leading to a denial\nof service. (CVE-2008-3525)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP) did\nnot correctly validate the key length in the SCTP_AUTH_KEY option. If SCTP\nis in use, a remote attacker could send specially crafted network traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2008-3526)\n\nIt was discovered that the tmpfs implementation did not correctly handle\ncertain sequences of inode operations. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-3534)\n\nIt was discovered that the readv/writev functions did not correctly handle\ncertain sequences of file operations. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-3535)\n\nIt was discovered that SCTP did not correctly validate its userspace\narguments. A local attacker could call certain sctp_* functions with\nmalicious options and cause a system crash, leading to a denial of service.\n(CVE-2008-3792, CVE-2008-4113, CVE-2008-4445)\n\nIt was discovered the the i915 video driver did not correctly validate\nmemory addresses.  A local attacker could exploit this to remap memory\nthat could cause a system crash, leading to a denial of service.\n(CVE-2008-3831)\n\nJohann Dahm and David Richter discovered that NFSv4 did not correctly\nhandle certain file ACLs. If NFSv4 is in use, a local attacker could create\na malicious ACL that could cause a system crash, leading to a denial of\nservice. (CVE-2008-3915)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-15.59","description":"","is_source":true},{"name":"linux-image-2.6.22-15-mckinley","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-generic","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-hppa32","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-xen","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-sparc64-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-itanium","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-lpiacompat","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-386","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-lpia","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-sparc64","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-rt","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-virtual","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-server","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc64-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-hppa64","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-cell","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-ume","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-52.73","description":"","is_source":true},{"name":"linux-image-2.6.15-52-386","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-mckinley","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-server","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa32","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-k7","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-686","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-k8","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-server-bigiron","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-sparc64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-itanium","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-server","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa32-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-xeon","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-mckinley-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa64","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-generic","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-itanium-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-sparc64","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"}],"hardy":[{"name":"linux","version":"2.6.24-21.43","description":"","is_source":true},{"name":"linux-image-2.6.24-21-powerpc","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-powerpc64-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-sparc64","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-server","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-openvz","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-itanium","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-lpiacompat","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-386","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-generic","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-lpia","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-xen","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-hppa64","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-powerpc-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-mckinley","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-hppa32","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-rt","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-virtual","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-sparc64-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"}]},"type":"USN","cves_ids":["CVE-2007-6716","CVE-2008-2372","CVE-2008-3276","CVE-2008-3525","CVE-2008-3526","CVE-2008-3534","CVE-2008-3535","CVE-2008-3792","CVE-2008-3831","CVE-2008-3915","CVE-2008-4113","CVE-2008-4445"]}]},{"id":"CVE-2008-3534","published":"2008-08-08T19:41:00","updated_at":"2026-07-04T07:31:43.599995+00:00","description":"\nThe shmem_delete_inode function in mm/shmem.c in the tmpfs implementation\nin the Linux kernel before 2.6.26.1 allows local users to cause a denial of\nservice (system crash) via a certain sequence of file create, remove, and\noverwrite operations, as demonstrated by the insserv program, related to\nallocation of \"useless pages\" and improper maintenance of the i_blocks\ncount.","ubuntu_description":"\nIt was discovered that the tmpfs implementation did not correctly handle\ncertain sequences of inode operations.  A local attacker could exploit\nthis to crash the system, leading to a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-659-1","https://www.cve.org/CVERecord?id=CVE-2008-3534"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":["break-fix: 14fcc23fdc78e9d32372553ccf21758a9bd56fa1 d847471d063663b9f36927d265c66a270c0cfaab"]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-21.43","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc4","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-52.73","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc4","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc4","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-15.59","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc4","component":null,"pocket":"security"}]}],"notices_ids":["USN-659-1"],"notices":[{"id":"USN-659-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: For systems without the hardy-updates pocket enabled, the 8.04\nkernel update will include an unavoidable ABI change. The kernel update\nhas been given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2008-10-27T20:22:50.932571","description":"It was discovered that the direct-IO subsystem did not correctly validate\ncertain structures. A local attacker could exploit this to cause a system\ncrash, leading to a denial of service. (CVE-2007-6716)\n\nIt was discovered that the disabling of the ZERO_PAGE optimization could\nlead to large memory consumption. A local attacker could exploit this to\nallocate all available memory, leading to a denial of service.\n(CVE-2008-2372)\n\nIt was discovered that the Datagram Congestion Control Protocol (DCCP) did\nnot correctly validate its arguments. If DCCP was in use, a remote attacker\ncould send specially crafted network traffic and cause a system crash,\nleading to a denial of service. (CVE-2008-3276)\n\nIt was discovered that the SBNI WAN driver did not correctly check for the\nNET_ADMIN capability. A malicious local root user lacking CAP_NET_ADMIN\nwould be able to change the WAN device configuration, leading to a denial\nof service. (CVE-2008-3525)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP) did\nnot correctly validate the key length in the SCTP_AUTH_KEY option. If SCTP\nis in use, a remote attacker could send specially crafted network traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2008-3526)\n\nIt was discovered that the tmpfs implementation did not correctly handle\ncertain sequences of inode operations. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-3534)\n\nIt was discovered that the readv/writev functions did not correctly handle\ncertain sequences of file operations. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-3535)\n\nIt was discovered that SCTP did not correctly validate its userspace\narguments. A local attacker could call certain sctp_* functions with\nmalicious options and cause a system crash, leading to a denial of service.\n(CVE-2008-3792, CVE-2008-4113, CVE-2008-4445)\n\nIt was discovered the the i915 video driver did not correctly validate\nmemory addresses.  A local attacker could exploit this to remap memory\nthat could cause a system crash, leading to a denial of service.\n(CVE-2008-3831)\n\nJohann Dahm and David Richter discovered that NFSv4 did not correctly\nhandle certain file ACLs. If NFSv4 is in use, a local attacker could create\na malicious ACL that could cause a system crash, leading to a denial of\nservice. (CVE-2008-3915)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-15.59","description":"","is_source":true},{"name":"linux-image-2.6.22-15-mckinley","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-generic","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-hppa32","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-xen","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-sparc64-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-itanium","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-lpiacompat","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-386","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-lpia","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-sparc64","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-rt","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-virtual","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-server","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-powerpc64-smp","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-hppa64","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-cell","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"},{"name":"linux-image-2.6.22-15-ume","version":"2.6.22-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.59"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-52.73","description":"","is_source":true},{"name":"linux-image-2.6.15-52-386","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-mckinley","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-server","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa32","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-k7","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-686","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-k8","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-server-bigiron","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-sparc64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-itanium","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-server","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa32-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-xeon","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-mckinley-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa64-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-hppa64","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-powerpc-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-amd64-generic","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-itanium-smp","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"},{"name":"linux-image-2.6.15-52-sparc64","version":"2.6.15-52.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.73"}],"hardy":[{"name":"linux","version":"2.6.24-21.43","description":"","is_source":true},{"name":"linux-image-2.6.24-21-powerpc","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-powerpc64-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-sparc64","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-server","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-openvz","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-itanium","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-lpiacompat","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-386","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-generic","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-lpia","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-xen","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-hppa64","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-powerpc-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-mckinley","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-hppa32","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-rt","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-virtual","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"},{"name":"linux-image-2.6.24-21-sparc64-smp","version":"2.6.24-21.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-21.43"}]},"type":"USN","cves_ids":["CVE-2007-6716","CVE-2008-2372","CVE-2008-3276","CVE-2008-3525","CVE-2008-3526","CVE-2008-3534","CVE-2008-3535","CVE-2008-3792","CVE-2008-3831","CVE-2008-3915","CVE-2008-4113","CVE-2008-4445"]}]},{"id":"CVE-2008-3532","published":"2008-08-08T19:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL\ncertificates, which makes it easier for remote attackers to trick a user\ninto accepting an invalid server certificate for a spoofed service.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"In dapper, nss is not compiled in"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-675-1","https://www.cve.org/CVERecord?id=CVE-2008-3532"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=492434","https://bugs.launchpad.net/bugs/251304"],"patches":{"pidgin":["other: http://developer.pidgin.im/ticket/6500","upstream: http://developer.pidgin.im/viewmtn/revision/info/ad677f4ab3dcd31d42fe39edbb9e9207dcf93df6","upstream: http://developer.pidgin.im/viewmtn/revision/info/3cbc74478c8df61d53804d0363dc936a3e0adeb7"],"gaim":[]},"tags":{},"packages":[{"name":"gaim","source":"https://ubuntu.com/security/cve?package=gaim","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gaim","debian":"https://tracker.debian.org/pkg/gaim","statuses":[{"release_codename":"dapper","status":"not-affected","description":"1:1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.3-2","component":null,"pocket":"security"}]},{"name":"pidgin","source":"https://ubuntu.com/security/cve?package=pidgin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pidgin","debian":"https://tracker.debian.org/pkg/pidgin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1:2.2.1-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:2.4.1-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1:2.5.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.3-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-675-1"],"notices":[{"id":"USN-675-1","title":"Pidgin vulnerabilities","summary":"Pidgin vulnerabilities","instructions":"After a standard system upgrade you need to restart Pidgin to effect\nthe necessary changes.\n","references":[],"published":"2008-11-24T16:50:48.474060","description":"It was discovered that Pidgin did not properly handle certain malformed\nmessages in the MSN protocol handler. A remote attacker could send a specially\ncrafted message and possibly execute arbitrary code with user privileges.\n(CVE-2008-2927)\n\nIt was discovered that Pidgin did not properly handle file transfers containing\na long filename and special characters in the MSN protocol handler. A remote\nattacker could send a specially crafted filename in a file transfer request\nand cause Pidgin to crash, leading to a denial of service. (CVE-2008-2955)\n\nIt was discovered that Pidgin did not impose resource limitations in the UPnP\nservice. A remote attacker could cause Pidgin to download arbitrary files \nand cause a denial of service from memory or disk space exhaustion.\n(CVE-2008-2957)\n\nIt was discovered that Pidgin did not validate SSL certificates when using a\nsecure connection. If a remote attacker were able to perform a\nmachine-in-the-middle attack, this flaw could be exploited to view sensitive\ninformation. This update alters Pidgin behaviour by asking users to confirm\nthe validity of a certificate upon initial login. (CVE-2008-3532)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"pidgin","version":"1:2.2.1-1ubuntu4.3","description":"","is_source":true},{"name":"pidgin","version":"1:2.2.1-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.2.1-1ubuntu4.3"}],"hardy":[{"name":"pidgin","version":"1:2.4.1-1ubuntu2.2","description":"","is_source":true},{"name":"pidgin","version":"1:2.4.1-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pidgin","version_link":"https://launchpad.net/ubuntu/+source/pidgin/1:2.4.1-1ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2008-2927","CVE-2008-2957","CVE-2008-3532","CVE-2008-2955"]}]},{"id":"CVE-2008-3337","published":"2008-08-08T19:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPowerDNS Authoritative Server before 2.9.21.1 drops malformed queries,\nwhich might make it easier for remote attackers to poison DNS caches of\nother products running on other servers, a different issue than\nCVE-2008-1447 and CVE-2008-3217.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3337"],"bugs":[""],"patches":{"pdns":[]},"tags":{},"packages":[{"name":"pdns","source":"https://ubuntu.com/security/cve?package=pdns","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pdns","debian":"https://tracker.debian.org/pkg/pdns","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.21.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2377","published":"2008-08-08T19:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear\nfunction in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through\n2.4.0 allows remote attackers to cause a denial of service (crash) or\npossibly execute arbitrary code via TLS transmission of data that is\nimproperly used when the peer calls gnutls_handshake within a normal\nsession, leading to attempted access to a deallocated libgcrypt handle.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2377"],"bugs":[""],"patches":{"gnutls26":[],"gnutls12":[],"gnutls13":[]},"tags":{},"packages":[{"name":"gnutls12","source":"https://ubuntu.com/security/cve?package=gnutls12","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnutls12","debian":"https://tracker.debian.org/pkg/gnutls12","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.1","component":null,"pocket":"security"}]},{"name":"gnutls13","source":"https://ubuntu.com/security/cve?package=gnutls13","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnutls13","debian":"https://tracker.debian.org/pkg/gnutls13","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.1","component":null,"pocket":"security"}]},{"name":"gnutls26","source":"https://ubuntu.com/security/cve?package=gnutls26","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnutls26","debian":"https://tracker.debian.org/pkg/gnutls26","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3272","published":"2008-08-08T18:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe snd_seq_oss_synth_make_info function in\nsound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux\nkernel before 2.6.27-rc2 does not verify that the device number is within\nthe range defined by max_synthdev before returning certain data to the\ncaller, which allows local users to obtain sensitive information.","ubuntu_description":"\nTobias Klein discovered that the OSS interface through ALSA did not\ncorrectly validate the device number.  A local attacker could exploit\nthis to access sensitive kernel memory, leading to a denial of service\nor a loss of privacy.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-637-1","https://www.cve.org/CVERecord?id=CVE-2008-3272"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=82e68f7ffec3800425f2391c8c86277606860442"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-19.41","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-52.71","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-17.39","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-15.58","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.27~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-637-1"],"notices":[{"id":"USN-637-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-08-25T17:55:40.364727","description":"It was discovered that there were multiple NULL-pointer function\ndereferences in the Linux kernel terminal handling code. A local attacker\ncould exploit this to execute arbitrary code as root, or crash the system,\nleading to a denial of service. (CVE-2008-2812)\n\nThe do_change_type routine did not correctly validation administrative\nusers. A local attacker could exploit this to block mount points or cause\nprivate mounts to be shared, leading to denial of service or a possible\nloss of privacy. (CVE-2008-2931)\n\nTobias Klein discovered that the OSS interface through ALSA did not\ncorrectly validate the device number. A local attacker could exploit this\nto access sensitive kernel memory, leading to a denial of service or a loss\nof privacy. (CVE-2008-3272)\n\nZoltan Sogor discovered that new directory entries could be added to\nalready deleted directories. A local attacker could exploit this, filling\nup available memory and disk space, leading to a denial of service.\n(CVE-2008-3275)\n\nIn certain situations, the fix for CVE-2008-0598 from USN-623-1 was causing\ninfinite loops in the writev syscall.  This update corrects the mistake.  We\napologize for the inconvenience.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-15.58","description":"","is_source":true},{"name":"linux-image-2.6.22-15-mckinley","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-generic","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-hppa32","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-xen","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-sparc64-smp","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-powerpc","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-itanium","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-lpiacompat","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-386","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-powerpc-smp","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-lpia","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-sparc64","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-rt","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-virtual","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-server","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-powerpc64-smp","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-hppa64","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-cell","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"},{"name":"linux-image-2.6.22-15-ume","version":"2.6.22-15.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.58"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-52.71","description":"","is_source":true},{"name":"linux-image-2.6.15-52-386","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-mckinley","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-amd64-server","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-hppa32","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-k7","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-686","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-amd64-k8","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-server-bigiron","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-powerpc64-smp","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-sparc64-smp","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-itanium","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-server","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-hppa32-smp","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-amd64-xeon","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-mckinley-smp","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-hppa64-smp","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-hppa64","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-powerpc","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-powerpc-smp","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-amd64-generic","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-itanium-smp","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"},{"name":"linux-image-2.6.15-52-sparc64","version":"2.6.15-52.71","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.71"}],"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-17.39","description":"","is_source":true},{"name":"linux-image-2.6.20-17-hppa32","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-386","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-sparc64-smp","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-generic","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-hppa64","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-lowlatency","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-mckinley","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-server-bigiron","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-server","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-powerpc64-smp","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-powerpc","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-powerpc-smp","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-sparc64","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"},{"name":"linux-image-2.6.20-17-itanium","version":"2.6.20-17.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.39"}],"hardy":[{"name":"linux","version":"2.6.24-19.41","description":"","is_source":true},{"name":"linux-image-2.6.24-19-server","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-virtual","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-lpia","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-openvz","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-386","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-mckinley","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-powerpc","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-sparc64","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-sparc64-smp","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-powerpc-smp","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-itanium","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-hppa64","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-xen","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-powerpc64-smp","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-rt","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-generic","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-hppa32","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"},{"name":"linux-image-2.6.24-19-lpiacompat","version":"2.6.24-19.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.41"}]},"type":"USN","cves_ids":["CVE-2008-3272","CVE-2008-2931","CVE-2008-3275","CVE-2008-2812"]}]},{"id":"CVE-2008-1945","published":"2008-08-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nQEMU 0.9.0 does not properly handle changes to removable media, which\nallows guest OS users to read arbitrary files on the host OS by using the\ndiskformat: parameter in the -usbdevice option to modify the disk-image\nheader to identify a different format, a related issue to CVE-2008-2004.","ubuntu_description":"","notes":[{"author":"kees","note":"this follows CVE-2008-2004 chronologically.\nxen-utils-3.x is in universe."},{"author":"mdeslaur","note":"patch is xen-qemu-usbdisk-no-auto-format.patch in RHEL5"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-776-1","https://www.cve.org/CVERecord?id=CVE-2008-1945"],"bugs":[""],"patches":{"qemu":["vendor: http://www.mandriva.com/security/advisories?name=MDVSA-2008:162"],"xen-3.0":["vendor: http://people.ubuntu.com/~kees/qemu/xen-qemu-usbdisk-no-auto-format-CVE-2008-1945.patch"],"xen-3.1":["vendor: http://people.ubuntu.com/~kees/qemu/xen-qemu-usbdisk-no-auto-format-CVE-2008-1945.patch"],"xen-3.2":["vendor: http://people.ubuntu.com/~kees/qemu/xen-qemu-usbdisk-no-auto-format-CVE-2008-1945.patch"],"xen-3.3":[],"kvm":[],"qemu-kvm":[]},"tags":{"xen-3.1":["universe-binary"],"xen-3.2":["universe-binary"]},"packages":[{"name":"kvm","source":"https://ubuntu.com/security/cve?package=kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kvm","debian":"https://tracker.debian.org/pkg/kvm","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:62+dfsg-0ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:72+dfsg-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.0","source":"https://ubuntu.com/security/cve?package=xen-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen-3.0","debian":"https://tracker.debian.org/pkg/xen-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.1","source":"https://ubuntu.com/security/cve?package=xen-3.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen-3.1","debian":"https://tracker.debian.org/pkg/xen-3.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.2","source":"https://ubuntu.com/security/cve?package=xen-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen-3.2","debian":"https://tracker.debian.org/pkg/xen-3.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.3","source":"https://ubuntu.com/security/cve?package=xen-3.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen-3.3","debian":"https://tracker.debian.org/pkg/xen-3.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-776-1"],"notices":[{"id":"USN-776-1","title":"KVM vulnerabilities","summary":"KVM vulnerabilities","instructions":"After a standard system upgrade you need to restart all KVM VMs to effect\nthe necessary changes.\n","references":[],"published":"2009-05-12T22:23:50.165727","description":"Avi Kivity discovered that KVM did not correctly handle certain disk\nformats.  A local attacker could attach a malicious partition that\nwould allow the guest VM to read files on the VM host. (CVE-2008-1945,\nCVE-2008-2004)\n\nAlfredo Ortega discovered that KVM's VNC protocol handler did not\ncorrectly validate certain messages.  A remote attacker could send\nspecially crafted VNC messages that would cause KVM to consume CPU\nresources, leading to a denial of service. (CVE-2008-2382)\n\nJan Niehusmann discovered that KVM's Cirrus VGA implementation over VNC\ndid not correctly handle certain bitblt operations.  A local attacker\ncould exploit this flaw to potentially execute arbitrary code on the VM\nhost or crash KVM, leading to a denial of service. (CVE-2008-4539)\n\nIt was discovered that KVM's VNC password checks did not use the correct\nlength.  A remote attacker could exploit this flaw to cause KVM to crash,\nleading to a denial of service. (CVE-2008-5714)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"kvm","version":"1:62+dfsg-0ubuntu8.1","description":"","is_source":true},{"name":"kvm","version":"1:62+dfsg-0ubuntu8.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kvm","version_link":"https://launchpad.net/ubuntu/+source/kvm/1:62+dfsg-0ubuntu8.1"}],"intrepid":[{"name":"kvm","version":"1:72+dfsg-1ubuntu6.1","description":"","is_source":true},{"name":"kvm","version":"1:72+dfsg-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kvm","version_link":"https://launchpad.net/ubuntu/+source/kvm/1:72+dfsg-1ubuntu6.1"}]},"type":"USN","cves_ids":["CVE-2008-1945","CVE-2008-2004","CVE-2008-2382","CVE-2008-4539","CVE-2008-5714"]}]},{"id":"CVE-2008-3546","published":"2008-08-07T21:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the (1) diff_addremove and (2) diff_change\nfunctions in GIT before 1.5.6.4 might allow local users to execute\narbitrary code via a PATH whose length is larger than the system's PATH_MAX\nwhen running GIT utilities such as git-diff or git-grep.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-723-1","https://www.cve.org/CVERecord?id=CVE-2008-3546"],"bugs":[""],"patches":{"git-core":["upstream: http://git.kernel.org/?p=git/git.git;a=commitdiff;h=fd55a19","upstream: http://git.kernel.org/?p=git/git.git;a=commitdiff;h=620e2bb","upstream: http://git.kernel.org/?p=git/git.git;a=commitdiff;h=f66cf96","vendor: http://patch-tracking.debian.net/package/git-core/1:1.4.4.4-4+etch1"]},"tags":{},"packages":[{"name":"git-core","source":"https://ubuntu.com/security/cve?package=git-core","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=git-core","debian":"https://tracker.debian.org/pkg/git-core","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.3-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1:1.5.2.5-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:1.5.4.3-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:1.5.6.3-1.1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.5.6.3-1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-723-1"],"notices":[{"id":"USN-723-1","title":"Git vulnerabilities","summary":"Git vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-02-18T18:59:28.268850","description":"It was discovered that Git did not properly handle long file paths. If a user\nwere tricked into performing commands on a specially crafted Git repository, an\nattacker could possibly execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2008-3546)\n\nIt was discovered that the Git web interface (gitweb) did not correctly handle\nshell metacharacters when processing certain commands. A remote attacker could\nsend specially crafted commands to the Git server and execute arbitrary code\nwith the privileges of the Git web server. This issue only applied to Ubuntu\n7.10 and 8.04 LTS. (CVE-2008-5516, CVE-2008-5517)\n\nIt was discovered that the Git web interface (gitweb) did not properly restrict\nthe diff.external configuration parameter. A local attacker could exploit this\nissue and execute arbitrary code with the privileges of the Git web server.\nThis issue only applied to Ubuntu 8.04 LTS and 8.10. (CVE-2008-5916)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"git-core","version":"1:1.5.2.5-2ubuntu0.1","description":"","is_source":true},{"name":"git-core","version":"1:1.5.2.5-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/git-core","version_link":"https://launchpad.net/ubuntu/+source/git-core/1:1.5.2.5-2ubuntu0.1"},{"name":"gitweb","version":"1:1.5.2.5-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/git-core","version_link":"https://launchpad.net/ubuntu/+source/git-core/1:1.5.2.5-2ubuntu0.1"}],"dapper":[{"name":"git-core","version":"1.1.3-1ubuntu1.1","description":"","is_source":true},{"name":"git-core","version":"1.1.3-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/git-core","version_link":"https://launchpad.net/ubuntu/+source/git-core/1.1.3-1ubuntu1.1"}],"intrepid":[{"name":"git-core","version":"1:1.5.6.3-1.1ubuntu2.1","description":"","is_source":true},{"name":"git-core","version":"1:1.5.6.3-1.1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/git-core","version_link":"https://launchpad.net/ubuntu/+source/git-core/1:1.5.6.3-1.1ubuntu2.1"},{"name":"gitweb","version":"1:1.5.6.3-1.1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/git-core","version_link":"https://launchpad.net/ubuntu/+source/git-core/1:1.5.6.3-1.1ubuntu2.1"}],"hardy":[{"name":"git-core","version":"1:1.5.4.3-1ubuntu2.1","description":"","is_source":true},{"name":"git-core","version":"1:1.5.4.3-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/git-core","version_link":"https://launchpad.net/ubuntu/+source/git-core/1:1.5.4.3-1ubuntu2.1"},{"name":"gitweb","version":"1:1.5.4.3-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/git-core","version_link":"https://launchpad.net/ubuntu/+source/git-core/1:1.5.4.3-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2008-5516","CVE-2008-3546","CVE-2008-5916","CVE-2008-5517"]}]},{"id":"CVE-2008-3496","published":"2008-08-06T18:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in format descriptor parsing in the uvc_parse_format\nfunction in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the\nvideo4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has\nunknown impact and attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3496"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26.1","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2939","published":"2008-08-06T18:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in proxy_ftp.c in the\nmod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in\nthe mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows\nremote attackers to inject arbitrary web script or HTML via a wildcard in\nthe last directory component in the pathname in an FTP URI.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-731-1","https://www.cve.org/CVERecord?id=CVE-2008-2939"],"bugs":[""],"patches":{"apache":[],"apache2":["other: http://svn.apache.org/viewvc?view=rev&revision=682870"]},"tags":{},"packages":[{"name":"apache","source":"https://ubuntu.com/security/cve?package=apache","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apache","debian":"https://tracker.debian.org/pkg/apache","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.2.4-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.2.8-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.2.9-7ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.9-7","component":null,"pocket":"security"}]}],"notices_ids":["USN-731-1"],"notices":[{"id":"USN-731-1","title":"Apache vulnerabilities","summary":"Apache vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-03-10T20:22:03.948366","description":"It was discovered that Apache did not sanitize the method specifier header from\nan HTTP request when it is returned in an error message, which could result in\nbrowsers becoming vulnerable to cross-site scripting attacks when processing the\noutput. With cross-site scripting vulnerabilities, if a user were tricked into\nviewing server output during a crafted server request, a remote attacker could\nexploit this to modify the contents, or steal confidential data (such as\npasswords), within the same domain. This issue only affected Ubuntu 6.06 LTS and\n7.10. (CVE-2007-6203)\n\nIt was discovered that Apache was vulnerable to a cross-site request forgery\n(CSRF) in the mod_proxy_balancer balancer manager. If an Apache administrator\nwere tricked into clicking a link on a specially crafted web page, an attacker\ncould trigger commands that could modify the balancer manager configuration.\nThis issue only affected Ubuntu 7.10 and 8.04 LTS. (CVE-2007-6420)\n\nIt was discovered that Apache had a memory leak when using mod_ssl with\ncompression. A remote attacker could exploit this to exhaust server memory,\nleading to a denial of service. This issue only affected Ubuntu 7.10.\n(CVE-2008-1678)\n\nIt was discovered that in certain conditions, Apache did not specify a default\ncharacter set when returning certain error messages containing UTF-7 encoded\ndata, which could result in browsers becoming vulnerable to cross-site scripting\nattacks when processing the output. This issue only affected Ubuntu 6.06 LTS and\n7.10. (CVE-2008-2168)\n\nIt was discovered that when configured as a proxy server, Apache did not limit\nthe number of forwarded interim responses. A malicious remote server could send\na large number of interim responses and cause a denial of service via memory\nexhaustion. (CVE-2008-2364)\n\nIt was discovered that mod_proxy_ftp did not sanitize wildcard pathnames when\nthey are returned in directory listings, which could result in browsers becoming\nvulnerable to cross-site scripting attacks when processing the output.\n(CVE-2008-2939)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"apache2","version":"2.2.4-3ubuntu0.2","description":"","is_source":true},{"name":"apache2-mpm-worker","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"},{"name":"apache2-mpm-event","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"},{"name":"apache2.2-common","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"},{"name":"apache2-mpm-prefork","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"},{"name":"apache2-mpm-perchild","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"}],"dapper":[{"name":"apache2","version":"2.0.55-4ubuntu2.4","description":"","is_source":true},{"name":"apache2-mpm-worker","version":"2.0.55-4ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.4"},{"name":"apache2-mpm-perchild","version":"2.0.55-4ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.4"},{"name":"apache2-mpm-prefork","version":"2.0.55-4ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.4"},{"name":"apache2-common","version":"2.0.55-4ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.4"}],"hardy":[{"name":"apache2","version":"2.2.8-1ubuntu0.5","description":"","is_source":true},{"name":"apache2-mpm-worker","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"},{"name":"apache2-mpm-event","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"},{"name":"apache2.2-common","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"},{"name":"apache2-mpm-prefork","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"},{"name":"apache2-mpm-perchild","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"}]},"type":"USN","cves_ids":["CVE-2007-6203","CVE-2007-6420","CVE-2008-1678","CVE-2008-2168","CVE-2008-2364","CVE-2008-2939"]}]},{"id":"CVE-2008-3431","published":"2008-08-05T19:41:00","updated_at":"2025-08-25T19:38:04.295248+00:00","description":"\nThe VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox\nbefore 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and\ndoes not properly validate a buffer associated with the Irp object, which\nallows local users to gain privileges by opening the \\\\.\\VBoxDrv device and\ncalling DeviceIoControl to send a crafted kernel address.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3431","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"virtualbox-ose":[]},"tags":{},"packages":[{"name":"virtualbox-ose","source":"https://ubuntu.com/security/cve?package=virtualbox-ose","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=virtualbox-ose","debian":"https://tracker.debian.org/pkg/virtualbox-ose","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3459","published":"2008-08-04T19:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when\nrunning on non-Windows systems, allows remote servers to execute arbitrary\ncommands via crafted (1) lladdr and (2) iproute configuration directives,\nprobably related to shell metacharacters.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3459"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/openvpn/+bug/256621"],"patches":{"openvpn":[]},"tags":{},"packages":[{"name":"openvpn","source":"https://ubuntu.com/security/cve?package=openvpn","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openvpn","debian":"https://tracker.debian.org/pkg/openvpn","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1~rc9-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3457","published":"2008-08-04T19:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before\n2.11.8 allows user-assisted remote attackers to inject arbitrary web script\nor HTML via crafted setup arguments.  NOTE: this issue can only be\nexploited in limited scenarios in which the attacker must be able to modify\nconfig/config.inc.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3457"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/259839"],"patches":{"phpmyadmin":["upstream: http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=11423"]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4:2.11.3-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:2.11.8~rc1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3456","published":"2008-08-04T19:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nphpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using\nframes that point to pages in other domains, which makes it easier for\nremote attackers to conduct spoofing or phishing activities via a\ncross-site framing attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3456"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/259839"],"patches":{"phpmyadmin":["upstream: http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=11422"]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4:2.11.3-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:2.11.8~rc1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3444","published":"2008-08-04T10:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote\nattackers to cause a denial of service (NULL pointer dereference and\napplication crash) via a crafted but well-formed web page that contains \"a\nsimple set of legitimate HTML tags.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3444"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=448564"],"patches":{"firefox":[],"firefox-3.0":[],"iceweasel":[],"xulrunner":[],"xulrunner-1.9":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.12+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.12+build1+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.8+nobinonly-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceweasel","source":"https://ubuntu.com/security/cve?package=iceweasel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceweasel","debian":"https://tracker.debian.org/pkg/iceweasel","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.12+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.12+build1+nobinonly-0ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.8+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2370","published":"2008-08-04T01:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through\n6.0.16, when a RequestDispatcher is used, performs path normalization\nbefore removing the query string from the URI, which allows remote\nattackers to conduct directory traversal attacks and read arbitrary files\nvia a .. (dot dot) in a request parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2370"],"bugs":["http://launchpad.net/bugs/270553"],"patches":{"tomcat5.5":[],"tomcat6":[]},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.5.25-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.5.26-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"6.0.18-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-1232","published":"2008-08-04T01:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through\n4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote\nattackers to inject arbitrary web script or HTML via a crafted string that\nis used in the message argument to the HttpServletResponse.sendError\nmethod.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-1232"],"bugs":["http://launchpad.net/bugs/270553"],"patches":{"tomcat5.5":[],"tomcat6":[]},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.5.25-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.5.26-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"6.0.18-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3440","published":"2008-08-01T14:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSun Java 1.6.0_03 and earlier versions, and possibly later versions, does\nnot properly verify the authenticity of updates, which allows\nman-in-the-middle attackers to execute arbitrary code via a Trojan horse\nupdate, as demonstrated by evilgrade and DNS cache poisoning.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"AFAICT, sun-java5, sun-java6 and openjdk-6 don't do auto-updates\nDebian marked this CVE as Windows-only (java updater for Windows)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3440"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"6b09-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"6b12-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"1.5.0-13-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-15-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.5.0-16-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"6-03-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"6-06-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"6-10-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-3437","published":"2008-08-01T14:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity\nof updates, which allows man-in-the-middle attackers to execute arbitrary\ncode via a Trojan horse update, as demonstrated by evilgrade and DNS cache\npoisoning.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-3437"],"bugs":[""],"patches":{"openoffice.org":[]},"tags":{},"packages":[{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"not-affected","description":"update feature disabled","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"update feature disabled","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"update feature disabled","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"update feature disabled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":75140,"limit":20,"total_results":79316}