{"cves":[{"id":"CVE-2008-2302","published":"2008-05-23T15:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the login form in the\nadministration application in Django 0.91 before 0.91.2, 0.95 before\n0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary\nweb script or HTML via the URI of a certain previous request.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2302"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/python-django/+bug/234631"],"patches":{"python-django":["vendor: http://www.djangoproject.com/weblog/2008/may/14/security/","debdiff: http://launchpad.net/bugs/234631"]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.95.1-1ubuntu.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.96-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.96.1-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.96.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-1767","published":"2008-05-23T15:32:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in pattern.c in libxslt before 1.1.24 allows\ncontext-dependent attackers to cause a denial of service (crash) and\npossibly execute arbitrary code via an XSL style sheet file with a long\nXSLT \"transformation match\" condition that triggers a large number of\nsteps.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-633-1","https://www.cve.org/CVERecord?id=CVE-2008-1767"],"bugs":["https://bugs.launchpad.net/bugs/235909"],"patches":{"libxslt":[]},"tags":{},"packages":[{"name":"libxslt","source":"https://ubuntu.com/security/cve?package=libxslt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxslt","debian":"https://tracker.debian.org/pkg/libxslt","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.15-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.20-0ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.21-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.22-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.24","component":null,"pocket":"security"}]}],"notices_ids":["USN-633-1"],"notices":[{"id":"USN-633-1","title":"libxslt vulnerabilities","summary":"libxslt vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-08-01T14:32:08.919718","description":"It was discovered that long transformation matches in libxslt could\noverflow. If an attacker were able to make an application linked against\nlibxslt process malicious XSL style sheet input, they could execute\narbitrary code with user privileges or cause the application to crash,\nleading to a denial of serivce. (CVE-2008-1767)\n\nChris Evans discovered that the RC4 processing code in libxslt did not\ncorrectly handle corrupted key information. If a remote attacker were\nable to make an application linked against libxslt process malicious\nXML input, they could crash the application, leading to a denial of\nservice. (CVE-2008-2935)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"libxslt","version":"1.1.21-2ubuntu2.2","description":"","is_source":true},{"name":"libxslt1.1","version":"1.1.21-2ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxslt","version_link":"https://launchpad.net/ubuntu/+source/libxslt/1.1.21-2ubuntu2.2"}],"dapper":[{"name":"libxslt","version":"1.1.15-1ubuntu1.2","description":"","is_source":true},{"name":"libxslt1.1","version":"1.1.15-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxslt","version_link":"https://launchpad.net/ubuntu/+source/libxslt/1.1.15-1ubuntu1.2"}],"feisty":[{"name":"libxslt","version":"1.1.20-0ubuntu2.2","description":"","is_source":true},{"name":"libxslt1.1","version":"1.1.20-0ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxslt","version_link":"https://launchpad.net/ubuntu/+source/libxslt/1.1.20-0ubuntu2.2"}],"hardy":[{"name":"libxslt","version":"1.1.22-1ubuntu1.2","description":"","is_source":true},{"name":"libxslt1.1","version":"1.1.22-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxslt","version_link":"https://launchpad.net/ubuntu/+source/libxslt/1.1.22-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2008-1767","CVE-2008-2935"]}]},{"id":"CVE-2008-2400","published":"2008-05-22T13:09:00","updated_at":"2025-07-17T16:42:22.811865+00:00","description":"\nUnspecified vulnerability in stunnel before 4.23, when running as a service\non Windows, allows local users to gain privileges via unknown attack\nvectors.","ubuntu_description":"","notes":[{"author":"kees","note":"windows-specific"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2400"],"bugs":[""],"patches":{"stunnel4":[]},"tags":{},"packages":[{"name":"stunnel4","source":"https://ubuntu.com/security/cve?package=stunnel4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=stunnel4","debian":"https://tracker.debian.org/pkg/stunnel4","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-1804","published":"2008-05-22T13:09:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npreprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not\nproperly identify packet fragments that have dissimilar TTL values, which\nallows remote attackers to bypass detection rules by using a different TTL\nfor each fragment.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-1804"],"bugs":["https://bugs.launchpad.net/bugs/235901"],"patches":{"snort":[]},"tags":{},"packages":[{"name":"snort","source":"https://ubuntu.com/security/cve?package=snort","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=snort","debian":"https://tracker.debian.org/pkg/snort","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.7.0-22ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.8.4.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.8.5.2-2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.8.5.2-2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.8.5.2-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.8.5.2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.0-20","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5962","published":"2008-05-22T13:09:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMemory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat\nEnterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux\nand rPath appliances, allows remote attackers to cause a denial of service\n(memory consumption) via a large number of CWD commands, as demonstrated by\nan attack on a daemon with the deny_file configuration option.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5962"],"bugs":[""],"patches":{"vsftpd":[]},"tags":{},"packages":[{"name":"vsftpd","source":"https://ubuntu.com/security/cve?package=vsftpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vsftpd","debian":"https://tracker.debian.org/pkg/vsftpd","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2392","published":"2008-05-21T13:24:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnrestricted file upload vulnerability in WordPress 2.5.1 and earlier might\nallow remote authenticated administrators to upload and execute arbitrary\nPHP files via the Upload section in the Write Tabs area of the dashboard.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2392"],"bugs":[""],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.5.1-8ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.7.1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.8.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.9.1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.9.1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.9.1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.9.1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.1-4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2357","published":"2008-05-21T13:24:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the split_redraw function in split.c in mtr\nbefore 0.73, when invoked with the -p (aka --split) option, allows remote\nattackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it\ncould be argued that this is a vulnerability in the ns_name_ntop function\nin resolv/ns_name.c in glibc and the proper fix should be in glibc; if so,\nthen this should not be treated as a vulnerability in mtr.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2357"],"bugs":["https://launchpad.net/bugs/206071"],"patches":{"mtr":[]},"tags":{},"packages":[{"name":"mtr","source":"https://ubuntu.com/security/cve?package=mtr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mtr","debian":"https://tracker.debian.org/pkg/mtr","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.73","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-1950","published":"2008-05-21T13:24:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger signedness error in the _gnutls_ciphertext2compressed function in\nlib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote\nattackers to cause a denial of service (buffer over-read and crash) via a\ncertain integer value in the Random field in an encrypted Client Hello\nmessage within a TLS record with an invalid Record Length, which leads to\nan invalid cipher padding length, aka GNUTLS-SA-2008-1-3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-613-1","https://www.cve.org/CVERecord?id=CVE-2008-1950"],"bugs":[""],"patches":{"gnutls26":[],"gnutls13":[],"gnutls12":[]},"tags":{},"packages":[{"name":"gnutls12","source":"https://ubuntu.com/security/cve?package=gnutls12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls12","debian":"https://tracker.debian.org/pkg/gnutls12","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.9-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gnutls13","source":"https://ubuntu.com/security/cve?package=gnutls13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls13","debian":"https://tracker.debian.org/pkg/gnutls13","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.6.3-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.4-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gnutls26","source":"https://ubuntu.com/security/cve?package=gnutls26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls26","debian":"https://tracker.debian.org/pkg/gnutls26","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-613-1"],"notices":[{"id":"USN-613-1","title":"GnuTLS vulnerabilities","summary":"GnuTLS vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-05-21T12:47:20.409594","description":"Multiple flaws were discovered in the connection handling of GnuTLS.\nA remote attacker could exploit this to crash applications linked\nagainst GnuTLS, or possibly execute arbitrary code with permissions of\nthe application's user.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"gnutls13","version":"1.6.3-1ubuntu0.1","description":"","is_source":true},{"name":"libgnutls13","version":"1.6.3-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls13","version_link":"https://launchpad.net/ubuntu/+source/gnutls13/1.6.3-1ubuntu0.1"}],"dapper":[{"name":"gnutls12","version":"1.2.9-2ubuntu1.2","description":"","is_source":true},{"name":"libgnutls12","version":"1.2.9-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls12","version_link":"https://launchpad.net/ubuntu/+source/gnutls12/1.2.9-2ubuntu1.2"}],"feisty":[{"name":"gnutls13","version":"1.4.4-3ubuntu0.1","description":"","is_source":true},{"name":"libgnutls13","version":"1.4.4-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls13","version_link":"https://launchpad.net/ubuntu/+source/gnutls13/1.4.4-3ubuntu0.1"}],"hardy":[{"name":"gnutls13","version":"2.0.4-1ubuntu2.1","description":"","is_source":true},{"name":"libgnutls13","version":"2.0.4-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls13","version_link":"https://launchpad.net/ubuntu/+source/gnutls13/2.0.4-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2008-1948","CVE-2008-1949","CVE-2008-1950"]}]},{"id":"CVE-2008-1949","published":"2008-05-21T13:24:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls\nin gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello\nmessages within a TLS message after one has already been processed, which\nallows remote attackers to cause a denial of service (NULL dereference and\ncrash) via a TLS message containing multiple Client Hello messages, aka\nGNUTLS-SA-2008-1-2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-613-1","https://www.cve.org/CVERecord?id=CVE-2008-1949"],"bugs":[""],"patches":{"gnutls26":[],"gnutls13":[],"gnutls12":[]},"tags":{},"packages":[{"name":"gnutls12","source":"https://ubuntu.com/security/cve?package=gnutls12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls12","debian":"https://tracker.debian.org/pkg/gnutls12","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.9-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gnutls13","source":"https://ubuntu.com/security/cve?package=gnutls13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls13","debian":"https://tracker.debian.org/pkg/gnutls13","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.6.3-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.4-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gnutls26","source":"https://ubuntu.com/security/cve?package=gnutls26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls26","debian":"https://tracker.debian.org/pkg/gnutls26","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-613-1"],"notices":[{"id":"USN-613-1","title":"GnuTLS vulnerabilities","summary":"GnuTLS vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-05-21T12:47:20.409594","description":"Multiple flaws were discovered in the connection handling of GnuTLS.\nA remote attacker could exploit this to crash applications linked\nagainst GnuTLS, or possibly execute arbitrary code with permissions of\nthe application's user.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"gnutls13","version":"1.6.3-1ubuntu0.1","description":"","is_source":true},{"name":"libgnutls13","version":"1.6.3-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls13","version_link":"https://launchpad.net/ubuntu/+source/gnutls13/1.6.3-1ubuntu0.1"}],"dapper":[{"name":"gnutls12","version":"1.2.9-2ubuntu1.2","description":"","is_source":true},{"name":"libgnutls12","version":"1.2.9-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls12","version_link":"https://launchpad.net/ubuntu/+source/gnutls12/1.2.9-2ubuntu1.2"}],"feisty":[{"name":"gnutls13","version":"1.4.4-3ubuntu0.1","description":"","is_source":true},{"name":"libgnutls13","version":"1.4.4-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls13","version_link":"https://launchpad.net/ubuntu/+source/gnutls13/1.4.4-3ubuntu0.1"}],"hardy":[{"name":"gnutls13","version":"2.0.4-1ubuntu2.1","description":"","is_source":true},{"name":"libgnutls13","version":"2.0.4-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls13","version_link":"https://launchpad.net/ubuntu/+source/gnutls13/2.0.4-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2008-1948","CVE-2008-1949","CVE-2008-1950"]}]},{"id":"CVE-2008-1948","published":"2008-05-21T13:24:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe _gnutls_server_name_recv_params function in lib/ext_server_name.c in\nlibgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate\nthe number of Server Names in a TLS 1.0 Client Hello message during\nextension handling, which allows remote attackers to cause a denial of\nservice (crash) or possibly execute arbitrary code via a zero value for the\nlength of Server Names, which leads to a buffer overflow in session\nresumption data in the pack_security_parameters function, aka\nGNUTLS-SA-2008-1-1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-613-1","https://www.cve.org/CVERecord?id=CVE-2008-1948"],"bugs":[""],"patches":{"gnutls26":[],"gnutls13":[],"gnutls12":[]},"tags":{},"packages":[{"name":"gnutls12","source":"https://ubuntu.com/security/cve?package=gnutls12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls12","debian":"https://tracker.debian.org/pkg/gnutls12","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.9-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gnutls13","source":"https://ubuntu.com/security/cve?package=gnutls13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls13","debian":"https://tracker.debian.org/pkg/gnutls13","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.6.3-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.4-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gnutls26","source":"https://ubuntu.com/security/cve?package=gnutls26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls26","debian":"https://tracker.debian.org/pkg/gnutls26","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-613-1"],"notices":[{"id":"USN-613-1","title":"GnuTLS vulnerabilities","summary":"GnuTLS vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-05-21T12:47:20.409594","description":"Multiple flaws were discovered in the connection handling of GnuTLS.\nA remote attacker could exploit this to crash applications linked\nagainst GnuTLS, or possibly execute arbitrary code with permissions of\nthe application's user.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"gnutls13","version":"1.6.3-1ubuntu0.1","description":"","is_source":true},{"name":"libgnutls13","version":"1.6.3-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls13","version_link":"https://launchpad.net/ubuntu/+source/gnutls13/1.6.3-1ubuntu0.1"}],"dapper":[{"name":"gnutls12","version":"1.2.9-2ubuntu1.2","description":"","is_source":true},{"name":"libgnutls12","version":"1.2.9-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls12","version_link":"https://launchpad.net/ubuntu/+source/gnutls12/1.2.9-2ubuntu1.2"}],"feisty":[{"name":"gnutls13","version":"1.4.4-3ubuntu0.1","description":"","is_source":true},{"name":"libgnutls13","version":"1.4.4-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls13","version_link":"https://launchpad.net/ubuntu/+source/gnutls13/1.4.4-3ubuntu0.1"}],"hardy":[{"name":"gnutls13","version":"2.0.4-1ubuntu2.1","description":"","is_source":true},{"name":"libgnutls13","version":"2.0.4-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls13","version_link":"https://launchpad.net/ubuntu/+source/gnutls13/2.0.4-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2008-1948","CVE-2008-1949","CVE-2008-1950"]}]},{"id":"CVE-2008-2292","published":"2008-05-18T14:20:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the __snprint_value function in snmp_get in Net-SNMP\n5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote\nattackers to cause a denial of service (crash) and possibly execute\narbitrary code via a large OCTETSTRING in an attribute value pair (AVP).","ubuntu_description":"","notes":[{"author":"nxvl","note":"Upstream patch for 5.4 branch: http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/branches/V5-4-patches/net-snmp/perl/SNMP/SNMP.xs?r1=16765&r2=16770&view=patch"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-685-1","https://www.cve.org/CVERecord?id=CVE-2008-2292"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482333","https://bugs.edge.launchpad.net/ubuntu/+source/net-snmp/+bug/241892"],"patches":{"net-snmp":["debdiff: http://launchpad.net/bugs/241892"]},"tags":{},"packages":[{"name":"net-snmp","source":"https://ubuntu.com/security/cve?package=net-snmp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=net-snmp","debian":"https://tracker.debian.org/pkg/net-snmp","statuses":[{"release_codename":"dapper","status":"released","description":"5.2.1.2-4ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.3.1-6ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.4.1~dfsg-4ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-685-1"],"notices":[{"id":"USN-685-1","title":"Net-SNMP vulnerabilities","summary":"Net-SNMP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-12-03T22:39:34.429418","description":"Wes Hardaker discovered that the SNMP service did not correctly validate\nHMAC authentication requests. An unauthenticated remote attacker\ncould send specially crafted SNMPv3 traffic with a valid username\nand gain access to the user's views without a valid authentication\npassphrase. (CVE-2008-0960)\n\nJohn Kortink discovered that the Net-SNMP Perl module did not correctly\ncheck the size of returned values. If a user or automated system were\ntricked into querying a malicious SNMP server, the application using\nthe Perl module could be made to crash, leading to a denial of service.\nThis did not affect Ubuntu 8.10. (CVE-2008-2292)\n\nIt was discovered that the SNMP service did not correctly handle large\nGETBULK requests. If an unauthenticated remote attacker sent a specially\ncrafted request, the SNMP service could be made to crash, leading to a\ndenial of service. (CVE-2008-4309)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"net-snmp","version":"5.3.1-6ubuntu2.2","description":"","is_source":true},{"name":"libsnmp-perl","version":"5.3.1-6ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.3.1-6ubuntu2.2"},{"name":"libsnmp10","version":"5.3.1-6ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.3.1-6ubuntu2.2"}],"dapper":[{"name":"net-snmp","version":"5.2.1.2-4ubuntu2.3","description":"","is_source":true},{"name":"libsnmp-perl","version":"5.2.1.2-4ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.2.1.2-4ubuntu2.3"},{"name":"libsnmp9","version":"5.2.1.2-4ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.2.1.2-4ubuntu2.3"}],"intrepid":[{"name":"net-snmp","version":"5.4.1~dfsg-7.1ubuntu6.1","description":"","is_source":true},{"name":"libsnmp15","version":"5.4.1~dfsg-7.1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.4.1~dfsg-7.1ubuntu6.1"}],"hardy":[{"name":"net-snmp","version":"5.4.1~dfsg-4ubuntu4.2","description":"","is_source":true},{"name":"libsnmp-perl","version":"5.4.1~dfsg-4ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.4.1~dfsg-4ubuntu4.2"},{"name":"libsnmp15","version":"5.4.1~dfsg-4ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/net-snmp","version_link":"https://launchpad.net/ubuntu/+source/net-snmp/5.4.1~dfsg-4ubuntu4.2"}]},"type":"USN","cves_ids":["CVE-2008-0960","CVE-2008-2292","CVE-2008-4309"]}]},{"id":"CVE-2008-2285","published":"2008-05-18T14:20:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not\nrecognize authorized_keys lines that contain options, which makes it easier\nfor remote attackers to exploit CVE-2008-0166 by guessing a key that was\nnot identified by this tool.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-612-5","https://www.cve.org/CVERecord?id=CVE-2008-2285"],"bugs":[""],"patches":{"openssh":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"dapper","status":"released","description":"1:4.2p1-7ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1:4.3p2-8ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1:4.6p1-5ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:4.7p1-8ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-612-5"],"notices":[{"id":"USN-612-5","title":"OpenSSH update","summary":"OpenSSH update","instructions":"After performing a standard system upgrade, users are encouraged to\nre-run ssh-vulnkey on their systems.\n","references":["https://launchpad.net/bugs/230029","http://www.ubuntu.com/usn/usn-612-2"],"published":"2008-05-14T15:59:36.147035","description":"Matt Zimmerman discovered that entries in ~/.ssh/authorized_keys\nwith options (such as \"no-port-forwarding\" or forced commands) were\nignored by the new ssh-vulnkey tool introduced in OpenSSH (see\nUSN-612-2). This could cause some compromised keys not to be\nlisted in ssh-vulnkey's output.\n\nThis update also adds more information to ssh-vulnkey's manual page.\n\nOriginal advisory details:\n\n A weakness has been discovered in the random number generator used\n by OpenSSL on Debian and Ubuntu systems. As a result of this\n weakness, certain encryption keys are much more common than they\n should be, such that an attacker could guess the key through a\n brute-force attack given minimal knowledge of the system. This\n particularly affects the use of encryption keys in OpenSSH, OpenVPN\n and SSL certificates.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"openssh","version":"1:4.6p1-5ubuntu0.5","description":"","is_source":true},{"name":"openssh-client","version":"1:4.6p1-5ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.6p1-5ubuntu0.5"},{"name":"openssh-client-udeb","version":"1:4.6p1-5ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.6p1-5ubuntu0.5"}],"feisty":[{"name":"openssh","version":"1:4.3p2-8ubuntu1.4","description":"","is_source":true},{"name":"openssh-client","version":"1:4.3p2-8ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.3p2-8ubuntu1.4"},{"name":"openssh-client-udeb","version":"1:4.3p2-8ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.3p2-8ubuntu1.4"}],"hardy":[{"name":"openssh","version":"1:4.7p1-8ubuntu1.2","description":"","is_source":true},{"name":"openssh-client","version":"1:4.7p1-8ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.7p1-8ubuntu1.2"},{"name":"openssh-client-udeb","version":"1:4.7p1-8ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.7p1-8ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2008-2285"]}]},{"id":"CVE-2008-0167","published":"2008-05-18T14:20:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe write_array_file function in utils/include.pl in GForge 4.5.14 updates\nconfiguration files by truncating them to zero length and then writing new\ndata, which might allow attackers to bypass intended access restrictions or\nhave unspecified other impact in opportunistic circumstances.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0167"],"bugs":[""],"patches":{"gforge":[]},"tags":{},"packages":[{"name":"gforge","source":"https://ubuntu.com/security/cve?package=gforge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gforge","debian":"https://tracker.debian.org/pkg/gforge","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"4.6.99+svn6496-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"4.7~rc2-7lenny3build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"4.7.3-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"4.8.2-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"4.8.2-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.6.99+svn6491-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2276","published":"2008-05-16T12:54:00","updated_at":"2025-07-17T16:42:22.811865+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in manage_user_create.php\nin Mantis 1.1.1 allows remote attackers to create new administrative users\nvia a crafted link.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2276"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2266","published":"2008-05-16T12:54:00","updated_at":"2025-07-17T16:42:22.811865+00:00","description":"\nuulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and\npossibly other products, allows local users to overwrite arbitrary files\nvia a symlink attack on a temporary filename generated by the tempnam\nfunction. NOTE: this may be a CVE-2004-2265 regression.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2266"],"bugs":[""],"patches":{"libconvert-uulib-perl":[],"uudeview":[]},"tags":{},"packages":[{"name":"libconvert-uulib-perl","source":"https://ubuntu.com/security/cve?package=libconvert-uulib-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libconvert-uulib-perl","debian":"https://tracker.debian.org/pkg/libconvert-uulib-perl","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"uudeview","source":"https://ubuntu.com/security/cve?package=uudeview","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=uudeview","debian":"https://tracker.debian.org/pkg/uudeview","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2136","published":"2008-05-16T12:54:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMemory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel\n2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to\ncause a denial of service (memory consumption) via network traffic to a\nSimple Internet Transition (SIT) tunnel interface, related to the\npskb_may_pull and kfree_skb functions, and management of an skb reference\ncount.","ubuntu_description":"\nPaul Marks discovered that the SIT interfaces did not correctly manage\nallocated memory. A remote attacker could exploit this to fill all\navailable memory, leading to a denial of service.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-625-1","https://www.cve.org/CVERecord?id=CVE-2008-2136"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":["upstream: 36ca34cc3b8335eb1fe8bd9a1d0a2592980c3f02"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-19.36","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-52.69","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-17.37","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-15.56","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.26~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-625-1"],"notices":[{"id":"USN-625-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-07-15T16:42:28.816056","description":"Dirk Nehring discovered that the IPsec protocol stack did not correctly\nhandle fragmented ESP packets. A remote attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2007-6282)\n\nJohannes Bauer discovered that the 64bit kernel did not correctly handle\nhrtimer updates. A local attacker could request a large expiration value\nand cause the system to hang, leading to a denial of service.\n(CVE-2007-6712)\n\nTavis Ormandy discovered that the ia32 emulation under 64bit kernels did\nnot fully clear uninitialized data. A local attacker could read private\nkernel memory, leading to a loss of privacy. (CVE-2008-0598)\n\nJan Kratochvil discovered that PTRACE did not correctly handle certain\ncalls when running under 64bit kernels. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2008-1615)\n\nWei Wang discovered that the ASN.1 decoding routines in CIFS and SNMP NAT\ndid not correctly handle certain length values. Remote attackers could\nexploit this to execute arbitrary code or crash the system. (CVE-2008-1673)\n\nPaul Marks discovered that the SIT interfaces did not correctly manage\nallocated memory. A remote attacker could exploit this to fill all\navailable memory, leading to a denial of service. (CVE-2008-2136)\n\nDavid Miller and Jan Lieskovsky discovered that the Sparc kernel did not\ncorrectly range-check memory regions allocated with mmap. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2008-2137)\n\nThe sys_utimensat system call did not correctly check file permissions in\ncertain situations. A local attacker could exploit this to modify the file\ntimes of arbitrary files which could lead to a denial of service.\n(CVE-2008-2148)\n\nBrandon Edwards discovered that the DCCP system in the kernel did not\ncorrectly check feature lengths. A remote attacker could exploit this to\nexecute arbitrary code. (CVE-2008-2358)\n\nA race condition was discovered between ptrace and utrace in the kernel. A\nlocal attacker could exploit this to crash the system, leading to a denial\nof service. (CVE-2008-2365)\n\nThe copy_to_user routine in the kernel did not correctly clear memory\ndestination addresses when running on 64bit kernels. A local attacker could\nexploit this to gain access to sensitive kernel memory, leading to a loss\nof privacy. (CVE-2008-2729)\n\nThe PPP over L2TP routines in the kernel did not correctly handle certain\nmessages. A remote attacker could send a specially crafted packet that\ncould crash the system or execute arbitrary code. (CVE-2008-2750)\n\nGabriel Campana discovered that SCTP routines did not correctly check for\nlarge addresses. A local user could exploit this to allocate all available\nmemory, leading to a denial of service. (CVE-2008-2826)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-15.56","description":"","is_source":true},{"name":"linux-image-2.6.22-15-mckinley","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-generic","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-hppa32","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-xen","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-sparc64-smp","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-powerpc","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-itanium","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-lpiacompat","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-386","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-powerpc-smp","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-lpia","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-sparc64","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-rt","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-virtual","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-server","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-powerpc64-smp","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-hppa64","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-cell","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"},{"name":"linux-image-2.6.22-15-ume","version":"2.6.22-15.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.56"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-52.69","description":"","is_source":true},{"name":"linux-image-2.6.15-52-386","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-mckinley","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-server","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa32","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-k7","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-686","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-k8","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-server-bigiron","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-powerpc64-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-sparc64-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-itanium","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-server","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa32-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-xeon","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-mckinley-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa64-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-hppa64","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-powerpc","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-powerpc-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-amd64-generic","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-itanium-smp","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"},{"name":"linux-image-2.6.15-52-sparc64","version":"2.6.15-52.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.69"}],"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-17.37","description":"","is_source":true},{"name":"linux-image-2.6.20-17-hppa32","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-386","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-sparc64-smp","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-generic","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-hppa64","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-lowlatency","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-mckinley","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-server-bigiron","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-server","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-powerpc64-smp","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-powerpc","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-powerpc-smp","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-sparc64","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"},{"name":"linux-image-2.6.20-17-itanium","version":"2.6.20-17.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.37"}],"hardy":[{"name":"linux","version":"2.6.24-19.36","description":"","is_source":true},{"name":"linux-image-2.6.24-19-server","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-virtual","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-lpia","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-openvz","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-386","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-mckinley","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-powerpc","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-sparc64","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-sparc64-smp","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-powerpc-smp","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-itanium","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-hppa64","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-xen","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-powerpc64-smp","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-rt","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-generic","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-hppa32","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"},{"name":"linux-image-2.6.24-19-lpiacompat","version":"2.6.24-19.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-19.36"}]},"type":"USN","cves_ids":["CVE-2008-2826","CVE-2008-2729","CVE-2008-1673","CVE-2008-2137","CVE-2008-2358","CVE-2007-6282","CVE-2008-2148","CVE-2008-1615","CVE-2008-2365","CVE-2008-2750","CVE-2008-0598","CVE-2008-2136","CVE-2007-6712"]}]},{"id":"CVE-2008-1423","published":"2008-05-16T12:54:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in a certain quantvals and quantlist calculation in\nXiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a\ndenial of service (crash) or execute arbitrary code via a crafted OGG file\nwith a large virtual space for its codebook, which triggers a heap\noverflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482518","https://ubuntu.com/security/notices/USN-682-1","https://www.cve.org/CVERecord?id=CVE-2008-1423"],"bugs":["https://bugs.launchpad.net/bugs/232150"],"patches":{"libvorbis":["upstream: https://trac.xiph.org/changeset/14604","vendor: https://bugzilla.redhat.com/show_bug.cgi?id=440709","vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482518"]},"tags":{},"packages":[{"name":"libvorbis","source":"https://ubuntu.com/security/cve?package=libvorbis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvorbis","debian":"https://tracker.debian.org/pkg/libvorbis","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.2-0ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.2.0.dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.0.dfsg-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.2.0.dfsg-3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-682-1"],"notices":[{"id":"USN-682-1","title":"libvorbis vulnerabilities","summary":"libvorbis vulnerabilities","instructions":"After a standard system upgrade you need to restart any applications that\nuse libvorbis, such as Totem and gtkpod, to effect the necessary changes.\n","references":[],"published":"2008-12-01T17:08:48.659843","description":"It was discovered that libvorbis did not correctly handle certain malformed\nsound files. If a user were tricked into opening a specially crafted sound\nfile with an application that uses libvorbis, an attacker could execute\narbitrary code with the user's privileges.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"libvorbis","version":"1.2.0.dfsg-1ubuntu0.1","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-1ubuntu0.1"}],"dapper":[{"name":"libvorbis","version":"1.1.2-0ubuntu2.3","description":"","is_source":true},{"name":"libvorbis0a","version":"1.1.2-0ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.1.2-0ubuntu2.3"}],"hardy":[{"name":"libvorbis","version":"1.2.0.dfsg-2ubuntu0.1","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2008-1423","CVE-2008-1419","CVE-2008-1420"]}]},{"id":"CVE-2008-1420","published":"2008-05-16T12:54:00","updated_at":"2025-05-26T12:47:04.920981+00:00","description":"\nInteger overflow in residue partition value (aka partvals) evaluation in\nXiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute\narbitrary code via a crafted OGG file, which triggers a heap overflow.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Regression #1: https://trac.xiph.org/ticket/1456\nfixes: https://trac.xiph.org/changeset/15532\nfixes: https://trac.xiph.org/changeset/15533\nRegression #2: https://trac.xiph.org/ticket/1572\nfixes: https://trac.xiph.org/changeset/16327\nfixes: https://trac.xiph.org/changeset/16552"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482518","https://ubuntu.com/security/notices/USN-682-1","https://www.cve.org/CVERecord?id=CVE-2008-1420","https://ubuntu.com/security/notices/USN-825-1"],"bugs":["https://bugs.launchpad.net/bugs/232150"],"patches":{"libvorbis":["upstream: https://trac.xiph.org/changeset/14598","vendor: https://bugzilla.redhat.com/show_bug.cgi?id=440706","vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482518"]},"tags":{},"packages":[{"name":"libvorbis","source":"https://ubuntu.com/security/cve?package=libvorbis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvorbis","debian":"https://tracker.debian.org/pkg/libvorbis","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.2-0ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.2.0.dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.0.dfsg-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.2.0.dfsg-3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-825-1","USN-682-1"],"notices":[{"id":"USN-825-1","title":"libvorbis vulnerability","summary":"libvorbis vulnerability","instructions":"After a standard system upgrade you need to restart any applications that\nuse libvorbis, such as Totem and gtkpod, to effect the necessary changes.\n","references":[],"published":"2009-08-24T15:31:16.373829","description":"It was discovered that libvorbis did not correctly handle certain malformed\nogg files. If a user were tricked into opening a specially crafted ogg file\nwith an application that uses libvorbis, an attacker could execute\narbitrary code with the user's privileges. (CVE-2009-2663)\n\nUSN-682-1 provided updated libvorbis packages to fix multiple security\nvulnerabilities. The upstream security patch to fix CVE-2008-1420\nintroduced a regression when reading sound files encoded with libvorbis\n1.0beta1. This update corrects the problem.\n\nOriginal advisory details:\n\n It was discovered that libvorbis did not correctly handle certain\n malformed sound files. If a user were tricked into opening a specially\n crafted sound file with an application that uses libvorbis, an attacker\n could execute arbitrary code with the user's privileges. (CVE-2008-1420)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libvorbis","version":"1.2.0.dfsg-2ubuntu0.2","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-2ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-2ubuntu0.2"}],"intrepid":[{"name":"libvorbis","version":"1.2.0.dfsg-3.1ubuntu0.8.10.1","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-3.1ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-3.1ubuntu0.8.10.1"}],"jaunty":[{"name":"libvorbis","version":"1.2.0.dfsg-3.1ubuntu0.9.04.1","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-3.1ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-3.1ubuntu0.9.04.1"}]},"type":"USN","cves_ids":["CVE-2008-1420","CVE-2009-2663"]},{"id":"USN-682-1","title":"libvorbis vulnerabilities","summary":"libvorbis vulnerabilities","instructions":"After a standard system upgrade you need to restart any applications that\nuse libvorbis, such as Totem and gtkpod, to effect the necessary changes.\n","references":[],"published":"2008-12-01T17:08:48.659843","description":"It was discovered that libvorbis did not correctly handle certain malformed\nsound files. If a user were tricked into opening a specially crafted sound\nfile with an application that uses libvorbis, an attacker could execute\narbitrary code with the user's privileges.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"libvorbis","version":"1.2.0.dfsg-1ubuntu0.1","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-1ubuntu0.1"}],"dapper":[{"name":"libvorbis","version":"1.1.2-0ubuntu2.3","description":"","is_source":true},{"name":"libvorbis0a","version":"1.1.2-0ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.1.2-0ubuntu2.3"}],"hardy":[{"name":"libvorbis","version":"1.2.0.dfsg-2ubuntu0.1","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2008-1423","CVE-2008-1419","CVE-2008-1420"]}]},{"id":"CVE-2008-1419","published":"2008-05-16T12:54:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nXiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value\nfor codebook.dim, which allows remote attackers to cause a denial of\nservice (crash or infinite loop) or trigger an integer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482518","https://ubuntu.com/security/notices/USN-682-1","https://www.cve.org/CVERecord?id=CVE-2008-1419"],"bugs":["https://bugs.launchpad.net/bugs/232150"],"patches":{"libvorbis":["upstream: https://trac.xiph.org/changeset/14602","vendor: https://bugzilla.redhat.com/show_bug.cgi?id=440700","vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482518"]},"tags":{},"packages":[{"name":"libvorbis","source":"https://ubuntu.com/security/cve?package=libvorbis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvorbis","debian":"https://tracker.debian.org/pkg/libvorbis","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.2-0ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.2.0.dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.0.dfsg-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.2.0.dfsg-3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-682-1"],"notices":[{"id":"USN-682-1","title":"libvorbis vulnerabilities","summary":"libvorbis vulnerabilities","instructions":"After a standard system upgrade you need to restart any applications that\nuse libvorbis, such as Totem and gtkpod, to effect the necessary changes.\n","references":[],"published":"2008-12-01T17:08:48.659843","description":"It was discovered that libvorbis did not correctly handle certain malformed\nsound files. If a user were tricked into opening a specially crafted sound\nfile with an application that uses libvorbis, an attacker could execute\narbitrary code with the user's privileges.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"libvorbis","version":"1.2.0.dfsg-1ubuntu0.1","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-1ubuntu0.1"}],"dapper":[{"name":"libvorbis","version":"1.1.2-0ubuntu2.3","description":"","is_source":true},{"name":"libvorbis0a","version":"1.1.2-0ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.1.2-0ubuntu2.3"}],"hardy":[{"name":"libvorbis","version":"1.2.0.dfsg-2ubuntu0.1","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2008-1423","CVE-2008-1419","CVE-2008-1420"]}]},{"id":"CVE-2008-2009","published":"2008-05-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nXiph.org libvorbis before 1.0 does not properly check for underpopulated\nHuffman trees, which allows remote attackers to cause a denial of service\n(crash) via a crafted OGG file that triggers memory corruption during\nexecution of the _make_decode_tree function.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"description is misleading, part of the patch applies to\nrecent versions."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=444443","https://ubuntu.com/security/notices/USN-861-1","https://www.cve.org/CVERecord?id=CVE-2008-2009"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482039","https://bugzilla.redhat.com/show_bug.cgi?id=444443"],"patches":{"libvorbis":["upstream: https://trac.xiph.org/changeset/2959","upstream: https://trac.xiph.org/changeset/2960","upstream: https://trac.xiph.org/changeset/14811"]},"tags":{},"packages":[{"name":"libvorbis","source":"https://ubuntu.com/security/cve?package=libvorbis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvorbis","debian":"https://tracker.debian.org/pkg/libvorbis","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.0.dfsg-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.2.0.dfsg-3.1ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.2.0.dfsg-3.1ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.2.0.dfsg-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-861-1"],"notices":[{"id":"USN-861-1","title":"libvorbis vulnerabilities","summary":"libvorbis vulnerabilities","instructions":"After a standard system upgrade you need to restart any applications that\nuse libvorbis, such as Totem and gtkpod, to effect the necessary changes.\n","references":[],"published":"2009-11-24T13:19:42.144185","description":"It was discovered that libvorbis did not correctly handle ogg files with\nunderpopulated Huffman trees. If a user were tricked into opening a\nspecially crafted ogg file with an application that uses libvorbis, an\nattacker could cause a denial of service. (CVE-2008-2009)\n\nIt was discovered that libvorbis did not correctly handle certain malformed\nogg files. If a user were tricked into opening a specially crafted ogg file\nwith an application that uses libvorbis, an attacker could cause a denial\nof service or possibly execute arbitrary code with the user's privileges.\n(CVE-2009-3379)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"libvorbis","version":"1.2.0.dfsg-2ubuntu0.3","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-2ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-2ubuntu0.3"}],"intrepid":[{"name":"libvorbis","version":"1.2.0.dfsg-3.1ubuntu0.8.10.2","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-3.1ubuntu0.8.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-3.1ubuntu0.8.10.2"}],"jaunty":[{"name":"libvorbis","version":"1.2.0.dfsg-3.1ubuntu0.9.04.2","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-3.1ubuntu0.9.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-3.1ubuntu0.9.04.2"}],"karmic":[{"name":"libvorbis","version":"1.2.0.dfsg-6ubuntu0.1","description":"","is_source":true},{"name":"libvorbis0a","version":"1.2.0.dfsg-6ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.2.0.dfsg-6ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2008-2009","CVE-2009-3379"]}]}],"offset":75360,"limit":20,"total_results":79316}