{"cves":[{"id":"CVE-2007-6698","published":"2008-02-01T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe BDB backend for slapd in OpenLDAP before 2.3.36 allows remote\nauthenticated users to cause a denial of service (crash) via a\npotentially-successful modify operation with the NOOP control set to\ncritical, possibly due to a double free vulnerability.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"openldap2 source package does not ship slapd"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-584-1","https://www.cve.org/CVERecord?id=CVE-2007-6698"],"bugs":["https://bugs.launchpad.net/bugs/197077"],"patches":{"openldap2.3":["vendor: https://rhn.redhat.com/errata/RHSA-2008-0110.html"],"openldap2.2":[],"openldap2":[]},"tags":{},"packages":[{"name":"openldap2","source":"https://ubuntu.com/security/cve?package=openldap2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap2","debian":"https://tracker.debian.org/pkg/openldap2","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openldap2.2","source":"https://ubuntu.com/security/cve?package=openldap2.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap2.2","debian":"https://tracker.debian.org/pkg/openldap2.2","statuses":[{"release_codename":"dapper","status":"released","description":"2.2.26-5ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.2.26-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openldap2.3","source":"https://ubuntu.com/security/cve?package=openldap2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openldap2.3","debian":"https://tracker.debian.org/pkg/openldap2.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.3.30-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.3.35-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-584-1"],"notices":[{"id":"USN-584-1","title":"OpenLDAP vulnerabilities","summary":"OpenLDAP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-03-05T20:47:43.012960","description":"Jonathan Clarke discovered that the OpenLDAP slapd server did not\nproperly handle modify requests when using the Berkeley DB backend\nand specifying the NOOP control. An authenticated user with modify\npermissions could send a crafted modify request and cause a denial\nof service via application crash. Ubuntu 7.10 is not affected by\nthis issue. (CVE-2007-6698)\n\nRalf Haferkamp discovered that the OpenLDAP slapd server did not\nproperly handle modrdn requests when using the Berkeley DB backend\nand specifying the NOOP control. An authenticated user with modrdn\npermissions could send a crafted modrdn request and possibly cause a\ndenial of service via application crash. (CVE-2007-6698)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"openldap2.3","version":"2.3.35-1ubuntu0.2","description":"","is_source":true},{"name":"slapd","version":"2.3.35-1ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openldap2.3","version_link":"https://launchpad.net/ubuntu/+source/openldap2.3/2.3.35-1ubuntu0.2"}],"dapper":[{"name":"openldap2.2","version":"2.2.26-5ubuntu2.6","description":"","is_source":true},{"name":"slapd","version":"2.2.26-5ubuntu2.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openldap2.2","version_link":"https://launchpad.net/ubuntu/+source/openldap2.2/2.2.26-5ubuntu2.6"}],"feisty":[{"name":"openldap2.3","version":"2.3.30-2ubuntu0.2","description":"","is_source":true},{"name":"slapd","version":"2.3.30-2ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openldap2.3","version_link":"https://launchpad.net/ubuntu/+source/openldap2.3/2.3.30-2ubuntu0.2"}],"edgy":[{"name":"openldap2.2","version":"2.2.26-5ubuntu3.3","description":"","is_source":true},{"name":"slapd","version":"2.2.26-5ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openldap2.2","version_link":"https://launchpad.net/ubuntu/+source/openldap2.2/2.2.26-5ubuntu3.3"}]},"type":"USN","cves_ids":["CVE-2007-6698","CVE-2008-0658"]}]},{"id":"CVE-2008-0544","published":"2008-02-01T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the IMG_LoadLBM_RW function in IMG_lbm.c in\nSDL_image before 1.2.7 allows remote attackers to cause a denial of service\n(application crash) or possibly execute arbitrary code via a crafted IFF\nILBM file. NOTE: some of these details are obtained from third party\ninformation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-595-1","https://www.cve.org/CVERecord?id=CVE-2008-0544"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/sdl-image1.2/+bug/185782"],"patches":{"sdl-image1.2":["vendor: http://www.debian.org/security/2008/dsa-1493","debdiff: https://bugs.launchpad.net/ubuntu/+source/sdl-image1.2/+bug/185782"]},"tags":{},"packages":[{"name":"sdl-image1.2","source":"https://ubuntu.com/security/cve?package=sdl-image1.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sdl-image1.2","debian":"https://tracker.debian.org/pkg/sdl-image1.2","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.4-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.5-2ubuntu0.6.10.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.5-2ubuntu0.7.04.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.2.5-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-595-1"],"notices":[{"id":"USN-595-1","title":"SDL_image vulnerabilities","summary":"SDL_image vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-03-26T18:18:42.175735","description":"Michael Skladnikiewicz discovered that SDL_image did not correctly load\nGIF images. If a user or automated system were tricked into processing\na specially crafted GIF, a remote attacker could execute arbitrary code\nor cause a crash, leading to a denial of service. (CVE-2007-6697)\n\nDavid Raulo discovered that SDL_image did not correctly load ILBM images.\nIf a user or automated system were tricked into processing a specially\ncrafted ILBM, a remote attacker could execute arbitrary code or cause\na crash, leading to a denial of service. (CVE-2008-0544)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"sdl-image1.2","version":"1.2.5-3ubuntu0.1","description":"","is_source":true},{"name":"libsdl-image1.2","version":"1.2.5-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2","version_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2/1.2.5-3ubuntu0.1"}],"dapper":[{"name":"sdl-image1.2","version":"1.2.4-1ubuntu0.1","description":"","is_source":true},{"name":"libsdl-image1.2","version":"1.2.4-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2","version_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2/1.2.4-1ubuntu0.1"}],"feisty":[{"name":"sdl-image1.2","version":"1.2.5-2ubuntu0.7.04.1","description":"","is_source":true},{"name":"libsdl-image1.2","version":"1.2.5-2ubuntu0.7.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2","version_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2/1.2.5-2ubuntu0.7.04.1"}],"edgy":[{"name":"sdl-image1.2","version":"1.2.5-2ubuntu0.6.10.1","description":"","is_source":true},{"name":"libsdl-image1.2","version":"1.2.5-2ubuntu0.6.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2","version_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2/1.2.5-2ubuntu0.6.10.1"}]},"type":"USN","cves_ids":["CVE-2007-6697","CVE-2008-0544"]}]},{"id":"CVE-2007-6697","published":"2008-02-01T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the LWZReadByte function in IMG_gif.c in SDL_image\nbefore 1.2.7 allows remote attackers to cause a denial of service\n(application crash) or possibly execute arbitrary code via a crafted GIF\nfile, a similar issue to CVE-2006-4484. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-595-1","https://www.cve.org/CVERecord?id=CVE-2007-6697"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/sdl-image1.2/+bug/185782"],"patches":{"sdl-image1.2":["vendor: http://www.debian.org/security/2008/dsa-1493","debdiff: https://bugs.launchpad.net/ubuntu/+source/sdl-image1.2/+bug/185782"],"swi-prolog":["upstream: http://www.swi-prolog.org/git/packages/xpce.git/commit/785efb7b94d28c7dbb5b4f2b6f5a908092cf7652"]},"tags":{},"packages":[{"name":"sdl-image1.2","source":"https://ubuntu.com/security/cve?package=sdl-image1.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sdl-image1.2","debian":"https://tracker.debian.org/pkg/sdl-image1.2","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"1.2.4-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.5-2ubuntu0.6.10.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.5-2ubuntu0.7.04.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.2.5-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.6-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"swi-prolog","source":"https://ubuntu.com/security/cve?package=swi-prolog","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swi-prolog","debian":"https://tracker.debian.org/pkg/swi-prolog","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":["USN-595-1"],"notices":[{"id":"USN-595-1","title":"SDL_image vulnerabilities","summary":"SDL_image vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-03-26T18:18:42.175735","description":"Michael Skladnikiewicz discovered that SDL_image did not correctly load\nGIF images. If a user or automated system were tricked into processing\na specially crafted GIF, a remote attacker could execute arbitrary code\nor cause a crash, leading to a denial of service. (CVE-2007-6697)\n\nDavid Raulo discovered that SDL_image did not correctly load ILBM images.\nIf a user or automated system were tricked into processing a specially\ncrafted ILBM, a remote attacker could execute arbitrary code or cause\na crash, leading to a denial of service. (CVE-2008-0544)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"sdl-image1.2","version":"1.2.5-3ubuntu0.1","description":"","is_source":true},{"name":"libsdl-image1.2","version":"1.2.5-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2","version_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2/1.2.5-3ubuntu0.1"}],"dapper":[{"name":"sdl-image1.2","version":"1.2.4-1ubuntu0.1","description":"","is_source":true},{"name":"libsdl-image1.2","version":"1.2.4-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2","version_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2/1.2.4-1ubuntu0.1"}],"feisty":[{"name":"sdl-image1.2","version":"1.2.5-2ubuntu0.7.04.1","description":"","is_source":true},{"name":"libsdl-image1.2","version":"1.2.5-2ubuntu0.7.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2","version_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2/1.2.5-2ubuntu0.7.04.1"}],"edgy":[{"name":"sdl-image1.2","version":"1.2.5-2ubuntu0.6.10.1","description":"","is_source":true},{"name":"libsdl-image1.2","version":"1.2.5-2ubuntu0.6.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2","version_link":"https://launchpad.net/ubuntu/+source/sdl-image1.2/1.2.5-2ubuntu0.6.10.1"}]},"type":"USN","cves_ids":["CVE-2007-6697","CVE-2008-0544"]}]},{"id":"CVE-2007-6696","published":"2008-02-01T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6\nallow remote attackers to inject arbitrary web script or HTML via (1) an\nevent description, (2) the query string to pref.php, and (3) the adv\nparameter to search.php. NOTE: vector 1 requires user authentication.","ubuntu_description":"","notes":[{"author":"fujitsu","note":"None of the three vulnerabilities are present in Debian's 1.0.x.\nSee the Debian bug for explanation."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-6696"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=457781"],"patches":{"webcalendar":[]},"tags":{},"packages":[{"name":"webcalendar","source":"https://ubuntu.com/security/cve?package=webcalendar","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webcalendar","debian":"https://tracker.debian.org/pkg/webcalendar","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4998","published":"2008-01-31T21:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncp, when running with an option to preserve symlinks on multiple OSes,\nallows local, user-assisted attackers to overwrite arbitrary files via a\nsymlink attack using crafted directories containing multiple source files\nthat are copied to the same destination.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu coreutils should not be affected. This problem is many years\nold. busybox 1.6.1 and 1.9.0 known not to be affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4998"],"bugs":[""],"patches":{"coreutils":[],"busybox":[]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"coreutils","source":"https://ubuntu.com/security/cve?package=coreutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=coreutils","debian":"https://tracker.debian.org/pkg/coreutils","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0471","published":"2008-01-29T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB\n2.0.22 allows remote attackers to delete private messages (PM) as arbitrary\nusers via a deleteall action.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0471"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpbb2/+bug/191201"],"patches":{"phpbb2":["vendor: http://www.debian.org/security/2008/dsa-1488"]},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.22-3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.22-3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-6694","published":"2008-01-29T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe chrp_show_cpuinfo function (chrp/setup.c) in Linux kernel 2.4.21\nthrough 2.6.18-53, when running on PowerPC, might allow local users to\ncause a denial of service (crash) via unknown vectors that cause the\nof_get_property function to fail, which triggers a NULL pointer\ndereference.","ubuntu_description":"","notes":[{"author":"kees","note":"not actually a security issue"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-614-1","https://ubuntu.com/security/notices/USN-618-1","https://www.cve.org/CVERecord?id=CVE-2007-6694"],"bugs":["https://bugs.launchpad.net/bugs/227315"],"patches":{"linux-source-2.6.15":[],"linux-source-2.6.17":[],"linux-source-2.6.20":[],"linux-source-2.6.22":[],"linux":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-18.32","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-52.67","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-17.36","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-15.54","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-614-1","USN-618-1"],"notices":[{"id":"USN-614-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2008-06-03T18:17:51.918260","description":"It was discovered that PowerPC kernels did not correctly handle reporting\ncertain system details. By requesting a specific set of information,\na local attacker could cause a system crash resulting in a denial\nof service. (CVE-2007-6694)\n\nA race condition was discovered between dnotify fcntl() and close() in\nthe kernel. If a local attacker performed malicious dnotify requests,\nthey could cause memory consumption leading to a denial of service,\nor possibly send arbitrary signals to any process. (CVE-2008-1375)\n\nOn SMP systems, a race condition existed in fcntl(). Local attackers\ncould perform malicious locks, causing system crashes and leading to\na denial of service. (CVE-2008-1669)\n\nThe tehuti network driver did not correctly handle certain IO functions.\nA local attacker could perform malicious requests to the driver,\npotentially accessing kernel memory, leading to privilege escalation\nor access to private system information. (CVE-2008-1675)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-18.32","description":"","is_source":true},{"name":"linux-image-2.6.24-18-lpiacompat","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-hppa32","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-sparc64-smp","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-xen","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-powerpc-smp","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-hppa64","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-powerpc64-smp","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-openvz","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-virtual","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-rt","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-generic","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-lpia","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-powerpc","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-mckinley","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-sparc64","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-server","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-386","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"},{"name":"linux-image-2.6.24-18-itanium","version":"2.6.24-18.32","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-18.32"}]},"type":"USN","cves_ids":["CVE-2007-6694","CVE-2008-1375","CVE-2008-1669","CVE-2008-1675"]},{"id":"USN-618-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2008-06-19T16:50:49.119001","description":"It was discovered that the ALSA /proc interface did not write the\ncorrect number of bytes when reporting memory allocations. A local\nattacker might be able to access sensitive kernel memory, leading to\na loss of privacy. (CVE-2007-4571)\n\nMultiple buffer overflows were discovered in the handling of CIFS\nfilesystems. A malicious CIFS server could cause a client system crash\nor possibly execute arbitrary code with kernel privileges. (CVE-2007-5904)\n\nIt was discovered that PowerPC kernels did not correctly handle reporting\ncertain system details. By requesting a specific set of information,\na local attacker could cause a system crash resulting in a denial\nof service. (CVE-2007-6694)\n\nIt was discovered that some device driver fault handlers did not\ncorrectly verify memory ranges. A local attacker could exploit this\nto access sensitive kernel memory, possibly leading to a loss of privacy.\n(CVE-2008-0007)\n\nIt was discovered that CPU resource limits could be bypassed.\nA malicious local user could exploit this to avoid administratively\nimposed resource limits. (CVE-2008-1294)\n\nA race condition was discovered between dnotify fcntl() and close() in\nthe kernel. If a local attacker performed malicious dnotify requests,\nthey could cause memory consumption leading to a denial of service,\nor possibly send arbitrary signals to any process. (CVE-2008-1375)\n\nOn SMP systems, a race condition existed in fcntl(). Local attackers\ncould perform malicious locks, causing system crashes and leading to\na denial of service. (CVE-2008-1669)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-backports-modules-2.6.22","version":"2.6.22-15.16","description":"","is_source":true},{"name":"linux-ubuntu-modules-2.6.22","version":"2.6.22-15.39","description":"","is_source":true},{"name":"linux-restricted-modules-2.6.22","version":"2.6.22.4-15.11","description":"","is_source":true},{"name":"linux-source-2.6.22","version":"2.6.22-15.54","description":"","is_source":true},{"name":"linux-image-2.6.22-15-mckinley","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-generic","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-hppa32","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-xen","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-sparc64-smp","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-powerpc","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-itanium","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-lpiacompat","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-386","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-powerpc-smp","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-lpia","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-sparc64","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-rt","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-virtual","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-server","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-powerpc64-smp","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-hppa64","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-cell","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"},{"name":"linux-image-2.6.22-15-ume","version":"2.6.22-15.54","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-15.54"}],"dapper":[{"name":"linux-restricted-modules-2.6.15","version":"2.6.15.12-52.3","description":"","is_source":true},{"name":"linux-source-2.6.15","version":"2.6.15-52.67","description":"","is_source":true},{"name":"linux-backports-modules-2.6.15","version":"2.6.15-52.10","description":"","is_source":true},{"name":"linux-image-2.6.15-52-386","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-mckinley","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-amd64-server","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-hppa32","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-k7","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-686","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-amd64-k8","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-server-bigiron","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-powerpc64-smp","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-sparc64-smp","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-itanium","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-server","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-hppa32-smp","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-amd64-xeon","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-mckinley-smp","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-hppa64-smp","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-hppa64","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-powerpc","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-powerpc-smp","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-amd64-generic","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-itanium-smp","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"},{"name":"linux-image-2.6.15-52-sparc64","version":"2.6.15-52.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-52.67"}],"feisty":[{"name":"linux-restricted-modules-2.6.20","version":"2.6.20.6-17.31","description":"","is_source":true},{"name":"linux-backports-modules-2.6.20","version":"2.6.20-17.12","description":"","is_source":true},{"name":"linux-source-2.6.20","version":"2.6.20-17.36","description":"","is_source":true},{"name":"linux-image-2.6.20-17-hppa32","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-386","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-sparc64-smp","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-generic","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-hppa64","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-lowlatency","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-mckinley","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-server-bigiron","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-server","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-powerpc64-smp","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-powerpc","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-powerpc-smp","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-sparc64","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"},{"name":"linux-image-2.6.20-17-itanium","version":"2.6.20-17.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-17.36"}]},"type":"USN","cves_ids":["CVE-2007-4571","CVE-2007-5904","CVE-2007-6694","CVE-2008-0007","CVE-2008-1294","CVE-2008-1375","CVE-2008-1669"]}]},{"id":"CVE-2008-0467","published":"2008-01-29T02:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before\n2.1.0 RC1, might allow remote attackers to execute arbitrary code via a\nlong username.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0467"],"bugs":[""],"patches":{"firebird2.0":[],"firebird2":[]},"tags":{},"packages":[{"name":"firebird2","source":"https://ubuntu.com/security/cve?package=firebird2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2","debian":"https://tracker.debian.org/pkg/firebird2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"firebird2.0","source":"https://ubuntu.com/security/cve?package=firebird2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2.0","debian":"https://tracker.debian.org/pkg/firebird2.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.3.12981.ds1-5","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.3.12981.ds1-5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0387","published":"2008-01-29T02:00:00","updated_at":"2025-07-17T16:42:18.994089+00:00","description":"\nInteger overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6,\n2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers\nto execute arbitrary code via crafted (1) op_receive, (2) op_start, (3)\nop_start_and_receive, (4) op_send, (5) op_start_and_send, and (6)\nop_start_send_and_receive XDR requests, which triggers memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0387"],"bugs":[""],"patches":{"firebird2.0":[],"firebird2":[]},"tags":{},"packages":[{"name":"firebird2","source":"https://ubuntu.com/security/cve?package=firebird2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2","debian":"https://tracker.debian.org/pkg/firebird2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"firebird2.0","source":"https://ubuntu.com/security/cve?package=firebird2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2.0","debian":"https://tracker.debian.org/pkg/firebird2.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.3.12981.ds1-4","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.3.12981.ds1-4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.3.12981.ds1-4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.3.12981.ds1-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0008","published":"2008-01-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build,\ndoes not check return values from (1) setresuid, (2) setreuid, (3) setuid,\nand (4) seteuid calls when attempting to drop privileges, which might allow\nlocal users to gain privileges by causing those calls to fail via attacks\nsuch as resource exhaustion.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"not possible to exploit in default installation. In fact, need an\nLSM to fail the call and then not protect the binary properly, so this is\nalmost a non-issue on Ubuntu\npatched prepared"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-573-1","https://www.cve.org/CVERecord?id=CVE-2008-0008"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/pulseaudio/+bug/185534","https://bugs.launchpad.net/ubuntu/+source/pulseaudio/+bug/186571"],"patches":{"pulseaudio":["vendor: http://www.debian.org/security/2008/dsa-1476","vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:027"]},"tags":{},"packages":[{"name":"pulseaudio","source":"https://ubuntu.com/security/cve?package=pulseaudio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pulseaudio","debian":"https://tracker.debian.org/pkg/pulseaudio","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.9.5-5ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.9.6-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.9","component":null,"pocket":"security"}]}],"notices_ids":["USN-573-1"],"notices":[{"id":"USN-573-1","title":"PulseAudio vulnerability","summary":"PulseAudio vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-01-31T20:21:31.129339","description":"It was discovered that PulseAudio did not properly drop privileges\nwhen running as a daemon. Local users may be able to exploit this\nand gain privileges. The default Ubuntu configuration is not\naffected.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"pulseaudio","version":"0.9.6-1ubuntu2.1","description":"","is_source":true},{"name":"pulseaudio","version":"0.9.6-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pulseaudio","version_link":"https://launchpad.net/ubuntu/+source/pulseaudio/0.9.6-1ubuntu2.1"}],"feisty":[{"name":"pulseaudio","version":"0.9.5-5ubuntu4.2","description":"","is_source":true},{"name":"pulseaudio","version":"0.9.5-5ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pulseaudio","version_link":"https://launchpad.net/ubuntu/+source/pulseaudio/0.9.5-5ubuntu4.2"}]},"type":"USN","cves_ids":["CVE-2008-0008"]}]},{"id":"CVE-2007-4771","published":"2008-01-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the doInterval function in regexcmp.cpp in\nlibicu in International Components for Unicode (ICU) 3.8.1 and earlier\nallows context-dependent attackers to cause a denial of service (memory\nconsumption) and possibly have unspecified other impact via a regular\nexpression that writes a large amount of data to the backtracking stack.\nNOTE: some of these details are obtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-591-1","https://www.cve.org/CVERecord?id=CVE-2007-4771"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/icu/+bug/186578"],"patches":{"icu":["vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:026","vendor: https://rhn.redhat.com/errata/RHSA-2008-0090.html","vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463688","other: http://sourceforge.net/mailarchive/message.php?msg_name=d03a2ffb0801221538x68825e42xb4a4aaf0fcccecbd%40mail.gmail.com"]},"tags":{},"packages":[{"name":"icu","source":"https://ubuntu.com/security/cve?package=icu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icu","debian":"https://tracker.debian.org/pkg/icu","statuses":[{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"3.4.1a-1ubuntu1.6.06.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.4.1a-1ubuntu1.6.10.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.6-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-591-1"],"notices":[{"id":"USN-591-1","title":"libicu vulnerabilities","summary":"libicu vulnerabilities","instructions":"After a standard system upgrade you need to restart applications linked\nagainst libicu, such as OpenOffice.org, to effect the necessary changes.\n","references":[],"published":"2008-03-24T18:02:14.928607","description":"Will Drewry discovered that libicu did not properly handle '\\0' when\nprocessing regular expressions. If an application linked against libicu\nprocessed a crafted regular expression, an attacker could execute\narbitrary code with privileges of the user invoking the program.\n(CVE-2007-4770)\n\nWill Drewry discovered that libicu did not properly limit its\nbacktracking stack size. If an application linked against libicu\nprocessed a crafted regular expression, an attacker could cause a denial\nof service via resource exhaustion. (CVE-2007-4771)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"icu","version":"3.6-3ubuntu0.1","description":"","is_source":true},{"name":"libicu36","version":"3.6-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icu","version_link":"https://launchpad.net/ubuntu/+source/icu/3.6-3ubuntu0.1"}],"dapper":[{"name":"icu","version":"3.4.1a-1ubuntu1.6.06.1","description":"","is_source":true},{"name":"libicu34","version":"3.4.1a-1ubuntu1.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icu","version_link":"https://launchpad.net/ubuntu/+source/icu/3.4.1a-1ubuntu1.6.06.1"}],"feisty":[{"name":"icu","version":"3.6-2ubuntu0.1","description":"","is_source":true},{"name":"libicu36","version":"3.6-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icu","version_link":"https://launchpad.net/ubuntu/+source/icu/3.6-2ubuntu0.1"}],"edgy":[{"name":"icu","version":"3.4.1a-1ubuntu1.6.10.1","description":"","is_source":true},{"name":"libicu34","version":"3.4.1a-1ubuntu1.6.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icu","version_link":"https://launchpad.net/ubuntu/+source/icu/3.4.1a-1ubuntu1.6.10.1"}]},"type":"USN","cves_ids":["CVE-2007-4770","CVE-2007-4771"]}]},{"id":"CVE-2007-4770","published":"2008-01-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibicu in International Components for Unicode (ICU) 3.8.1 and earlier\nattempts to process backreferences to the nonexistent capture group zero\n(aka \\0), which might allow context-dependent attackers to read from, or\nwrite to, out-of-bounds memory locations, related to corruption of\nREStackFrames.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-591-1","https://www.cve.org/CVERecord?id=CVE-2007-4770"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/icu/+bug/186578"],"patches":{"icu":["vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:026","vendor: https://rhn.redhat.com/errata/RHSA-2008-0090.html","vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463688","other: http://sourceforge.net/mailarchive/message.php?msg_name=d03a2ffb0801221538x68825e42xb4a4aaf0fcccecbd%40mail.gmail.com"]},"tags":{},"packages":[{"name":"icu","source":"https://ubuntu.com/security/cve?package=icu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icu","debian":"https://tracker.debian.org/pkg/icu","statuses":[{"release_codename":"dapper","status":"released","description":"3.4.1a-1ubuntu1.6.06.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.4.1a-1ubuntu1.6.10.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.6-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"3.6-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-591-1"],"notices":[{"id":"USN-591-1","title":"libicu vulnerabilities","summary":"libicu vulnerabilities","instructions":"After a standard system upgrade you need to restart applications linked\nagainst libicu, such as OpenOffice.org, to effect the necessary changes.\n","references":[],"published":"2008-03-24T18:02:14.928607","description":"Will Drewry discovered that libicu did not properly handle '\\0' when\nprocessing regular expressions. If an application linked against libicu\nprocessed a crafted regular expression, an attacker could execute\narbitrary code with privileges of the user invoking the program.\n(CVE-2007-4770)\n\nWill Drewry discovered that libicu did not properly limit its\nbacktracking stack size. If an application linked against libicu\nprocessed a crafted regular expression, an attacker could cause a denial\nof service via resource exhaustion. (CVE-2007-4771)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"icu","version":"3.6-3ubuntu0.1","description":"","is_source":true},{"name":"libicu36","version":"3.6-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icu","version_link":"https://launchpad.net/ubuntu/+source/icu/3.6-3ubuntu0.1"}],"dapper":[{"name":"icu","version":"3.4.1a-1ubuntu1.6.06.1","description":"","is_source":true},{"name":"libicu34","version":"3.4.1a-1ubuntu1.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icu","version_link":"https://launchpad.net/ubuntu/+source/icu/3.4.1a-1ubuntu1.6.06.1"}],"feisty":[{"name":"icu","version":"3.6-2ubuntu0.1","description":"","is_source":true},{"name":"libicu36","version":"3.6-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icu","version_link":"https://launchpad.net/ubuntu/+source/icu/3.6-2ubuntu0.1"}],"edgy":[{"name":"icu","version":"3.4.1a-1ubuntu1.6.10.1","description":"","is_source":true},{"name":"libicu34","version":"3.4.1a-1ubuntu1.6.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icu","version_link":"https://launchpad.net/ubuntu/+source/icu/3.4.1a-1ubuntu1.6.10.1"}]},"type":"USN","cves_ids":["CVE-2007-4770","CVE-2007-4771"]}]},{"id":"CVE-2008-0460","published":"2008-01-25T16:00:00","updated_at":"2025-07-17T16:42:18.994089+00:00","description":"\nCross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11\nthrough 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2)\nthe BotQuery extension for MediaWiki 1.7 and earlier; when Internet\nExplorer is used, allows remote attackers to inject arbitrary web script or\nHTML via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0460"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1:1.11.1-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1:1.11.1-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1:1.11.1-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1:1.11.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0456","published":"2008-01-25T01:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCRLF injection vulnerability in the mod_negotiation module in the Apache\nHTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in\nthe 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote\nauthenticated users to inject arbitrary HTTP headers and conduct HTTP\nresponse splitting attacks by uploading a file with a multi-line name\ncontaining HTTP header sequences and a file extension, which leads to\ninjection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\"\nHTTP response when the extension is omitted in a request for the file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Doesn't appear to be fixed by upstream or by vendors as of 2009-02-23\nNeed to be able to create a file with a special filename. If you can\ndo that, you can put the XSS directly in the file...so this isn't\nreally a security issue.\nSee: http://mail-archives.apache.org/mod_mbox/httpd-dev/200802.mbox/%3CFDD5D99066749040AF9098A720E98977080B7263@CIWMEXZSA0E.ex.ordersx.org%3E"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0456"],"bugs":[""],"patches":{"apache":[],"apache2":[]},"tags":{},"packages":[{"name":"apache","source":"https://ubuntu.com/security/cve?package=apache","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache","debian":"https://tracker.debian.org/pkg/apache","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0455","published":"2008-01-25T01:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the mod_negotiation module in\nthe Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and\nearlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series\nallows remote authenticated users to inject arbitrary web script or HTML by\nuploading a file with a name containing XSS sequences and a file extension,\nwhich leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300\nMultiple Choices\" HTTP response when the extension is omitted in a request\nfor the file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Doesn't appear to be fixed by upstream or by vendors as of 2009-02-23\nNeed to be able to create a file with a special filename. If you can\ndo that, you can put the XSS directly in the file...so this isn't\nreally a security issue.\nSee: http://mail-archives.apache.org/mod_mbox/httpd-dev/200802.mbox/%3CFDD5D99066749040AF9098A720E98977080B7263@CIWMEXZSA0E.ex.ordersx.org%3E"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0455"],"bugs":[""],"patches":{"apache":[],"apache2":[]},"tags":{},"packages":[{"name":"apache","source":"https://ubuntu.com/security/cve?package=apache","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache","debian":"https://tracker.debian.org/pkg/apache","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"1.3.39","component":null,"pocket":"security"}]},{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"2.2.6, 2.0.61","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0445","published":"2008-01-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe replace_inline_img function in elogd in Electronic Logbook (ELOG)\nbefore 2.7.1 allows remote attackers to cause a denial of service (infinite\nloop) via crafted logbook entries. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0445"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/elog/+bug/216301"],"patches":{"elog":[]},"tags":{},"packages":[{"name":"elog","source":"https://ubuntu.com/security/cve?package=elog","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=elog","debian":"https://tracker.debian.org/pkg/elog","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0444","published":"2008-01-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG)\nbefore 2.7.0 allows remote attackers to inject arbitrary web script or HTML\nvia subtext parameter to unspecified components.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0444"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/elog/+bug/216301"],"patches":{"elog":[]},"tags":{},"packages":[{"name":"elog","source":"https://ubuntu.com/security/cve?package=elog","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=elog","debian":"https://tracker.debian.org/pkg/elog","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-6415","published":"2008-01-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nscponly 4.6 and earlier allows remote authenticated users to bypass\nintended restrictions and execute arbitrary code by invoking scp, as\nimplemented by OpenSSH, with the -F and -o options.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"debdiff in bug needs more information"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-6415"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/scponly/+bug/249593"],"patches":{"scponly":[]},"tags":{},"packages":[{"name":"scponly","source":"https://ubuntu.com/security/cve?package=scponly","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=scponly","debian":"https://tracker.debian.org/pkg/scponly","statuses":[{"release_codename":"dapper","status":"released","description":"4.6-1etch1build0.6.06.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4.6-1.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4.6-1.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4.6-1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.6-1.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4850","published":"2008-01-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncurl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5\nallows context-dependent attackers to bypass safe_mode and open_basedir\nrestrictions and read arbitrary files via a file:// request containing a\n\\x00 sequence, a different vulnerability than CVE-2006-2563.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"safe mode and open_basedir. Dapper not affected (code does not\nexist)"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugzilla.redhat.com/show_bug.cgi?id=169857#c1","https://ubuntu.com/security/notices/USN-628-1","https://www.cve.org/CVERecord?id=CVE-2007-4850"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/php5/+bug/227464"],"patches":{"php4":[],"php5":["debdiff: http://launchpadlibrarian.net/15065228/php5_5.2.4-2ubuntu5.2.debdiff","other: http://cvs.php.net/viewvc.cgi/php-src/ext/curl/interface.c?r1=1.62.2.14.2.33&r2=1.62.2.14.2.34&view=patch"]},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.2.6-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.2.6-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.6-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-628-1"],"notices":[{"id":"USN-628-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-07-23T19:08:24.013715","description":"It was discovered that PHP did not properly check the length of the\nstring parameter to the fnmatch function. An attacker could cause a\ndenial of service in the PHP interpreter if a script passed untrusted\ninput to the fnmatch function. (CVE-2007-4782)\n\nMaksymilian Arciemowicz discovered a flaw in the cURL library that\nallowed safe_mode and open_basedir restrictions to be bypassed. If a\nPHP application were tricked into processing a bad file:// request,\nan attacker could read arbitrary files. (CVE-2007-4850)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas\nof memory, possibly gaining access to sensitive information. This\nissue affects Ubuntu 8.04 LTS, and an updated fix is included for\nUbuntu 6.06 LTS, 7.04 and 7.10. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var function would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. This issue only affects\nUbuntu 8.04 LTS. (CVE-2007-5899)\n\nIt was discovered that PHP did not properly calculate the length of\nPATH_TRANSLATED. If a PHP application were tricked into processing\na malicious URI, and attacker may be able to execute arbitrary code\nwith application privileges. (CVE-2008-0599)\n\nAn integer overflow was discovered in the php_sprintf_appendstring\nfunction. Attackers could exploit this to cause a denial of service.\n(CVE-2008-1384)\n\nAndrei Nigmatulin discovered stack-based overflows in the FastCGI SAPI\nof PHP. An attacker may be able to leverage this issue to perform\nattacks against PHP applications. (CVE-2008-2050)\n\nIt was discovered that the escapeshellcmd did not properly process\nmultibyte characters. An attacker may be able to bypass quoting\nrestrictions and possibly execute arbitrary code with application\nprivileges. (CVE-2008-2051)\n\nIt was discovered that the GENERATE_SEED macro produced a predictable\nseed under certain circumstances. Attackers may by able to easily\npredict the results of the rand and mt_rand functions.\n(CVE-2008-2107, CVE-2008-2108)\n\nTavis Ormandy discovered that the PCRE library did not correctly\nhandle certain in-pattern options. An attacker could cause PHP\napplications using pcre to crash, leading to a denial of service.\nUSN-624-1 fixed vulnerabilities in the pcre3 library. This update\nprovides the corresponding update for PHP. (CVE-2008-2371)\n\nIt was discovered that php_imap used obsolete API calls. If a PHP\napplication were tricked into processing a malicious IMAP request,\nan attacker could cause a denial of service or possibly execute code\nwith application privileges. (CVE-2008-2829)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.4","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.4"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.4"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.4"},{"name":"php5-curl","version":"5.2.3-1ubuntu6.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.4"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.12","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.12"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.12"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.12"},{"name":"php5-curl","version":"5.1.2-1ubuntu3.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.12"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.6"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.6"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.6"},{"name":"php5-curl","version":"5.2.1-0ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.6"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.3","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.3"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.3"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.3"},{"name":"php5-curl","version":"5.2.4-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.3"}]},"type":"USN","cves_ids":["CVE-2007-4782","CVE-2007-4850","CVE-2007-5898","CVE-2007-5899","CVE-2008-0599","CVE-2008-1384","CVE-2008-2050","CVE-2008-2051","CVE-2008-2107","CVE-2008-2108","CVE-2008-2371","CVE-2008-2829"]}]},{"id":"CVE-2008-0404","published":"2008-01-23T12:00:00","updated_at":"2025-07-17T16:42:18.994089+00:00","description":"\nCross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows\nremote attackers to inject arbitrary web script or HTML via vectors related\nto the \"Most active bugs\" summary.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian-- code introduced in 1.1 series"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0404"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"dapper","status":"not-affected","description":"0.19.4-2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"0.19.4-3.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"1.0.6+dfsg-4.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"1.0.7+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":75700,"limit":20,"total_results":79316}