{"cves":[{"id":"CVE-2007-6685","published":"2008-01-17T02:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Publish XP module Menalto Gallery before\n2.2.4 allows attackers to create albums and upload files via unknown\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-6685"],"bugs":[""],"patches":{"gallery2":[],"gallery":[]},"tags":{},"packages":[{"name":"gallery","source":"https://ubuntu.com/security/cve?package=gallery","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gallery","debian":"https://tracker.debian.org/pkg/gallery","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"gallery2","source":"https://ubuntu.com/security/cve?package=gallery2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gallery2","debian":"https://tracker.debian.org/pkg/gallery2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.2.4-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.2.4-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.2.4-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.2.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.4-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-6684","published":"2008-01-17T01:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a\ndenial of service (crash) via a request without a Transport parameter,\nwhich triggers a NULL pointer dereference.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-6684"],"bugs":[""],"patches":{"vlc":[]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6e","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-6683","published":"2008-01-17T01:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to\noverwrite arbitrary files via (1) the :demuxdump-file option in a filename\nin a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an\nargument injection vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-6683"],"bugs":[""],"patches":{"vlc":[]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6e","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-6682","published":"2008-01-17T01:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nFormat string vulnerability in the httpd_FileCallBack function\n(network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute\narbitrary code via format string specifiers in the Connection parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-6682"],"bugs":[""],"patches":{"vlc":[]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6e","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-6681","published":"2008-01-17T01:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC\n0.8.6d allows remote attackers to execute arbitrary code via a long\nsubtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-6681"],"bugs":[""],"patches":{"vlc":[]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6e","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0299","published":"2008-01-16T23:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncommon.py in Paramiko 1.7.1 and earlier, when using threads or forked\nprocesses, does not properly use RandomPool, which allows one session to\nobtain sensitive information from another session by predicting the state\nof the pool.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.lag.net/pipermail/paramiko/2008-January/000599.html","https://www.cve.org/CVERecord?id=CVE-2008-0299"],"bugs":[""],"patches":{"paramiko":[]},"tags":{},"packages":[{"name":"paramiko","source":"https://ubuntu.com/security/cve?package=paramiko","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=paramiko","debian":"https://tracker.debian.org/pkg/paramiko","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.7.3-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.7.3-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.7.3-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.7.3-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.7.3-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.7.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0298","published":"2008-01-16T23:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nKHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a\ndenial of service (browser crash) via a crafted web page, possibly\ninvolving a STYLE attribute of a DIV element.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"I can't find detailed info on this bug but:\nSafari 3 is not vulnerable, and webkit in gutsy is more recent\nAlso, test exploit doesn't work in gutsy"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.s21sec.com/avisos/s21sec-039-en.txt","https://www.cve.org/CVERecord?id=CVE-2008-0298"],"bugs":[""],"patches":{"webkit":[]},"tags":{},"packages":[{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"0~svn25144-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"0~svn29752-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.0.1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0296","published":"2008-01-16T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC\nMedia Player 0.8.6d and earlier on Windows might allow remote RTSP servers\nto cause a denial of service (application crash) or execute arbitrary code\nvia a long string.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0296"],"bugs":[""],"patches":{"vlc":[]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6e","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0295","published":"2008-01-16T22:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the\nXine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier,\nallows user-assisted remote attackers to cause a denial of service (crash)\nor execute arbitrary code via long Session Description Protocol (SDP) data.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian this does not affect xine-lib, just vlc as it ships\na really old version"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0295"],"bugs":[""],"patches":{"vlc":[]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.8.6e-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6e","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0217","published":"2008-01-16T02:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty,\nwhich creates a pseudo-terminal with world-readable and world-writable\npermissions when it is not run as root, which allows local users to read\ndata from the terminal of the user running script.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0217"],"bugs":[""],"patches":{"kfreebsd-5":[]},"tags":{},"packages":[{"name":"kfreebsd-5","source":"https://ubuntu.com/security/cve?package=kfreebsd-5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kfreebsd-5","debian":"https://tracker.debian.org/pkg/kfreebsd-5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0216","published":"2008-01-16T02:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not\nproperly verify that a certain portion of a device name is associated with\na pty of a user who is calling the pt_chown function, which might allow\nlocal users to read data from the pty from another user.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0216"],"bugs":[""],"patches":{"kfreebsd-5":[]},"tags":{},"packages":[{"name":"kfreebsd-5","source":"https://ubuntu.com/security/cve?package=kfreebsd-5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kfreebsd-5","debian":"https://tracker.debian.org/pkg/kfreebsd-5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0122","published":"2008-01-16T02:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the inet_network function in libbind in ISC BIND 9.4.2\nand earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows\ncontext-dependent attackers to cause a denial of service (crash) and\npossibly execute arbitrary code via crafted input that triggers memory\ncorruption.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"from RH bug: This problem allows an attacker to write 1 unsigned\nlong int value (4 or 8 bytes, depending on the platform used) beyond the\nend of the buffer. This overwrite is too short to modify function return\naddress, so this problem does not seem to be easily exploitable or\nverifiable using reproducer.\nnothing linked against libbind9 in any Ubuntu releases, except for\nbind9 packages, and upstream says that none of the applications shipped with\nBIND 9 call inet_network()"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=bind-announce&m=120067515802939&w=2","https://www.cve.org/CVERecord?id=CVE-2008-0122"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=429149"],"patches":{"bind9":[]},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:9.4.2-8","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:9.4.2-8","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1:9.4.2-8","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:9.4.2-8","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1:9.4.2-8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1:9.4.2-8","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1:9.4.2-8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:9.4.2-8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0285","published":"2008-01-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote\nattackers to cause a denial of service (crash) via crafted IRC PART\nmessage, which triggers an invalid dereference.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0285"],"bugs":[""],"patches":{"ngircd":[]},"tags":{},"packages":[{"name":"ngircd","source":"https://ubuntu.com/security/cve?package=ngircd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ngircd","debian":"https://tracker.debian.org/pkg/ngircd","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.10.3-2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.10.3-2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.10.3-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.10.3-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.10.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0274","published":"2008-01-15T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when\ncertain .htaccess protections are disabled, allows remote attackers to\ninject arbitrary web script or HTML via crafted links involving theme\n.tpl.php files.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"according to Debian, needs register_globals On"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0274"],"bugs":[""],"patches":{"drupal5":[],"drupal":[]},"tags":{},"packages":[{"name":"drupal","source":"https://ubuntu.com/security/cve?package=drupal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal","debian":"https://tracker.debian.org/pkg/drupal","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"drupal5","source":"https://ubuntu.com/security/cve?package=drupal5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal5","debian":"https://tracker.debian.org/pkg/drupal5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.6-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.6-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.6-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0273","published":"2008-01-15T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInterpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6,\nwhen Internet Explorer 6 is used, allows remote attackers to conduct\ncross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which\nare not processed as UTF-8 by Drupal's HTML filtering, but are processed as\nUTF-8 by Internet Explorer, effectively removing characters from the\ndocument and defeating the HTML protection mechanism.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0273"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/drupal5/+bug/181984"],"patches":{"drupal5":["upstream: http://drupal.org/node/208564"],"drupal":["upstream: http://drupal.org/node/208564"]},"tags":{},"packages":[{"name":"drupal","source":"https://ubuntu.com/security/cve?package=drupal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal","debian":"https://tracker.debian.org/pkg/drupal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.1-0ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.11, 5.6","component":null,"pocket":"security"}]},{"name":"drupal5","source":"https://ubuntu.com/security/cve?package=drupal5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal5","debian":"https://tracker.debian.org/pkg/drupal5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"5.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0272","published":"2008-01-15T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in the aggregator module in\nDrupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to\ndelete items from a feed as privileged users.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0272"],"bugs":["http://drupal.org/node/208562","https://bugs.launchpad.net/ubuntu/+source/drupal5/+bug/181984"],"patches":{"drupal5":["upstream: http://drupal.org/node/208562"],"drupal":["upstream: http://drupal.org/node/208562"]},"tags":{},"packages":[{"name":"drupal","source":"https://ubuntu.com/security/cve?package=drupal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal","debian":"https://tracker.debian.org/pkg/drupal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.1-0ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.11","component":null,"pocket":"security"}]},{"name":"drupal5","source":"https://ubuntu.com/security/cve?package=drupal5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal5","debian":"https://tracker.debian.org/pkg/drupal5","statuses":[{"release_codename":"gutsy","status":"released","description":"5.2-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"5.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0173","published":"2008-01-15T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in Gforge 4.6.99 and earlier allows remote\nattackers to execute arbitrary SQL commands via unspecified parameters,\nrelated to RSS exports.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"from Debian \"Requires register_globals to be On\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0173"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/gforge/+bug/182809"],"patches":{"gforge":["vendor: http://www.debian.org/security/2008/dsa-1459"]},"tags":{},"packages":[{"name":"gforge","source":"https://ubuntu.com/security/cve?package=gforge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gforge","debian":"https://tracker.debian.org/pkg/gforge","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"4.6.99+svn6347-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.6.99+svn6347-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0001","published":"2008-01-15T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nVFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14,\nperforms tests of access mode by using the flag variable instead of the\nacc_mode variable, which might allow local users to bypass intended\npermissions and remove directories.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-574-1","https://ubuntu.com/security/notices/USN-578-1","https://www.cve.org/CVERecord?id=CVE-2008-0001"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/linux-meta/+bug/187275"],"patches":{"linus":["break-fix: 834f2a4a1554dc5b2598038b3fe8703defcbe467 974a9f0b47da74e28f68b9c8645c3786aa5ace1a"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.24.14","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-51.66","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.43","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.34","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.22-14.51","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-574-1","USN-578-1"],"notices":[{"id":"USN-574-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-02-04T16:25:54.511756","description":"The minix filesystem did not properly validate certain filesystem\nvalues. If a local attacker could trick the system into attempting\nto mount a corrupted minix filesystem, the kernel could be made to\nhang for long periods of time, resulting in a denial of service.\nThis was only vulnerable in Ubuntu 7.04 and 7.10. (CVE-2006-6058)\n\nThe signal handling on PowerPC systems using HTX allowed local users\nto cause a denial of service via floating point corruption. This was\nonly vulnerable in Ubuntu 6.10 and 7.04. (CVE-2007-3107)\n\nThe Linux kernel did not properly validate the hop-by-hop IPv6\nextended header. Remote attackers could send a crafted IPv6 packet\nand cause a denial of service via kernel panic. This was only\nvulnerable in Ubuntu 7.04. (CVE-2007-4567)\n\nThe JFFS2 filesystem with ACL support enabled did not properly store\npermissions during inode creation and ACL setting. Local users could\npossibly access restricted files after a remount. This was only\nvulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-4849)\n\nChris Evans discovered an issue with certain drivers that use the\nieee80211_rx function. Remote attackers could send a crafted 802.11\nframe and cause a denial of service via crash. This was only\nvulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-4997)\n\nAlex Smith discovered an issue with the pwc driver for certain webcam\ndevices. A local user with physical access to the system could remove\nthe device while a userspace application had it open and cause the USB\nsubsystem to block. This was only vulnerable in Ubuntu 7.04.\n(CVE-2007-5093)\n\nScott James Remnant discovered a coding error in ptrace. Local users\ncould exploit this and cause the kernel to enter an infinite loop.\nThis was only vulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-5500)\n\nIt was discovered that the Linux kernel could dereference a NULL\npointer when processing certain IPv4 TCP packets. A remote attacker\ncould send a crafted TCP ACK response and cause a denial of service\nvia crash. This was only vulnerable in Ubuntu 7.10. (CVE-2007-5501)\n\nWarren Togami discovered that the hrtimer subsystem did not properly\ncheck for large relative timeouts. A local user could exploit this and\ncause a denial of service via soft lockup. (CVE-2007-5966)\n\nVenustech AD-LAB discovered a buffer overflow in the isdn net\nsubsystem. This issue is exploitable by local users via crafted input\nto the isdn_ioctl function. (CVE-2007-6063)\n\nIt was discovered that the isdn subsystem did not properly check for\nNULL termination when performing ioctl handling. A local user could\nexploit this to cause a denial of service. (CVE-2007-6151)\n\nBlake Frantz discovered that when a root process overwrote an existing\ncore file, the resulting core file retained the previous core file's\nownership. Local users could exploit this to gain access to sensitive\ninformation. (CVE-2007-6206)\n\nHugh Dickins discovered the when using the tmpfs filesystem, under\nrare circumstances, a kernel page may be improperly cleared. A local\nuser may be able to exploit this and read sensitive kernel data or\ncause a denial of service via crash. (CVE-2007-6417)\n\nBill Roman discovered that the VFS subsystem did not properly check\naccess modes. A local user may be able to gain removal privileges on\ndirectories. (CVE-2008-0001)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-14.51","description":"","is_source":true},{"name":"linux-image-2.6.22-14-itanium","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-xen","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-lpia","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-hppa32","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-powerpc-smp","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-386","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-mckinley","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-sparc64-smp","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-sparc64","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-generic","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-virtual","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-powerpc","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-cell","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-rt","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-hppa64","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-lpiacompat","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-ume","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-powerpc64-smp","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-server","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"}],"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-16.34","description":"","is_source":true},{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"}],"edgy":[{"name":"linux-source-2.6.17","version":"2.6.17.1-12.43","description":"","is_source":true},{"name":"linux-image-2.6.17-12-mckinley","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-powerpc64-smp","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-hppa32","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-hppa64","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-sparc64-smp","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-generic","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-powerpc-smp","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-386","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-server-bigiron","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-itanium","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-powerpc","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-sparc64","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-server","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"}]},"type":"USN","cves_ids":["CVE-2006-6058","CVE-2007-3107","CVE-2007-4567","CVE-2007-4849","CVE-2007-4997","CVE-2007-5093","CVE-2007-5500","CVE-2007-5501","CVE-2007-5966","CVE-2007-6063","CVE-2007-6151","CVE-2007-6206","CVE-2007-6417","CVE-2008-0001"]},{"id":"USN-578-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2008-02-14T04:20:02.366593","description":"The minix filesystem did not properly validate certain filesystem\nvalues. If a local attacker could trick the system into attempting\nto mount a corrupted minix filesystem, the kernel could be made to\nhang for long periods of time, resulting in a denial of service.\n(CVE-2006-6058)\n\nAlexander Schulze discovered that the skge driver does not properly\nuse the spin_lock and spin_unlock functions. Remote attackers could\nexploit this by sending a flood of network traffic and cause a denial\nof service (crash). (CVE-2006-7229)\n\nHugh Dickins discovered that hugetlbfs performed certain prio_tree\ncalculations using HPAGE_SIZE instead of PAGE_SIZE. A local user\ncould exploit this and cause a denial of service via kernel panic.\n(CVE-2007-4133)\n\nChris Evans discovered an issue with certain drivers that use the\nieee80211_rx function. Remote attackers could send a crafted 802.11\nframe and cause a denial of service via crash. (CVE-2007-4997)\n\nAlex Smith discovered an issue with the pwc driver for certain webcam\ndevices. A local user with physical access to the system could remove\nthe device while a userspace application had it open and cause the USB\nsubsystem to block. (CVE-2007-5093)\n\nScott James Remnant discovered a coding error in ptrace. Local users\ncould exploit this and cause the kernel to enter an infinite loop.\n(CVE-2007-5500)\n\nVenustech AD-LAB discovered a buffer overflow in the isdn net\nsubsystem. This issue is exploitable by local users via crafted input\nto the isdn_ioctl function. (CVE-2007-6063)\n\nIt was discovered that the isdn subsystem did not properly check for\nNULL termination when performing ioctl handling. A local user could\nexploit this to cause a denial of service. (CVE-2007-6151)\n\nBlake Frantz discovered that when a root process overwrote an existing\ncore file, the resulting core file retained the previous core file's\nownership. Local users could exploit this to gain access to sensitive\ninformation. (CVE-2007-6206)\n\nHugh Dickins discovered the when using the tmpfs filesystem, under\nrare circumstances, a kernel page may be improperly cleared. A local\nuser may be able to exploit this and read sensitive kernel data or\ncause a denial of service via crash. (CVE-2007-6417)\n\nBill Roman discovered that the VFS subsystem did not properly check\naccess modes. A local user may be able to gain removal privileges\non directories. (CVE-2008-0001)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-51.66","description":"","is_source":true},{"name":"linux-image-2.6.15-51-amd64-k8","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-mckinley-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-mckinley","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-server-bigiron","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-386","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-686","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-sparc64","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-amd64-generic","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-hppa64-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-itanium","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-hppa64","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-sparc64-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-k7","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-itanium-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-server","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-hppa32-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-powerpc","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-amd64-server","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-powerpc64-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-amd64-xeon","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-powerpc-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-hppa32","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"}]},"type":"USN","cves_ids":["CVE-2006-7229","CVE-2006-6058","CVE-2007-4133","CVE-2007-4997","CVE-2007-5093","CVE-2007-5500","CVE-2007-6063","CVE-2007-6151","CVE-2007-6206","CVE-2007-6417","CVE-2008-0001"]}]},{"id":"CVE-2008-0252","published":"2008-01-12T02:46:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in the _get_file_path function in (1)\nlib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py\nin CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows\nremote attackers to create or delete arbitrary files, and possibly read and\nwrite portions of arbitrary files, via a crafted session id in a cookie.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0252"],"bugs":["https://bugs.launchpad.net/bugs/187481"],"patches":{"python-cherrypy":["vendor: http://www.debian.org/security/2008/dsa-1481"],"cherrypy3":[]},"tags":{},"packages":[{"name":"cherrypy3","source":"https://ubuntu.com/security/cve?package=cherrypy3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cherrypy3","debian":"https://tracker.debian.org/pkg/cherrypy3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"3.0.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"3.0.2-2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"3.0.2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"python-cherrypy","source":"https://ubuntu.com/security/cve?package=python-cherrypy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-cherrypy","debian":"https://tracker.debian.org/pkg/python-cherrypy","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.1-3ubuntu1.7.04","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.2.1-3ubuntu1.7.10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.2.1-3.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.2.1-3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-0244","published":"2008-01-12T02:46:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute\narbitrary commands via \"&&\" and other shell metacharacters in exec_sdbinfo\nand other unspecified commands, which are executed when MaxDB invokes\ncons.exe.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-0244"],"bugs":[""],"patches":{"maxdb-7.5.00":[]},"tags":{},"packages":[{"name":"maxdb-7.5.00","source":"https://ubuntu.com/security/cve?package=maxdb-7.5.00","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=maxdb-7.5.00","debian":"https://tracker.debian.org/pkg/maxdb-7.5.00","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":75740,"limit":20,"total_results":79316}