{"cves":[{"id":"CVE-2007-3918","published":"2007-10-05T22:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in account/verify.php in GForge\n4.6b2 allows remote attackers to inject arbitrary web script or HTML via\nthe confirm_hash parameter.","ubuntu_description":"","notes":[{"author":"kees","note":"sarge:3.1-31sarge3 etch:4.5.14-22etch2 sid:4.6.99+svn6094-1"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3918"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gforge","source":"https://ubuntu.com/security/cve?package=gforge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gforge","debian":"https://tracker.debian.org/pkg/gforge","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5226","published":"2007-10-05T21:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nirc_server.c in dircproxy 1.2.0 and earlier allows remote attackers to\ncause a denial of service (segmentation fault) via an ACTION command\nwithout a parameter, which triggers a NULL pointer dereference, as\ndemonstrated using a blank /me message from irssi.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugs.launchpad.net/bugs/150848","https://www.cve.org/CVERecord?id=CVE-2007-5226"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"dircproxy","source":"https://ubuntu.com/security/cve?package=dircproxy","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dircproxy","debian":"https://tracker.debian.org/pkg/dircproxy","statuses":[{"release_codename":"dapper","status":"released","description":"1.0.5-4ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.0.5-4ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.0.5-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4990","published":"2007-10-05T21:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe swap_char2b function in X.Org X Font Server (xfs) before 1.0.5 allows\ncontext-dependent attackers to execute arbitrary code via (1) QueryXBitmaps\nand (2) QueryXExtents protocol requests with crafted size values that\nspecify an arbitrary number of bytes to be swapped on the heap, which\ntriggers heap corruption.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"runs as root"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4990"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xfs","source":"https://ubuntu.com/security/cve?package=xfs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xfs","debian":"https://tracker.debian.org/pkg/xfs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1:1.0.5-2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1:1.0.5-2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1:1.0.5-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1:1.0.5-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4568","published":"2007-10-05T21:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the build_range function in X.Org X Font Server (xfs)\nbefore 1.0.5 allows context-dependent attackers to execute arbitrary code\nvia (1) QueryXBitmaps and (2) QueryXExtents protocol requests with crafted\nsize values, which triggers a heap-based buffer overflow.","ubuntu_description":"","notes":[{"author":"kees","note":"sarge:4.3.0.dfsg.1-14sarge5, etch:1.0.1-7, unstable:1.0.5-1"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4568"],"bugs":["https://launchpad.net/bugs/148940"],"patches":{},"tags":{},"packages":[{"name":"xfs","source":"https://ubuntu.com/security/cve?package=xfs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xfs","debian":"https://tracker.debian.org/pkg/xfs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1:1.0.4-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:1.0.4-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:1.0.4-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1:1.0.4-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:1.0.4-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4133","published":"2007-10-04T23:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) hugetlb_vmtruncate_list and (2) hugetlb_vmtruncate functions in\nfs/hugetlbfs/inode.c in the Linux kernel before 2.6.19-rc4 perform certain\nprio_tree calculations using HPAGE_SIZE instead of PAGE_SIZE units, which\nallows local users to cause a denial of service (panic) via unspecified\nvectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"fixed in DSA 1381-1"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-578-1","https://ubuntu.com/security/notices/USN-558-1","https://www.cve.org/CVERecord?id=CVE-2007-4133"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"released","description":"2.6.20","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-51.66","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.42","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-578-1","USN-558-1"],"notices":[{"id":"USN-578-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2008-02-14T04:20:02.366593","description":"The minix filesystem did not properly validate certain filesystem\nvalues. If a local attacker could trick the system into attempting\nto mount a corrupted minix filesystem, the kernel could be made to\nhang for long periods of time, resulting in a denial of service.\n(CVE-2006-6058)\n\nAlexander Schulze discovered that the skge driver does not properly\nuse the spin_lock and spin_unlock functions. Remote attackers could\nexploit this by sending a flood of network traffic and cause a denial\nof service (crash). (CVE-2006-7229)\n\nHugh Dickins discovered that hugetlbfs performed certain prio_tree\ncalculations using HPAGE_SIZE instead of PAGE_SIZE. A local user\ncould exploit this and cause a denial of service via kernel panic.\n(CVE-2007-4133)\n\nChris Evans discovered an issue with certain drivers that use the\nieee80211_rx function. Remote attackers could send a crafted 802.11\nframe and cause a denial of service via crash. (CVE-2007-4997)\n\nAlex Smith discovered an issue with the pwc driver for certain webcam\ndevices. A local user with physical access to the system could remove\nthe device while a userspace application had it open and cause the USB\nsubsystem to block. (CVE-2007-5093)\n\nScott James Remnant discovered a coding error in ptrace. Local users\ncould exploit this and cause the kernel to enter an infinite loop.\n(CVE-2007-5500)\n\nVenustech AD-LAB discovered a buffer overflow in the isdn net\nsubsystem. This issue is exploitable by local users via crafted input\nto the isdn_ioctl function. (CVE-2007-6063)\n\nIt was discovered that the isdn subsystem did not properly check for\nNULL termination when performing ioctl handling. A local user could\nexploit this to cause a denial of service. (CVE-2007-6151)\n\nBlake Frantz discovered that when a root process overwrote an existing\ncore file, the resulting core file retained the previous core file's\nownership. Local users could exploit this to gain access to sensitive\ninformation. (CVE-2007-6206)\n\nHugh Dickins discovered the when using the tmpfs filesystem, under\nrare circumstances, a kernel page may be improperly cleared. A local\nuser may be able to exploit this and read sensitive kernel data or\ncause a denial of service via crash. (CVE-2007-6417)\n\nBill Roman discovered that the VFS subsystem did not properly check\naccess modes. A local user may be able to gain removal privileges\non directories. (CVE-2008-0001)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-51.66","description":"","is_source":true},{"name":"linux-image-2.6.15-51-amd64-k8","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-mckinley-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-mckinley","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-server-bigiron","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-386","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-686","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-sparc64","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-amd64-generic","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-hppa64-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-itanium","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-hppa64","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-sparc64-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-k7","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-itanium-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-server","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-hppa32-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-powerpc","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-amd64-server","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-powerpc64-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-amd64-xeon","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-powerpc-smp","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"},{"name":"linux-image-2.6.15-51-hppa32","version":"2.6.15-51.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-51.66"}]},"type":"USN","cves_ids":["CVE-2006-7229","CVE-2006-6058","CVE-2007-4133","CVE-2007-4997","CVE-2007-5093","CVE-2007-5500","CVE-2007-6063","CVE-2007-6151","CVE-2007-6206","CVE-2007-6417","CVE-2008-0001"]},{"id":"USN-558-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-12-19T00:52:22.886062","description":"The minix filesystem did not properly validate certain filesystem values.\nIf a local attacker could trick the system into attempting to mount a\ncorrupted minix filesystem, the kernel could be made to hang for long\nperiods of time, resulting in a denial of service. (CVE-2006-6058)\n\nCertain calculations in the hugetlb code were not correct.  A local\nattacker could exploit this to cause a kernel panic, leading to a denial\nof service. (CVE-2007-4133)\n\nEric Sesterhenn and Victor Julien discovered that the hop-by-hop IPv6\nextended header was not correctly validated.  If a system was configured\nfor IPv6, a remote attacker could send a specially crafted IPv6 packet\nand cause the kernel to panic, leading to a denial of service.  This\nwas only vulnerable in Ubuntu 7.04. (CVE-2007-4567)\n\nPermissions were not correctly stored on JFFS2 ACLs.  For systems using\nACLs on JFFS2, a local attacker may gain access to private files.\n(CVE-2007-4849)\n\nChris Evans discovered that the 802.11 network stack did not correctly\nhandle certain QOS frames.  A remote attacker on the local wireless network\ncould send specially crafted packets that would panic the kernel, resulting\nin a denial of service. (CVE-2007-4997)\n\nThe Philips USB Webcam driver did not correctly handle disconnects.\nIf a local attacker tricked another user into disconnecting a webcam\nunsafely, the kernel could hang or consume CPU resources, leading to\na denial of service. (CVE-2007-5093)\n\nScott James Remnant discovered that the waitid function could be made\nto hang the system.  A local attacker could execute a specially crafted\nprogram which would leave the system unresponsive, resulting in a denial\nof service. (CVE-2007-5500)\n\nIlpo Järvinen discovered that it might be possible for the TCP stack\nto panic the kernel when receiving a crafted ACK response.  Only Ubuntu\n7.10 contained the vulnerable code, and it is believed not to have\nbeen exploitable. (CVE-2007-5501)\n\nWhen mounting the same remote NFS share to separate local locations, the\nfirst location's mount options would apply to all subsequent mounts of the\nsame NFS share.  In some configurations, this could lead to incorrectly\nconfigured permissions, allowing local users to gain additional access\nto the mounted share. (https://launchpad.net/bugs/164231)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-14.47","description":"","is_source":true},{"name":"linux-image-2.6.22-14-itanium","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-xen","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-lpia","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-hppa32","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-powerpc-smp","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-386","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-mckinley","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-sparc64-smp","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-sparc64","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-generic","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-virtual","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-powerpc","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-cell","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-rt","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-hppa64","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-lpiacompat","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-ume","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-powerpc64-smp","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"},{"name":"linux-image-2.6.22-14-server","version":"2.6.22-14.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.47"}],"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-16.33","description":"","is_source":true},{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.33"}],"edgy":[{"name":"linux-source-2.6.17","version":"2.6.17.1-12.42","description":"","is_source":true},{"name":"linux-image-2.6.17-12-mckinley","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-powerpc64-smp","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-hppa32","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-hppa64","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-sparc64-smp","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-generic","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-powerpc-smp","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-386","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-server-bigiron","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-itanium","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-powerpc","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-sparc64","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"},{"name":"linux-image-2.6.17-12-server","version":"2.6.17.1-12.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.42"}]},"type":"USN","cves_ids":["CVE-2006-6058","CVE-2007-4133","CVE-2007-4567","CVE-2007-4849","CVE-2007-4997","CVE-2007-5093","CVE-2007-5500","CVE-2007-5501"]}]},{"id":"CVE-2007-5207","published":"2007-10-04T21:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nguilt 0.27 allows local users to overwrite arbitrary files via a symlink\nattack on a guilt.log.[PID] temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5207"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"guilt","source":"https://ubuntu.com/security/cve?package=guilt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=guilt","debian":"https://tracker.debian.org/pkg/guilt","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"0.28-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"0.28-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.27-1.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5201","published":"2007-10-04T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe FTP backend for Duplicity before 0.4.9 sends the password as a command\nline argument when calling ncftp, which might allow local users to read the\npassword by listing the process and its arguments.","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Introduced in 0.4.3."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5201"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"duplicity","source":"https://ubuntu.com/security/cve?package=duplicity","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=duplicity","debian":"https://tracker.debian.org/pkg/duplicity","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.4.3-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5198","published":"2007-10-04T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the redir function in check_http.c in Nagios Plugins\nbefore 1.4.10, when running with the -f (follow) option, allows remote web\nservers to execute arbitrary code via Location header responses (redirects)\nwith a large number of leading \"L\" characters.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"supplied debdiff in LP doesn't address (fixed in CVS before 1.4.11)\nhttp://sourceforge.net/tracker/index.php?func=detail&aid=1813346&group_id=29880&atid=397597\nalso has two DoS:\nhttp://sourceforge.net/tracker/index.php?func=detail&aid=1729692&group_id=29880&atid=397597\nhttp://nagiosplug.cvs.sourceforge.net/nagiosplug/nagiosplug/plugins/sslutils.c?r1=1.3&r2=1.4 (no bug report, see the changelog)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-532-1","https://www.cve.org/CVERecord?id=CVE-2007-5198"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/nagios-plugins/+bug/152624"],"patches":{},"tags":{},"packages":[{"name":"nagios-plugins","source":"https://ubuntu.com/security/cve?package=nagios-plugins","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nagios-plugins","debian":"https://tracker.debian.org/pkg/nagios-plugins","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.2-5ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3.0cvs.20060707-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.5-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.4.8-2.1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.11","component":null,"pocket":"security"}]}],"notices_ids":["USN-532-1"],"notices":[{"id":"USN-532-1","title":"nagios-plugins vulnerability","summary":"nagios-plugins vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-10-22T17:53:53.237367","description":"Nobuhiro Ban discovered that check_http in nagios-plugins did\nnot properly sanitize its input when following redirection\nrequests. A malicious remote web server could cause a denial\nof service or possibly execute arbitrary code as the user.\n(CVE-2007-5198)\n\nAravind Gottipati discovered that sslutils.c in nagios-plugins\ndid not properly reset pointers to NULL. A malicious remote web\nserver could cause a denial of service.\n\nAravind Gottipati discovered that check_http in nagios-plugins\ndid not properly calculate how much memory to reallocate when\nfollowing redirection requests. A malicious remote web server\ncould cause a denial of service.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"nagios-plugins","version":"1.4.2-5ubuntu3.1","description":"","is_source":true},{"name":"nagios-plugins","version":"1.4.2-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios-plugins","version_link":"https://launchpad.net/ubuntu/+source/nagios-plugins/1.4.2-5ubuntu3.1"},{"name":"nagios-plugins-basic","version":"1.4.2-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios-plugins","version_link":"https://launchpad.net/ubuntu/+source/nagios-plugins/1.4.2-5ubuntu3.1"},{"name":"nagios-plugins-standard","version":"1.4.2-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios-plugins","version_link":"https://launchpad.net/ubuntu/+source/nagios-plugins/1.4.2-5ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2007-5198"]}]},{"id":"CVE-2007-5193","published":"2007-10-04T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly\nother operating systems, specifies the work area directory\n(cfg{RCS}{WorkAreaDir}) under the web document root, which might allow\nremote attackers to obtain sensitive information when .htaccess\nrestrictions are not applied.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5193"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"twiki","source":"https://ubuntu.com/security/cve?package=twiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twiki","debian":"https://tracker.debian.org/pkg/twiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:4.1.2-3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:4.1.2-3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1:4.1.2-3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:4.1.2-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5191","published":"2007-10-04T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmount and umount in util-linux and loop-aes-utils call the setuid and\nsetgid functions in the wrong order and do not check the return values,\nwhich might allow attackers to gain privileges via helpers such as\nmount.nfs.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://git.kernel.org/?p=utils/util-linux-ng/util-linux-ng.git;a=commit;h=ebbeb2c7ac1b00b6083905957837a271e80b187e","https://ubuntu.com/security/notices/USN-533-1","https://www.cve.org/CVERecord?id=CVE-2007-5191"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/loop-aes-utils/+bug/180976"],"patches":{"loop-aes-utils":["vendor: http://www.debian.org/security/2008/dsa-1449"]},"tags":{},"packages":[{"name":"loop-aes-utils","source":"https://ubuntu.com/security/cve?package=loop-aes-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=loop-aes-utils","debian":"https://tracker.debian.org/pkg/loop-aes-utils","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.13-2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.13-2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.13-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.13-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"util-linux","source":"https://ubuntu.com/security/cve?package=util-linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=util-linux","debian":"https://tracker.debian.org/pkg/util-linux","statuses":[{"release_codename":"dapper","status":"released","description":"2.12r-4ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.12r-11ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.12r-17ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.13-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.13-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.13-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.13-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.13-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-533-1"],"notices":[{"id":"USN-533-1","title":"util-linux vulnerability","summary":"util-linux vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-10-22T18:01:13.438115","description":"Ludwig Nussel discovered that mount and umount did not properly\ndrop privileges when using helper programs. Local attackers may be\nable to bypass security restrictions and gain root privileges using\nprograms such as mount.nfs or mount.cifs.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"util-linux","version":"2.12r-4ubuntu6.1","description":"","is_source":true},{"name":"mount","version":"2.12r-4ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/util-linux","version_link":"https://launchpad.net/ubuntu/+source/util-linux/2.12r-4ubuntu6.1"}],"feisty":[{"name":"util-linux","version":"2.12r-17ubuntu2.1","description":"","is_source":true},{"name":"mount","version":"2.12r-17ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/util-linux","version_link":"https://launchpad.net/ubuntu/+source/util-linux/2.12r-17ubuntu2.1"}],"edgy":[{"name":"util-linux","version":"2.12r-11ubuntu2.1","description":"","is_source":true},{"name":"mount","version":"2.12r-11ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/util-linux","version_link":"https://launchpad.net/ubuntu/+source/util-linux/2.12r-11ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2007-5191"]}]},{"id":"CVE-2007-4996","published":"2007-10-01T20:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibpurple in Pidgin before 2.2.1 does not properly handle MSN nudge\nmessages from users who are not on the receiver's buddy list, which allows\nremote attackers to cause a denial of service (crash) via a nudge message\nthat triggers an access of \"an invalid memory location.\"","ubuntu_description":"","notes":[{"author":"kees","note":"remote crasher, but only in 2.2 series, it seems based on the patch"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://developer.pidgin.im/viewmtn/revision/diff/f7687aed5d4c60018282a0629b67556f506ceb54/with/a5dd91b5d76972cf72a56209503c7e32d71c6e3c/libpurple/protocols/msn/switchboard.c","https://www.cve.org/CVERecord?id=CVE-2007-4996"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gaim","source":"https://ubuntu.com/security/cve?package=gaim","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gaim","debian":"https://tracker.debian.org/pkg/gaim","statuses":[{"release_codename":"dapper","status":"not-affected","description":"nudge code not present","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"nudge code not vulnerable","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"nudge code not vulnerable","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"pidgin","source":"https://ubuntu.com/security/cve?package=pidgin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pidgin","debian":"https://tracker.debian.org/pkg/pidgin","statuses":[{"release_codename":"upstream","status":"released","description":"2.2.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5162","published":"2007-10-01T05:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe connect method in lib/net/http.rb in the (1) Net::HTTP and (2)\nNet::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the\ncommonName (CN) field in a server certificate matches the domain name in an\nHTTPS request, which makes it easier for remote attackers to intercept SSL\ntransmissions via a man-in-the-middle attack or spoofed web site.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"LP bug has debdiffs"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-596-1","https://www.cve.org/CVERecord?id=CVE-2007-5162"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/ruby1.8/+bug/149616"],"patches":{"ruby1.8":["debdiff: https://bugs.launchpad.net/ubuntu/+source/ruby1.8/+bug/149616"],"libopenssl-ruby":[]},"tags":{},"packages":[{"name":"libopenssl-ruby","source":"https://ubuntu.com/security/cve?package=libopenssl-ruby","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libopenssl-ruby","debian":"https://tracker.debian.org/pkg/libopenssl-ruby","statuses":[{"release_codename":"dapper","status":"not-affected","description":"fixed in ruby1.8","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"fixed in ruby1.8","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"fixed in ruby1.8","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"fixed in ruby1.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"fixed in ruby1.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.1.4a-1sarge1","component":null,"pocket":"security"}]},{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"dapper","status":"released","description":"1.8.4-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.4-5ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.5-4ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.6.36-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.6.111","component":null,"pocket":"security"}]}],"notices_ids":["USN-596-1"],"notices":[{"id":"USN-596-1","title":"Ruby vulnerabilities","summary":"Ruby vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-03-26T21:43:03.028721","description":"Chris Clark discovered that Ruby's HTTPS module did not check for\ncommonName mismatches early enough during SSL negotiation.  If a remote\nattacker were able to perform machine-in-the-middle attacks, this flaw could\nbe exploited to view sensitive information in HTTPS requests coming from\nRuby applications. (CVE-2007-5162)\n\nIt was discovered that Ruby's FTPTLS, telnets, and IMAPS modules\ndid not check the commonName when performing SSL certificate checks.\nIf a remote attacker were able to perform machine-in-the-middle attacks,\nthis flaw could be exploited to eavesdrop on encrypted communications\nfrom Ruby applications using these protocols. (CVE-2007-5770)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"ruby1.8","version":"1.8.4-1ubuntu1.4","description":"","is_source":true},{"name":"libopenssl-ruby1.8","version":"1.8.4-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.4-1ubuntu1.4"},{"name":"libruby1.8","version":"1.8.4-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.4-1ubuntu1.4"}],"edgy":[{"name":"ruby1.8","version":"1.8.4-5ubuntu1.3","description":"","is_source":true},{"name":"libopenssl-ruby1.8","version":"1.8.4-5ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.4-5ubuntu1.3"},{"name":"libruby1.8","version":"1.8.4-5ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.4-5ubuntu1.3"}],"feisty":[{"name":"ruby1.8","version":"1.8.5-4ubuntu2.1","description":"","is_source":true},{"name":"libopenssl-ruby1.8","version":"1.8.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.5-4ubuntu2.1"},{"name":"libruby1.8","version":"1.8.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.5-4ubuntu2.1"}],"gutsy":[{"name":"ruby1.8","version":"1.8.6.36-1ubuntu3.1","description":"","is_source":true},{"name":"libopenssl-ruby1.8","version":"1.8.6.36-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.6.36-1ubuntu3.1"},{"name":"libruby1.8","version":"1.8.6.36-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.6.36-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2007-5770","CVE-2007-5162"]}]},{"id":"CVE-2007-5159","published":"2007-10-01T05:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ntfs-3g package before 1.913-2.fc7 in Fedora 7, and an ntfs-3g package\nin Ubuntu 7.10/Gutsy, assign incorrect permissions (setuid root) to\nmount.ntfs-3g, which allows local users with fuse group membership to read\nfrom and write to arbitrary block devices, possibly involving a file\ndescriptor leak.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5159"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1:1.913-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1:1.2216-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.913-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5156","published":"2007-10-01T05:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nIncomplete blacklist vulnerability in\neditor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS\n0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other\nproducts, allows remote attackers to upload and execute arbitrary PHP code\nvia a file whose name contains \".php.\" and has an unknown extension, which\nis recognized as a .php file by the Apache HTTP server, a different\nvulnerability than CVE-2006-0658 and CVE-2006-2529.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5156"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"knowledgeroot","source":"https://ubuntu.com/security/cve?package=knowledgeroot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=knowledgeroot","debian":"https://tracker.debian.org/pkg/knowledgeroot","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.9.8.4-1.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.9.8.4-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5137","published":"2007-09-28T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl\n(Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary\ncode via multi-frame interlaced GIF files in which later frames are smaller\nthan the first.  NOTE: this issue is due to an incorrect patch for\nCVE-2007-5378.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVE only affects feisty and gutsy tk8.4.  These releases have a fix\nfor tcl/tk bug #1458234, which either introduced or unmasked the issue in\nthis CVE (investigate). Bug #1458234 is a memory corruption crasher as well,\nand though it doesn't have a CVE, it should be fixed. tk8.3 is affected by\n#1458234 in all releases, so when fixing it, be sure to fix the CVE as well.\ntk8.4 in dapper and edgy need both fixes too."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-529-1","https://www.cve.org/CVERecord?id=CVE-2007-5137"],"bugs":[""],"patches":{"libtk-img":[]},"tags":{},"packages":[{"name":"libtk-img","source":"https://ubuntu.com/security/cve?package=libtk-img","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libtk-img","debian":"https://tracker.debian.org/pkg/libtk-img","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1:1.3-release-7+lenny1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.3-release-8","component":null,"pocket":"security"}]},{"name":"tk8.3","source":"https://ubuntu.com/security/cve?package=tk8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tk8.3","debian":"https://tracker.debian.org/pkg/tk8.3","statuses":[{"release_codename":"dapper","status":"released","description":"8.3.5-4ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"8.3.5-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"8.3.5-6ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"8.3.5-12ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.3.5-9","component":null,"pocket":"security"}]},{"name":"tk8.4","source":"https://ubuntu.com/security/cve?package=tk8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tk8.4","debian":"https://tracker.debian.org/pkg/tk8.4","statuses":[{"release_codename":"dapper","status":"released","description":"8.4.12-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"8.4.12-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"8.4.14-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"8.4.16-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.16","component":null,"pocket":"security"}]}],"notices_ids":["USN-529-1"],"notices":[{"id":"USN-529-1","title":"Tk vulnerability","summary":"Tk vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-10-11T18:02:19.028280","description":"It was discovered that Tk could be made to overrun a buffer when loading\ncertain images. If a user were tricked into opening a specially crafted\nGIF image, remote attackers could cause a denial of service or execute\narbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"tk8.4","version":"8.4.12-0ubuntu1.1","description":"","is_source":true},{"name":"tk8.3","version":"8.3.5-4ubuntu1.1","description":"","is_source":true},{"name":"tk8.4","version":"8.4.12-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tk8.4","version_link":"https://launchpad.net/ubuntu/+source/tk8.4/8.4.12-0ubuntu1.1"},{"name":"tk8.3","version":"8.3.5-4ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tk8.3","version_link":"https://launchpad.net/ubuntu/+source/tk8.3/8.3.5-4ubuntu1.1"}],"feisty":[{"name":"tk8.4","version":"8.4.14-0ubuntu2.1","description":"","is_source":true},{"name":"tk8.3","version":"8.3.5-6ubuntu2.1","description":"","is_source":true},{"name":"tk8.4","version":"8.4.14-0ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tk8.4","version_link":"https://launchpad.net/ubuntu/+source/tk8.4/8.4.14-0ubuntu2.1"},{"name":"tk8.3","version":"8.3.5-6ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tk8.3","version_link":"https://launchpad.net/ubuntu/+source/tk8.3/8.3.5-6ubuntu2.1"}],"edgy":[{"name":"tk8.4","version":"8.4.12-1ubuntu0.1","description":"","is_source":true},{"name":"tk8.3","version":"8.3.5-6ubuntu1.1","description":"","is_source":true},{"name":"tk8.4","version":"8.4.12-1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tk8.4","version_link":"https://launchpad.net/ubuntu/+source/tk8.4/8.4.12-1ubuntu0.1"},{"name":"tk8.3","version":"8.3.5-6ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tk8.3","version_link":"https://launchpad.net/ubuntu/+source/tk8.3/8.3.5-6ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2007-5137","CVE-2007-5378"]}]},{"id":"CVE-2007-5121","published":"2007-09-27T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in JSPWiki 2.5.139-beta allows\nremote attackers to inject arbitrary web script or HTML via the redirect\nparameter to wiki-3/Login.jsp and unspecified other components.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"version 2.2 (as in Ubuntu) may not be afected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5121"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"jspwiki","source":"https://ubuntu.com/security/cve?package=jspwiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jspwiki","debian":"https://tracker.debian.org/pkg/jspwiki","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5120","published":"2007-09-27T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and\n2.5.139-beta allow remote attackers to inject arbitrary web script or HTML\nvia the (1) group and (2) members parameters in (a) NewGroup.jsp; the (3)\nedittime parameter in (b) Edit.jsp; the (4) edittime, (5) author, and (6)\nlink parameters in (c) Comment.jsp; the (7) loginname, (8) wikiname, (9)\nfullname, and (10) email parameters in (d) UserPreferences.jsp and (e)\nLogin.jsp; the (11) r1 and (12) r2 parameters in (f) Diff.jsp; and the (13)\nchangenote parameter in (g) PageInfo.jsp.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"version 2.2 (as in Ubuntu) may not be afected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5120"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"jspwiki","source":"https://ubuntu.com/security/cve?package=jspwiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jspwiki","debian":"https://tracker.debian.org/pkg/jspwiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.5.139-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.5.139-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.5.139-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.5.139-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.139","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-5119","published":"2007-09-27T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nJSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain\nsensitive information (full path) via an invalid integer in the version\nparameter to the default URI under attach/Main/.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"version 2.2 (as in Ubuntu) may not be afected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-5119"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"jspwiki","source":"https://ubuntu.com/security/cve?package=jspwiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jspwiki","debian":"https://tracker.debian.org/pkg/jspwiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.5.139-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.5.139-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.5.139-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.5.139-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.139","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4993","published":"2007-09-27T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest\ndomain, allows local users with elevated privileges in the guest domain to\nexecute arbitrary commands in domain 0 via a crafted grub.conf file whose\ncontents are used in exec statements.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-527-1","https://www.cve.org/CVERecord?id=CVE-2007-4993"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xen-3.0","source":"https://ubuntu.com/security/cve?package=xen-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen-3.0","debian":"https://tracker.debian.org/pkg/xen-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.0.3-0ubuntu10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.1","source":"https://ubuntu.com/security/cve?package=xen-3.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen-3.1","debian":"https://tracker.debian.org/pkg/xen-3.1","statuses":[{"release_codename":"gutsy","status":"released","description":"3.1.0-0ubuntu16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-527-1"],"notices":[{"id":"USN-527-1","title":"xen-3.0 vulnerability","summary":"xen-3.0 vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-10-05T17:08:17.332869","description":"Joris van Rantwijk discovered that the Xen host did not correctly validate\nthe contents of a Xen guests's grug.conf file.  Xen guest root users could\nexploit this to run arbitrary commands on the host when the guest system\nwas rebooted.\n","is_hidden":false,"release_packages":{"feisty":[{"name":"xen-3.0","version":"3.0.3-0ubuntu10.1","description":"","is_source":true},{"name":"xen-utils-3.0","version":"3.0.3-0ubuntu10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xen-3.0","version_link":"https://launchpad.net/ubuntu/+source/xen-3.0/3.0.3-0ubuntu10.1"}]},"type":"USN","cves_ids":["CVE-2007-4993"]}]},{"id":"CVE-2007-5135","published":"2007-09-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up\nto 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute\narbitrary code via a crafted packet that triggers a one-byte buffer\nunderflow.  NOTE: this issue was introduced as a result of a fix for\nCVE-2006-3738.  As of 20071012, it is unknown whether code execution is\npossible.","ubuntu_description":"\nMoritz Jodeit discovered that OpenSSL's SSL_get_shared_ciphers function\ndid not correctly check the size of the buffer it was writing to.\nA remote attacker could exploit this to write one NULL byte past the end of\nan application's cipher list buffer, possibly leading to arbitrary code\nexecution or a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-522-1","https://www.cve.org/CVERecord?id=CVE-2007-5135"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"dapper","status":"released","description":"0.9.8a-7ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.9.8b-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.9.8c-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.9.8e-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.9.8e-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.9.8e-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.9.8e-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.9.8e-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.8f","component":null,"pocket":"security"}]},{"name":"openssl097","source":"https://ubuntu.com/security/cve?package=openssl097","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl097","debian":"https://tracker.debian.org/pkg/openssl097","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-522-1"],"notices":[{"id":"USN-522-1","title":"openssl vulnerabilities","summary":"openssl vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-09-28T23:11:34.704219","description":"It was discovered that OpenSSL did not correctly perform Montgomery\nmultiplications.  Local attackers might be able to reconstruct RSA\nprivate keys by examining another user's OpenSSL processes. (CVE-2007-3108)\n\nMoritz Jodeit discovered that OpenSSL's SSL_get_shared_ciphers function\ndid not correctly check the size of the buffer it was writing to.\nA remote attacker could exploit this to write one NULL byte past the end of\nan application's cipher list buffer, possibly leading to arbitrary code\nexecution or a denial of service. (CVE-2007-5135)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"openssl","version":"0.9.8a-7ubuntu0.4","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8a-7ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8a-7ubuntu0.4"}],"feisty":[{"name":"openssl","version":"0.9.8c-4ubuntu0.1","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8c-4ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8c-4ubuntu0.1"}],"edgy":[{"name":"openssl","version":"0.9.8b-2ubuntu2.1","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8b-2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8b-2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2007-3108","CVE-2007-5135"]}]}],"offset":76100,"limit":20,"total_results":79316}