{"cves":[{"id":"CVE-2008-1379","published":"2008-06-16T19:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the fbShmPutImage function in the MIT-SHM extension in\nthe X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to\nread arbitrary process memory via crafted values for a Pixmap width and\nheight.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-616-1","https://www.cve.org/CVERecord?id=CVE-2008-1379"],"bugs":[""],"patches":{"xorg-server":["upstream: ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cve-2008-1379.diff"]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"dapper","status":"released","description":"1:1.0.2-0ubuntu10.13","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2:1.2.0-3ubuntu8.4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2:1.3.0.0.dfsg-12ubuntu8.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2:1.4.1~git20080131-1ubuntu9.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-616-1"],"notices":[{"id":"USN-616-1","title":"X.org vulnerabilities","summary":"X.org vulnerabilities","instructions":"After a standard system upgrade you need to restart your session to effect\nthe necessary changes.\n","references":[],"published":"2008-06-13T05:55:55.593213","description":"Multiple flaws were found in the RENDER, RECORD, and Security\nextensions of X.org which did not correctly validate function arguments.\nAn authenticated attacker could send specially crafted requests and gain\nroot privileges or crash X. (CVE-2008-1377, CVE-2008-2360, CVE-2008-2361,\nCVE-2008-2362)\n\nIt was discovered that the MIT-SHM extension of X.org did not correctly\nvalidate the location of memory during an image copy. An authenticated\nattacker could exploit this to read arbitrary memory locations within X,\nexposing sensitive information. (CVE-2008-1379)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"xorg-server","version":"2:1.3.0.0.dfsg-12ubuntu8.4","description":"","is_source":true},{"name":"xserver-xorg-core","version":"2:1.3.0.0.dfsg-12ubuntu8.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.3.0.0.dfsg-12ubuntu8.4"}],"dapper":[{"name":"xorg-server","version":"1:1.0.2-0ubuntu10.13","description":"","is_source":true},{"name":"xserver-xorg-core","version":"1:1.0.2-0ubuntu10.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/1:1.0.2-0ubuntu10.13"}],"feisty":[{"name":"xorg-server","version":"2:1.2.0-3ubuntu8.4","description":"","is_source":true},{"name":"xserver-xorg-core","version":"2:1.2.0-3ubuntu8.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.2.0-3ubuntu8.4"}],"hardy":[{"name":"xorg-server","version":"2:1.4.1~git20080131-1ubuntu9.2","description":"","is_source":true},{"name":"xserver-xorg-core","version":"2:1.4.1~git20080131-1ubuntu9.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.4.1~git20080131-1ubuntu9.2"}]},"type":"USN","cves_ids":["CVE-2008-2362","CVE-2008-2361","CVE-2008-1377","CVE-2008-2360","CVE-2008-1379"]}]},{"id":"CVE-2008-1377","published":"2008-06-16T19:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients\nfunctions in the Record extension and the (3)\nSProcSecurityGenerateAuthorization function in the Security extension in\nthe X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to\nexecute arbitrary code via requests with crafted length values that specify\nan arbitrary number of bytes to be swapped on the heap, which triggers heap\ncorruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-616-1","https://www.cve.org/CVERecord?id=CVE-2008-1377"],"bugs":[""],"patches":{"xorg-server":["upstream: ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cve-2008-1377.diff"]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"dapper","status":"released","description":"1:1.0.2-0ubuntu10.13","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2:1.2.0-3ubuntu8.4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2:1.3.0.0.dfsg-12ubuntu8.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2:1.4.1~git20080131-1ubuntu9.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-616-1"],"notices":[{"id":"USN-616-1","title":"X.org vulnerabilities","summary":"X.org vulnerabilities","instructions":"After a standard system upgrade you need to restart your session to effect\nthe necessary changes.\n","references":[],"published":"2008-06-13T05:55:55.593213","description":"Multiple flaws were found in the RENDER, RECORD, and Security\nextensions of X.org which did not correctly validate function arguments.\nAn authenticated attacker could send specially crafted requests and gain\nroot privileges or crash X. (CVE-2008-1377, CVE-2008-2360, CVE-2008-2361,\nCVE-2008-2362)\n\nIt was discovered that the MIT-SHM extension of X.org did not correctly\nvalidate the location of memory during an image copy. An authenticated\nattacker could exploit this to read arbitrary memory locations within X,\nexposing sensitive information. (CVE-2008-1379)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"xorg-server","version":"2:1.3.0.0.dfsg-12ubuntu8.4","description":"","is_source":true},{"name":"xserver-xorg-core","version":"2:1.3.0.0.dfsg-12ubuntu8.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.3.0.0.dfsg-12ubuntu8.4"}],"dapper":[{"name":"xorg-server","version":"1:1.0.2-0ubuntu10.13","description":"","is_source":true},{"name":"xserver-xorg-core","version":"1:1.0.2-0ubuntu10.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/1:1.0.2-0ubuntu10.13"}],"feisty":[{"name":"xorg-server","version":"2:1.2.0-3ubuntu8.4","description":"","is_source":true},{"name":"xserver-xorg-core","version":"2:1.2.0-3ubuntu8.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.2.0-3ubuntu8.4"}],"hardy":[{"name":"xorg-server","version":"2:1.4.1~git20080131-1ubuntu9.2","description":"","is_source":true},{"name":"xserver-xorg-core","version":"2:1.4.1~git20080131-1ubuntu9.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.4.1~git20080131-1ubuntu9.2"}]},"type":"USN","cves_ids":["CVE-2008-2362","CVE-2008-2361","CVE-2008-1377","CVE-2008-2360","CVE-2008-1379"]}]},{"id":"CVE-2008-2654","published":"2008-06-13T18:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the read_client function in webhttpd.c in Motion 3.2.10\nand earlier might allow remote attackers to execute arbitrary code via a\nlong request to a Motion HTTP Control interface, which triggers a\nstack-based buffer overflow with some combinations of processor\narchitecture and compiler.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2654"],"bugs":[""],"patches":{"motion":[]},"tags":{},"packages":[{"name":"motion","source":"https://ubuntu.com/security/cve?package=motion","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=motion","debian":"https://tracker.debian.org/pkg/motion","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"3.2.9-4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.2.9-4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.9-4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.9-4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.9-4","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.9-4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.9-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.9-4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2364","published":"2008-06-13T18:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ap_proxy_http_process_response function in mod_proxy_http.c in the\nmod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit\nthe number of forwarded interim responses, which allows remote HTTP servers\nto cause a denial of service (memory consumption) via a large number of\ninterim responses.","ubuntu_description":"","notes":[{"author":"kees","note":"only a problem when the server being proxied is untrusted"},{"author":"jdstrand","note":"PoC: http://svn.apache.org/viewvc/httpd/test/framework/trunk/t/security/CVE-2008-2364.t?revision=666283&view=markup"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-731-1","https://www.cve.org/CVERecord?id=CVE-2008-2364"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/apache2/+bug/239894"],"patches":{"apache2":["upstream: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&r2=666153&pathrev=666154","upstream: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&r2=666180","other: http://archive.apache.org/dist/httpd/patches/apply_to_2.0.63/CVE-2008-2364-patch-2.0.txt","debdiff: http://launchpad.net/bugs/239894"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.2.4-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.2.8-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.2.9-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.9","component":null,"pocket":"security"}]}],"notices_ids":["USN-731-1"],"notices":[{"id":"USN-731-1","title":"Apache vulnerabilities","summary":"Apache vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-03-10T20:22:03.948366","description":"It was discovered that Apache did not sanitize the method specifier header from\nan HTTP request when it is returned in an error message, which could result in\nbrowsers becoming vulnerable to cross-site scripting attacks when processing the\noutput. With cross-site scripting vulnerabilities, if a user were tricked into\nviewing server output during a crafted server request, a remote attacker could\nexploit this to modify the contents, or steal confidential data (such as\npasswords), within the same domain. This issue only affected Ubuntu 6.06 LTS and\n7.10. (CVE-2007-6203)\n\nIt was discovered that Apache was vulnerable to a cross-site request forgery\n(CSRF) in the mod_proxy_balancer balancer manager. If an Apache administrator\nwere tricked into clicking a link on a specially crafted web page, an attacker\ncould trigger commands that could modify the balancer manager configuration.\nThis issue only affected Ubuntu 7.10 and 8.04 LTS. (CVE-2007-6420)\n\nIt was discovered that Apache had a memory leak when using mod_ssl with\ncompression. A remote attacker could exploit this to exhaust server memory,\nleading to a denial of service. This issue only affected Ubuntu 7.10.\n(CVE-2008-1678)\n\nIt was discovered that in certain conditions, Apache did not specify a default\ncharacter set when returning certain error messages containing UTF-7 encoded\ndata, which could result in browsers becoming vulnerable to cross-site scripting\nattacks when processing the output. This issue only affected Ubuntu 6.06 LTS and\n7.10. (CVE-2008-2168)\n\nIt was discovered that when configured as a proxy server, Apache did not limit\nthe number of forwarded interim responses. A malicious remote server could send\na large number of interim responses and cause a denial of service via memory\nexhaustion. (CVE-2008-2364)\n\nIt was discovered that mod_proxy_ftp did not sanitize wildcard pathnames when\nthey are returned in directory listings, which could result in browsers becoming\nvulnerable to cross-site scripting attacks when processing the output.\n(CVE-2008-2939)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"apache2","version":"2.2.4-3ubuntu0.2","description":"","is_source":true},{"name":"apache2-mpm-worker","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"},{"name":"apache2-mpm-event","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"},{"name":"apache2.2-common","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"},{"name":"apache2-mpm-prefork","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"},{"name":"apache2-mpm-perchild","version":"2.2.4-3ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.4-3ubuntu0.2"}],"dapper":[{"name":"apache2","version":"2.0.55-4ubuntu2.4","description":"","is_source":true},{"name":"apache2-mpm-worker","version":"2.0.55-4ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.4"},{"name":"apache2-mpm-perchild","version":"2.0.55-4ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.4"},{"name":"apache2-mpm-prefork","version":"2.0.55-4ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.4"},{"name":"apache2-common","version":"2.0.55-4ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.0.55-4ubuntu2.4"}],"hardy":[{"name":"apache2","version":"2.2.8-1ubuntu0.5","description":"","is_source":true},{"name":"apache2-mpm-worker","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"},{"name":"apache2-mpm-event","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"},{"name":"apache2.2-common","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"},{"name":"apache2-mpm-prefork","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"},{"name":"apache2-mpm-perchild","version":"2.2.8-1ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.5"}]},"type":"USN","cves_ids":["CVE-2007-6203","CVE-2007-6420","CVE-2008-1678","CVE-2008-2168","CVE-2008-2364","CVE-2008-2939"]}]},{"id":"CVE-2008-2696","published":"2008-06-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nExiv2 0.16 allows user-assisted remote attackers to cause a denial of\nservice (divide-by-zero and application crash) via a zero value in Nikon\nlens information in the metadata of an image, related to \"pretty printing\"\nand the RationalValue::toLong function.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-655-1","https://www.cve.org/CVERecord?id=CVE-2008-2696"],"bugs":[""],"patches":{"exiv2":["upstream: http://dev.robotbattle.com/cgi-bin/viewvc.cgi/exiv2/trunk/src/nikonmn.cpp?r1=1398&r2=1399"]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.12-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.15-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.16-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"0.17-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.17-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.17-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.17.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-655-1"],"notices":[{"id":"USN-655-1","title":"exiv2 vulnerabilities","summary":"exiv2 vulnerabilities","instructions":"After a standard system upgrade you need to restart your session to effect\nthe necessary changes.\n","references":[],"published":"2008-10-15T01:49:13.085450","description":"Meder Kydyraliev discovered that exiv2 did not correctly handle certain\nEXIF headers. If a user or automated system were tricked into processing\na specially crafted image, a remote attacker could cause the application\nlinked against libexiv2 to crash, leading to a denial of service, or\npossibly executing arbitrary code with user privileges. (CVE-2007-6353)\n\nJoakim Bildrulle discovered that exiv2 did not correctly handle Nikon\nlens EXIF information. If a user or automated system were tricked into\nprocessing a specially crafted image, a remote attacker could cause the\napplication linked against libexiv2 to crash, leading to a denial of\nservice. (CVE-2008-2696)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"exiv2","version":"0.15-1ubuntu2.1","description":"","is_source":true},{"name":"libexiv2-0","version":"0.15-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.15-1ubuntu2.1"}],"feisty":[{"name":"exiv2","version":"0.12-0ubuntu2.1","description":"","is_source":true},{"name":"libexiv2-0.12","version":"0.12-0ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.12-0ubuntu2.1"}],"hardy":[{"name":"exiv2","version":"0.16-3ubuntu1.1","description":"","is_source":true},{"name":"libexiv2-2","version":"0.16-3ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.16-3ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2007-6353","CVE-2008-2696"]}]},{"id":"CVE-2008-2362","published":"2008-06-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in the Render extension in the X server 1.4 in\nX.Org X11R7.3 allow context-dependent attackers to execute arbitrary code\nvia a (1) SProcRenderCreateLinearGradient, (2)\nSProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient\nrequest with an invalid field specifying the number of bytes to swap in the\nrequest data, which triggers heap memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-616-1","https://www.cve.org/CVERecord?id=CVE-2008-2362"],"bugs":[""],"patches":{"xorg-server":["upstream: ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cve-2008-2362.diff"]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"dapper","status":"released","description":"1:1.0.2-0ubuntu10.13","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2:1.2.0-3ubuntu8.4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2:1.3.0.0.dfsg-12ubuntu8.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2:1.4.1~git20080131-1ubuntu9.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-616-1"],"notices":[{"id":"USN-616-1","title":"X.org vulnerabilities","summary":"X.org vulnerabilities","instructions":"After a standard system upgrade you need to restart your session to effect\nthe necessary changes.\n","references":[],"published":"2008-06-13T05:55:55.593213","description":"Multiple flaws were found in the RENDER, RECORD, and Security\nextensions of X.org which did not correctly validate function arguments.\nAn authenticated attacker could send specially crafted requests and gain\nroot privileges or crash X. (CVE-2008-1377, CVE-2008-2360, CVE-2008-2361,\nCVE-2008-2362)\n\nIt was discovered that the MIT-SHM extension of X.org did not correctly\nvalidate the location of memory during an image copy. An authenticated\nattacker could exploit this to read arbitrary memory locations within X,\nexposing sensitive information. (CVE-2008-1379)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"xorg-server","version":"2:1.3.0.0.dfsg-12ubuntu8.4","description":"","is_source":true},{"name":"xserver-xorg-core","version":"2:1.3.0.0.dfsg-12ubuntu8.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.3.0.0.dfsg-12ubuntu8.4"}],"dapper":[{"name":"xorg-server","version":"1:1.0.2-0ubuntu10.13","description":"","is_source":true},{"name":"xserver-xorg-core","version":"1:1.0.2-0ubuntu10.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/1:1.0.2-0ubuntu10.13"}],"feisty":[{"name":"xorg-server","version":"2:1.2.0-3ubuntu8.4","description":"","is_source":true},{"name":"xserver-xorg-core","version":"2:1.2.0-3ubuntu8.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.2.0-3ubuntu8.4"}],"hardy":[{"name":"xorg-server","version":"2:1.4.1~git20080131-1ubuntu9.2","description":"","is_source":true},{"name":"xserver-xorg-core","version":"2:1.4.1~git20080131-1ubuntu9.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.4.1~git20080131-1ubuntu9.2"}]},"type":"USN","cves_ids":["CVE-2008-2362","CVE-2008-2361","CVE-2008-1377","CVE-2008-2360","CVE-2008-1379"]}]},{"id":"CVE-2008-2230","published":"2008-06-11T01:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in (1) reportbug 3.8 and 3.31, and (2)\nreportbug-ng before 0.2008.06.04, allows local users to execute arbitrary\ncode via a malicious module file in the current working directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2230"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484311","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484474","https://bugs.launchpad.net/bugs/239124"],"patches":{"reportbug-ng":[],"reportbug":[]},"tags":{},"packages":[{"name":"reportbug","source":"https://ubuntu.com/security/cve?package=reportbug","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=reportbug","debian":"https://tracker.debian.org/pkg/reportbug","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"3.41ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.41ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.41ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.41ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.41ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.41ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.41ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.41","component":null,"pocket":"security"}]},{"name":"reportbug-ng","source":"https://ubuntu.com/security/cve?package=reportbug-ng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=reportbug-ng","debian":"https://tracker.debian.org/pkg/reportbug-ng","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2008.06.04","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2152","published":"2008-06-10T18:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the rtl_allocateMemory function in\nsal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4\nallows remote attackers to execute arbitrary code via a crafted file that\ntriggers a heap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openoffice.org/security/cves/CVE-2008-2152.html","http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714","https://www.cve.org/CVERecord?id=CVE-2008-2152"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openoffice.org/+bug/238925"],"patches":{"openoffice.org":[]},"tags":{},"packages":[{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"not-affected","description":"built with --with-alloc=system","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"built with --with-alloc=system","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"built with --with-alloc=system","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"built with --with-alloc=system","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2358","published":"2008-06-10T00:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the dccp_feat_change function in net/dccp/feat.c in the\nDatagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel\n2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges\nvia an invalid feature length, which leads to a heap-based buffer overflow.","ubuntu_description":"\nBrandon Edwards discovered that the DCCP system in the kernel did not\ncorrectly check feature lengths. A remote attacker could exploit this\nto execute arbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-625-1","https://www.cve.org/CVERecord?id=CVE-2008-2358"],"bugs":[""],"patches":{"linux-source-2.6.15":["vendor: http://www.debian.org/security/2008/dsa-1592"],"linux-source-2.6.20":["vendor: http://www.debian.org/security/2008/dsa-1592"],"linux-source-2.6.22":["vendor: http://www.debian.org/security/2008/dsa-1592"],"linux":["vendor: http://www.debian.org/security/2008/dsa-1592","upstream: 19443178fbfbf40db15c86012fc37df1a44ab857"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-19.36","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code does not exist","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-17.37","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-15.56","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-625-1"],"notices":[{"id":"USN-625-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-07-15T16:42:28.816056","description":"Dirk Nehring discovered that the IPsec protocol stack did not correctly\nhandle fragmented ESP packets. A remote attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2007-6282)\n\nJohannes Bauer discovered that the 64bit kernel did not correctly handle\nhrtimer updates. A local attacker could request a large expiration value\nand cause the system to hang, leading to a denial of service.\n(CVE-2007-6712)\n\nTavis Ormandy discovered that the ia32 emulation under 64bit kernels did\nnot fully clear uninitialized data. A local attacker could read private\nkernel memory, leading to a loss of privacy. (CVE-2008-0598)\n\nJan Kratochvil discovered that PTRACE did not correctly handle certain\ncalls when running under 64bit kernels. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-1615)\n\nWei Wang discovered that the ASN.1 decoding routines in CIFS and SNMP NAT\ndid not correctly handle certain length values. Remote attackers could\nexploit this to execute arbitrary code or crash the system. (CVE-2008-1673)\n\nPaul Marks discovered that the SIT interfaces did not correctly manage\nallocated memory. A remote attacker could exploit this to fill all\navailable memory, leading to a denial of service. (CVE-2008-2136)\n\nDavid Miller and Jan Lieskovsky discovered that the Sparc kernel did not\ncorrectly range-check memory regions allocated with mmap. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2008-2137)\n\nThe sys_utimensat system call did not correctly check file permissions in\ncertain situations. A local attacker could exploit this to modify the file\ntimes of arbitrary files which could lead to a denial of service.\n(CVE-2008-2148)\n\nBrandon Edwards discovered that the DCCP system in the kernel did not\ncorrectly check feature lengths. A remote attacker could exploit this to\nexecute arbitrary code. (CVE-2008-2358)\n\nA race condition was discovered between ptrace and utrace in the kernel. A\nlocal attacker could exploit this to crash the system, leading to a denial\nof service. (CVE-2008-2365)\n\nThe copy_to_user routine in the kernel did not correctly clear memory\ndestination addresses when running on 64bit kernels. A local attacker could\nexploit this to gain access to sensitive kernel memory, leading to a loss\nof privacy. (CVE-2008-2729)\n\nThe PPP over L2TP routines in the kernel did not correctly handle certain\nmessages. A remote attacker could send a specially crafted packet that\ncould crash the system or execute arbitrary code. (CVE-2008-2750)\n\nGabriel Campana discovered that SCTP routines did not correctly check for\nlarge addresses. A local user could exploit this to allocate all available\nmemory, leading to a denial of service. (CVE-2008-2826)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-15.56","description":"","is_source":true},{"name":"linux-image-2.6.22-15-mckinley","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-generic","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-hppa32","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-xen","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-sparc64-smp","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-powerpc","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-itanium","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-lpiacompat","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-386","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-powerpc-smp","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-lpia","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-sparc64","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-rt","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-virtual","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-server","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-powerpc64-smp","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-hppa64","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-cell","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-ume","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-52.69","description":"","is_source":true},{"name":"linux-image-2.6.15-52-386","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-mckinley","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-server","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa32","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-k7","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-686","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-k8","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-server-bigiron","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-powerpc64-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-sparc64-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-itanium","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-server","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa32-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-xeon","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-mckinley-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa64-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa64","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-powerpc","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-powerpc-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-generic","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-itanium-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-sparc64","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"}],"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-17.37","description":"","is_source":true},{"name":"linux-image-2.6.20-17-hppa32","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-386","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-sparc64-smp","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-generic","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-hppa64","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-lowlatency","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-mckinley","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-server-bigiron","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-server","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-powerpc64-smp","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-powerpc","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-powerpc-smp","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-sparc64","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-itanium","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"}],"hardy":[{"name":"linux","version":"2.6.24-19.36","description":"","is_source":true},{"name":"linux-image-2.6.24-19-server","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-virtual","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-lpia","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-openvz","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-386","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-mckinley","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-powerpc","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-sparc64","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-sparc64-smp","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-powerpc-smp","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-itanium","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-hppa64","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-xen","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-powerpc64-smp","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-rt","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-generic","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-hppa32","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-lpiacompat","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"}]},"type":"USN","cves_ids":["CVE-2008-2826","CVE-2008-2729","CVE-2008-1673","CVE-2008-2137","CVE-2008-2358","CVE-2007-6282","CVE-2008-2148","CVE-2008-1615","CVE-2008-2365","CVE-2008-2750","CVE-2008-0598","CVE-2008-2136","CVE-2007-6712"]}]},{"id":"CVE-2008-1673","published":"2008-06-10T00:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6\nbefore 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b)\nthe gxsnmp package; does not properly validate length values during\ndecoding of ASN.1 BER data, which allows remote attackers to cause a denial\nof service (crash) or execute arbitrary code via (1) a length greater than\nthe working buffer, which can lead to an unspecified overflow; (2) an oid\nlength of zero, which can lead to an off-by-one error; or (3) an indefinite\nlength for a primitive encoding.","ubuntu_description":"\nWei Wang discovered that the ASN.1 decoding routines in CIFS and SNMP\nNAT did not correctly handle certain length values. Remote attackers\ncould exploit this to execute arbitrary code or crash the system.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-625-1","https://www.cve.org/CVERecord?id=CVE-2008-1673"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":["other: http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.25.y.git;a=commit;h=33afb8403f361919aa5c8fe1d0a4f5ddbfbbea3c","other: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ddb2c43594f22843e9f3153da151deaba1a834c5"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-19.36","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-52.69","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-17.37","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-15.56","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-625-1"],"notices":[{"id":"USN-625-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-07-15T16:42:28.816056","description":"Dirk Nehring discovered that the IPsec protocol stack did not correctly\nhandle fragmented ESP packets. A remote attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2007-6282)\n\nJohannes Bauer discovered that the 64bit kernel did not correctly handle\nhrtimer updates. A local attacker could request a large expiration value\nand cause the system to hang, leading to a denial of service.\n(CVE-2007-6712)\n\nTavis Ormandy discovered that the ia32 emulation under 64bit kernels did\nnot fully clear uninitialized data. A local attacker could read private\nkernel memory, leading to a loss of privacy. (CVE-2008-0598)\n\nJan Kratochvil discovered that PTRACE did not correctly handle certain\ncalls when running under 64bit kernels. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-1615)\n\nWei Wang discovered that the ASN.1 decoding routines in CIFS and SNMP NAT\ndid not correctly handle certain length values. Remote attackers could\nexploit this to execute arbitrary code or crash the system. (CVE-2008-1673)\n\nPaul Marks discovered that the SIT interfaces did not correctly manage\nallocated memory. A remote attacker could exploit this to fill all\navailable memory, leading to a denial of service. (CVE-2008-2136)\n\nDavid Miller and Jan Lieskovsky discovered that the Sparc kernel did not\ncorrectly range-check memory regions allocated with mmap. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2008-2137)\n\nThe sys_utimensat system call did not correctly check file permissions in\ncertain situations. A local attacker could exploit this to modify the file\ntimes of arbitrary files which could lead to a denial of service.\n(CVE-2008-2148)\n\nBrandon Edwards discovered that the DCCP system in the kernel did not\ncorrectly check feature lengths. A remote attacker could exploit this to\nexecute arbitrary code. (CVE-2008-2358)\n\nA race condition was discovered between ptrace and utrace in the kernel. A\nlocal attacker could exploit this to crash the system, leading to a denial\nof service. (CVE-2008-2365)\n\nThe copy_to_user routine in the kernel did not correctly clear memory\ndestination addresses when running on 64bit kernels. A local attacker could\nexploit this to gain access to sensitive kernel memory, leading to a loss\nof privacy. (CVE-2008-2729)\n\nThe PPP over L2TP routines in the kernel did not correctly handle certain\nmessages. A remote attacker could send a specially crafted packet that\ncould crash the system or execute arbitrary code. (CVE-2008-2750)\n\nGabriel Campana discovered that SCTP routines did not correctly check for\nlarge addresses. A local user could exploit this to allocate all available\nmemory, leading to a denial of service. (CVE-2008-2826)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-15.56","description":"","is_source":true},{"name":"linux-image-2.6.22-15-mckinley","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-generic","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-hppa32","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-xen","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-sparc64-smp","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-powerpc","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-itanium","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-lpiacompat","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-386","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-powerpc-smp","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-lpia","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-sparc64","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-rt","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-virtual","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-server","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-powerpc64-smp","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-hppa64","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-cell","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-ume","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-52.69","description":"","is_source":true},{"name":"linux-image-2.6.15-52-386","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-mckinley","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-server","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa32","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-k7","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-686","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-k8","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-server-bigiron","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-powerpc64-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-sparc64-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-itanium","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-server","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa32-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-xeon","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-mckinley-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa64-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa64","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-powerpc","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-powerpc-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-generic","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-itanium-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-sparc64","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"}],"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-17.37","description":"","is_source":true},{"name":"linux-image-2.6.20-17-hppa32","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-386","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-sparc64-smp","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-generic","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-hppa64","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-lowlatency","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-mckinley","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-server-bigiron","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-server","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-powerpc64-smp","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-powerpc","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-powerpc-smp","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-sparc64","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-itanium","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"}],"hardy":[{"name":"linux","version":"2.6.24-19.36","description":"","is_source":true},{"name":"linux-image-2.6.24-19-server","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-virtual","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-lpia","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-openvz","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-386","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-mckinley","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-powerpc","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-sparc64","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-sparc64-smp","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-powerpc-smp","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-itanium","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-hppa64","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-xen","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-powerpc64-smp","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-rt","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-generic","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-hppa32","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-lpiacompat","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"}]},"type":"USN","cves_ids":["CVE-2008-2826","CVE-2008-2729","CVE-2008-1673","CVE-2008-2137","CVE-2008-2358","CVE-2007-6282","CVE-2008-2148","CVE-2008-1615","CVE-2008-2365","CVE-2008-2750","CVE-2008-0598","CVE-2008-2136","CVE-2007-6712"]}]},{"id":"CVE-2008-0960","published":"2008-06-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before\n5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper\nSession and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp\n(aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research\nbefore 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8)\nIngate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP\nOpenView SNMP Emanate Master Agent 15.x; and possibly other products relies\non the client to specify the HMAC length, which makes it easier for remote\nattackers to bypass SNMP authentication via a length value of 1, which only\nchecks the first byte.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"expoit tool: http://www.securityfocus.com/archive/1/493304/30/0/threaded"},{"author":"nxvl","note":"Upstream patch: http://sourceforge.net/tracker/download.php?group_id=12694&atid=456380&file_id=280776&aid=1989089"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-685-1","https://www.cve.org/CVERecord?id=CVE-2008-0960"],"bugs":["https://bugs.launchpad.net/bugs/cve/CVE-2008-0960","https://bugs.launchpad.net/bugs/239129"],"patches":{"net-snmp":["vendor: https://rhn.redhat.com/errata/RHSA-2008-0529.html","vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=485945"],"ucd-snmp":["vendor: https://rhn.redhat.com/errata/RHSA-2008-0528.html"]},"tags":{},"packages":[{"name":"net-snmp","source":"https://ubuntu.com/security/cve?package=net-snmp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=net-snmp","debian":"https://tracker.debian.org/pkg/net-snmp","statuses":[{"release_codename":"dapper","status":"released","description":"5.2.1.2-4ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.3.1-6ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.4.1~dfsg-4ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.4.1~dfsg-7.1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.4.1~dfsg-8.1","component":null,"pocket":"security"}]},{"name":"ucd-snmp","source":"https://ubuntu.com/security/cve?package=ucd-snmp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ucd-snmp","debian":"https://tracker.debian.org/pkg/ucd-snmp","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-685-1"],"notices":[{"id":"USN-685-1","title":"Net-SNMP vulnerabilities","summary":"Net-SNMP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-12-03T22:39:34.429418","description":"Wes Hardaker discovered that the SNMP service did not correctly validate\nHMAC authentication requests. An unauthenticated remote attacker\ncould send specially crafted SNMPv3 traffic with a valid username\nand gain access to the user's views without a valid authentication\npassphrase. (CVE-2008-0960)\n\nJohn Kortink discovered that the Net-SNMP Perl module did not correctly\ncheck the size of returned values. If a user or automated system were\ntricked into querying a malicious SNMP server, the application using\nthe Perl module could be made to crash, leading to a denial of service.\nThis did not affect Ubuntu 8.10. (CVE-2008-2292)\n\nIt was discovered that the SNMP service did not correctly handle large\nGETBULK requests. If an unauthenticated remote attacker sent a specially\ncrafted request, the SNMP service could be made to crash, leading to a\ndenial of service. (CVE-2008-4309)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"net-snmp","version":"5.3.1-6ubuntu2.2","description":"","is_source":true},{"name":"libsnmp-perl","version":"5.3.1-6ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.3.1-6ubuntu2.2"},{"name":"libsnmp10","version":"5.3.1-6ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.3.1-6ubuntu2.2"}],"dapper":[{"name":"net-snmp","version":"5.2.1.2-4ubuntu2.3","description":"","is_source":true},{"name":"libsnmp-perl","version":"5.2.1.2-4ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.2.1.2-4ubuntu2.3"},{"name":"libsnmp9","version":"5.2.1.2-4ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.2.1.2-4ubuntu2.3"}],"intrepid":[{"name":"net-snmp","version":"5.4.1~dfsg-7.1ubuntu6.1","description":"","is_source":true},{"name":"libsnmp15","version":"5.4.1~dfsg-7.1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.4.1~dfsg-7.1ubuntu6.1"}],"hardy":[{"name":"net-snmp","version":"5.4.1~dfsg-4ubuntu4.2","description":"","is_source":true},{"name":"libsnmp-perl","version":"5.4.1~dfsg-4ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.4.1~dfsg-4ubuntu4.2"},{"name":"libsnmp15","version":"5.4.1~dfsg-4ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.4.1~dfsg-4ubuntu4.2"}]},"type":"USN","cves_ids":["CVE-2008-0960","CVE-2008-2292","CVE-2008-4309"]}]},{"id":"CVE-2008-2575","published":"2008-06-06T22:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncbrPager before 0.9.17 allows user-assisted remote attackers to execute\narbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2)\nRAR (aka .cbr) archive filename.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2575"],"bugs":[""],"patches":{"cbrpager":[]},"tags":{},"packages":[{"name":"cbrpager","source":"https://ubuntu.com/security/cve?package=cbrpager","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cbrpager","debian":"https://tracker.debian.org/pkg/cbrpager","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"0.9.18-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.9.18-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.9.18-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.9.18-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.9.18-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.9.18-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.9.18-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.17-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2571","published":"2008-06-06T18:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly\nPHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas\nas administrators via a \"modify quota\" action.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2571"],"bugs":[""],"patches":{"limesurvey":[]},"tags":{},"packages":[{"name":"limesurvey","source":"https://ubuntu.com/security/cve?package=limesurvey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=limesurvey","debian":"https://tracker.debian.org/pkg/limesurvey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2553","published":"2008-06-05T20:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Slashdot Like Automated\nStorytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows\nremote attackers to inject arbitrary web script or HTML via the userfield\nparameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2553"],"bugs":[""],"patches":{"slash":[]},"tags":{},"packages":[{"name":"slash","source":"https://ubuntu.com/security/cve?package=slash","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=slash","debian":"https://tracker.debian.org/pkg/slash","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2543","published":"2008-06-05T20:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ooh323 channel driver in Asterisk Addons 1.2.x before 1.2.9 and\nAsterisk-Addons 1.4.x before 1.4.7 creates a remotely accessible TCP port\nthat is intended solely for localhost communication, and interprets some\nTCP application-data fields as addresses of memory to free, which allows\nremote attackers to cause a denial of service (daemon crash) via crafted\nTCP packets.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2543"],"bugs":[""],"patches":{"asterisk-addons":[]},"tags":{},"packages":[{"name":"asterisk-addons","source":"https://ubuntu.com/security/cve?package=asterisk-addons","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk-addons","debian":"https://tracker.debian.org/pkg/asterisk-addons","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.9, 1.4.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2231","published":"2008-06-05T20:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in Slashdot Like Automated Storytelling\nHomepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote\nattackers to execute SQL commands and read table information via the id\nparameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2231"],"bugs":[""],"patches":{"slash":[]},"tags":{},"packages":[{"name":"slash","source":"https://ubuntu.com/security/cve?package=slash","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=slash","debian":"https://tracker.debian.org/pkg/slash","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2100","published":"2008-06-05T20:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on\nVMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x,\nVMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1\nthrough 3.5 allow guest OS users to execute arbitrary code on the host OS\nvia unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2100"],"bugs":[""],"patches":{"vmware-server":[]},"tags":{},"packages":[{"name":"vmware-server","source":"https://ubuntu.com/security/cve?package=vmware-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vmware-server","debian":"https://tracker.debian.org/pkg/vmware-server","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0967","published":"2008-06-05T20:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in vmware-authd in VMware Workstation\n5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware\nPlayer 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and\nVMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and\nVMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a\nlibrary path option in a configuration file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0967"],"bugs":[""],"patches":{"vmware-server":[]},"tags":{},"packages":[{"name":"vmware-server","source":"https://ubuntu.com/security/cve?package=vmware-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vmware-server","debian":"https://tracker.debian.org/pkg/vmware-server","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5671","published":"2008-06-05T20:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6\nbuild 80404, VMware Player before 1.0.6 build 80404, VMware ACE before\n1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX\n2.5.4 through 3.0.2 does not properly validate arguments in user-mode\nMETHOD_NEITHER IOCTLs to the \\\\.\\hgfs device, which allows guest OS users\nto modify arbitrary memory locations in guest kernel memory and gain\nprivileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5671"],"bugs":[""],"patches":{"vmware-server":[]},"tags":{},"packages":[{"name":"vmware-server","source":"https://ubuntu.com/security/cve?package=vmware-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vmware-server","debian":"https://tracker.debian.org/pkg/vmware-server","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-1109","published":"2008-06-04T20:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote\nattackers to execute arbitrary code via a long DESCRIPTION property in an\niCalendar attachment, which is not properly handled during a reply in the\ncalendar view (aka the Calendars window).","ubuntu_description":"","notes":[{"author":"jdstrand","note":"redhat has patches for 2.12, 1,4,5, 2.0.2, 2.8"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-615-1","https://www.cve.org/CVERecord?id=CVE-2008-1109"],"bugs":[""],"patches":{"evolution":["other: http://svn.gnome.org/viewvc/evolution?view=revision&revision=35595","vendor: https://rhn.redhat.com/errata/RHSA-2008-0514.html"]},"tags":{},"packages":[{"name":"evolution","source":"https://ubuntu.com/security/cve?package=evolution","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=evolution","debian":"https://tracker.debian.org/pkg/evolution","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.1-0ubuntu7.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.10.1-0ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.12.1-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.22.2-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-615-1"],"notices":[{"id":"USN-615-1","title":"Evolution vulnerabilities","summary":"Evolution vulnerabilities","instructions":"After a standard system upgrade you need to restart Evolution to effect\nthe necessary changes.\n","references":[],"published":"2008-06-06T20:19:44.531831","description":"Alin Rad Pop of Secunia Research discovered that Evolution did not\nproperly validate timezone data when processing iCalendar attachments.\nIf a user disabled the ITip Formatter plugin and viewed a crafted\niCalendar attachment, an attacker could cause a denial of service or\npossibly execute code with user privileges. Note that the ITip\nFormatter plugin is enabled by default in Ubuntu. (CVE-2008-1108)\n\nAlin Rad Pop of Secunia Research discovered that Evolution did not\nproperly validate the DESCRIPTION field when processing iCalendar\nattachments. If a user were tricked into accepting a crafted\niCalendar attachment and replied to it from the calendar window, an\nattacker code cause a denial of service or execute code with user\nprivileges. (CVE-2008-1109)\n\nMatej Cepl discovered that Evolution did not properly validate date\nfields when processing iCalendar attachments. If a user disabled the\nITip Formatter plugin and viewed a crafted iCalendar attachment, an\nattacker could cause a denial of service. Note that the ITip\nFormatter plugin is enabled by default in Ubuntu.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"evolution","version":"2.12.1-0ubuntu1.3","description":"","is_source":true},{"name":"evolution","version":"2.12.1-0ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution","version_link":"https://launchpad.net/ubuntu/+source/evolution/2.12.1-0ubuntu1.3"}],"dapper":[{"name":"evolution","version":"2.6.1-0ubuntu7.4","description":"","is_source":true},{"name":"evolution","version":"2.6.1-0ubuntu7.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution","version_link":"https://launchpad.net/ubuntu/+source/evolution/2.6.1-0ubuntu7.4"}],"feisty":[{"name":"evolution","version":"2.10.1-0ubuntu2.4","description":"","is_source":true},{"name":"evolution","version":"2.10.1-0ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution","version_link":"https://launchpad.net/ubuntu/+source/evolution/2.10.1-0ubuntu2.4"}],"hardy":[{"name":"evolution","version":"2.22.2-0ubuntu1.2","description":"","is_source":true},{"name":"evolution","version":"2.22.2-0ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution","version_link":"https://launchpad.net/ubuntu/+source/evolution/2.22.2-0ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2008-1108","CVE-2008-1109"]}]}],"offset":75320,"limit":20,"total_results":79316}