{"cves":[{"id":"CVE-2007-4752","published":"2007-09-12T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie\ncannot be created and uses a trusted X11 cookie instead, which allows\nattackers to violate intended policy and gain privileges by causing an X\nclient to be treated as trusted.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"from secure-testing:\nAn exploit needs limited control over the machine running a\ntrusted X client, so this is only a slight privilege\nescalation. The X Security extension is merely an afterthought\nand is unlikely to provide strong security guarantees."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-566-1","https://www.cve.org/CVERecord?id=CVE-2007-4752"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/162171"],"patches":{"openssh":["debdiff: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/162171"]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"dapper","status":"released","description":"1:4.2p1-7ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1:4.3p2-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1:4.3p2-8ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1:4.6p1-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-566-1"],"notices":[{"id":"USN-566-1","title":"OpenSSH vulnerability","summary":"OpenSSH vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-01-09T23:42:49.942983","description":"Jan Pechanec discovered that ssh would forward trusted X11 cookies when\nuntrusted cookie generation failed. This could lead to unintended privileges\nbeing forwarded to a remote host.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"openssh","version":"1:4.6p1-5ubuntu0.1","description":"","is_source":true},{"name":"openssh-client","version":"1:4.6p1-5ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.6p1-5ubuntu0.1"}],"dapper":[{"name":"openssh","version":"1:4.2p1-7ubuntu3.2","description":"","is_source":true},{"name":"openssh-client","version":"1:4.2p1-7ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.2p1-7ubuntu3.2"}],"feisty":[{"name":"openssh","version":"1:4.3p2-8ubuntu1.1","description":"","is_source":true},{"name":"openssh-client","version":"1:4.3p2-8ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.3p2-8ubuntu1.1"}],"edgy":[{"name":"openssh","version":"1:4.3p2-5ubuntu1.1","description":"","is_source":true},{"name":"openssh-client","version":"1:4.3p2-5ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:4.3p2-5ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2007-4752"]}]},{"id":"CVE-2007-2930","published":"2007-09-12T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND\n8 before 8.4.7-P1 generate predictable DNS query identifiers when sending\noutgoing queries such as NOTIFY messages when answering questions as a\nresolver, which allows remote attackers to poison DNS caches via unknown\nvectors. NOTE: this issue is different from CVE-2007-2926.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-2930"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bind","source":"https://ubuntu.com/security/cve?package=bind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind","debian":"https://tracker.debian.org/pkg/bind","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.7-P1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4730","published":"2007-09-11T19:17:00","updated_at":"2025-07-17T16:42:09.648205+00:00","description":"\nBuffer overflow in the compNewPixmap function in compalloc.c in the\nComposite extension for the X.org X11 server before 1.4 allows local users\nto execute arbitrary code by copying data from a large pixel depth pixmap\ninto a smaller pixel depth pixmap.","ubuntu_description":"","notes":[{"author":"kees","note":"The vulnerable code is actually disabled by patches in edgy+"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-514-1","https://www.cve.org/CVERecord?id=CVE-2007-4730"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"dapper","status":"released","description":"1.0.2-0ubuntu10.7","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-514-1"],"notices":[{"id":"USN-514-1","title":"X.org vulnerability","summary":"X.org vulnerability","instructions":"After a standard system upgrade you need to restart your session to effect\nthe necessary changes.\n","references":[],"published":"2007-09-18T20:28:32.342504","description":"Aaron Plattner discovered that the Composite extension did not correctly\ncalculate the size of buffers when copying between different bit depths.\nAn authenticated user could exploit this to execute arbitrary code with\nroot privileges.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"xorg-server","version":"1:1.0.2-0ubuntu10.7","description":"","is_source":true},{"name":"xserver-xorg-core","version":"1:1.0.2-0ubuntu10.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/1:1.0.2-0ubuntu10.7"}]},"type":"USN","cves_ids":["CVE-2007-4730"]}]},{"id":"CVE-2007-4784","published":"2007-09-10T21:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe setlocale function in PHP before 5.2.4 allows context-dependent\nattackers to cause a denial of service (application crash) via a long\nstring in the locale parameter. NOTE: this might not be a vulnerability in\nmost web server environments that support multiple threads, unless this\nissue can be demonstrated for code execution.","ubuntu_description":"","notes":[{"author":"kees","note":"local script instance crasher is not a security issue."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4784"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4783","published":"2007-09-10T21:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe iconv_substr function in PHP 5.2.4 and earlier allows context-dependent\nattackers to cause (1) a denial of service (application crash) via a long\nstring in the charset parameter, probably also requiring a long string in\nthe str parameter; or (2) a denial of service (temporary application hang)\nvia a long string in the str parameter. NOTE: this might not be a\nvulnerability in most web server environments that support multiple\nthreads, unless these issues can be demonstrated for code execution.","ubuntu_description":"","notes":[{"author":"kees","note":"local php instance crasher only, not a serious security issue"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4783"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4782","published":"2007-09-10T21:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPHP before 5.2.3 allows context-dependent attackers to cause a denial of\nservice (application crash) via (1) a long string in the pattern parameter\nto the glob function; or (2) a long string in the string parameter to the\nfnmatch function, accompanied by a pattern parameter value with undefined\ncharacteristics, as demonstrated by a \"*[1]e\" value. NOTE: this might not\nbe a vulnerability in most web server environments that support multiple\nthreads, unless these issues can be demonstrated for code execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-628-1","https://www.cve.org/CVERecord?id=CVE-2007-4782"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"5.2.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-628-1"],"notices":[{"id":"USN-628-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-07-23T19:08:24.013715","description":"It was discovered that PHP did not properly check the length of the\nstring parameter to the fnmatch function. An attacker could cause a\ndenial of service in the PHP interpreter if a script passed untrusted\ninput to the fnmatch function. (CVE-2007-4782)\n\nMaksymilian Arciemowicz discovered a flaw in the cURL library that\nallowed safe_mode and open_basedir restrictions to be bypassed. If a\nPHP application were tricked into processing a bad file:// request,\nan attacker could read arbitrary files. (CVE-2007-4850)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas\nof memory, possibly gaining access to sensitive information. This\nissue affects Ubuntu 8.04 LTS, and an updated fix is included for\nUbuntu 6.06 LTS, 7.04 and 7.10. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var function would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. This issue only affects\nUbuntu 8.04 LTS. (CVE-2007-5899)\n\nIt was discovered that PHP did not properly calculate the length of\nPATH_TRANSLATED. If a PHP application were tricked into processing\na malicious URI, and attacker may be able to execute arbitrary code\nwith application privileges. (CVE-2008-0599)\n\nAn integer overflow was discovered in the php_sprintf_appendstring\nfunction. Attackers could exploit this to cause a denial of service.\n(CVE-2008-1384)\n\nAndrei Nigmatulin discovered stack-based overflows in the FastCGI SAPI\nof PHP. An attacker may be able to leverage this issue to perform\nattacks against PHP applications. (CVE-2008-2050)\n\nIt was discovered that the escapeshellcmd did not properly process\nmultibyte characters. An attacker may be able to bypass quoting\nrestrictions and possibly execute arbitrary code with application\nprivileges. (CVE-2008-2051)\n\nIt was discovered that the GENERATE_SEED macro produced a predictable\nseed under certain circumstances. Attackers may by able to easily\npredict the results of the rand and mt_rand functions.\n(CVE-2008-2107, CVE-2008-2108)\n\nTavis Ormandy discovered that the PCRE library did not correctly\nhandle certain in-pattern options. An attacker could cause PHP\napplications using pcre to crash, leading to a denial of service.\nUSN-624-1 fixed vulnerabilities in the pcre3 library. This update\nprovides the corresponding update for PHP. (CVE-2008-2371)\n\nIt was discovered that php_imap used obsolete API calls. If a PHP\napplication were tricked into processing a malicious IMAP request,\nan attacker could cause a denial of service or possibly execute code\nwith application privileges. (CVE-2008-2829)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.4","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.4"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.4"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.4"},{"name":"php5-curl","version":"5.2.3-1ubuntu6.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.4"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.12","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.12"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.12"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.12"},{"name":"php5-curl","version":"5.1.2-1ubuntu3.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.12"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.6"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.6"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.6"},{"name":"php5-curl","version":"5.2.1-0ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.6"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.3","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.3"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.3"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.3"},{"name":"php5-curl","version":"5.2.4-2ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.3"}]},"type":"USN","cves_ids":["CVE-2007-4782","CVE-2007-4850","CVE-2007-5898","CVE-2007-5899","CVE-2008-0599","CVE-2008-1384","CVE-2008-2050","CVE-2008-2051","CVE-2008-2107","CVE-2008-2108","CVE-2008-2371","CVE-2008-2829"]}]},{"id":"CVE-2007-3912","published":"2007-09-10T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncheckrestart in debian-goodies before 0.34 allows local users to gain\nprivileges via shell metacharacters in the name of the executable file for\na running process.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-526-1","https://www.cve.org/CVERecord?id=CVE-2007-3912"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"debian-goodies","source":"https://ubuntu.com/security/cve?package=debian-goodies","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=debian-goodies","debian":"https://tracker.debian.org/pkg/debian-goodies","statuses":[{"release_codename":"dapper","status":"released","description":"0.23ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.23ubuntu0.6.10.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.27ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.34","component":null,"pocket":"security"}]}],"notices_ids":["USN-526-1"],"notices":[{"id":"USN-526-1","title":"debian-goodies vulnerability","summary":"debian-goodies vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-10-04T21:37:33.153016","description":"Thomas de Grenier de Latour discovered that the checkrestart program included\nin debian-goodies did not correctly handle shell meta-characters. A local\nattacker could exploit this to gain the privileges of the user running\ncheckrestart.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"debian-goodies","version":"0.23ubuntu0.6.06.1","description":"","is_source":true},{"name":"debian-goodies","version":"0.23ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/debian-goodies","version_link":"https://launchpad.net/ubuntu/+source/debian-goodies/0.23ubuntu0.6.06.1"}],"feisty":[{"name":"debian-goodies","version":"0.27ubuntu0.1","description":"","is_source":true},{"name":"debian-goodies","version":"0.27ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/debian-goodies","version_link":"https://launchpad.net/ubuntu/+source/debian-goodies/0.27ubuntu0.1"}],"edgy":[{"name":"debian-goodies","version":"0.23ubuntu0.6.10.1","description":"","is_source":true},{"name":"debian-goodies","version":"0.23ubuntu0.6.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/debian-goodies","version_link":"https://launchpad.net/ubuntu/+source/debian-goodies/0.23ubuntu0.6.10.1"}]},"type":"USN","cves_ids":["CVE-2007-3912"]}]},{"id":"CVE-2007-4755","published":"2007-09-08T01:17:00","updated_at":"2025-07-17T16:42:11.785903+00:00","description":"\nAlien Arena 2007 6.10 and earlier allows remote attackers to cause a denial\nof service (client disconnect) by sending a client_connect command in a\nforged packet from the server to a client. NOTE: client IP addresses are\navailable via product-specific queries.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4755"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"alien-arena","source":"https://ubuntu.com/security/cve?package=alien-arena","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=alien-arena","debian":"https://tracker.debian.org/pkg/alien-arena","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4754","published":"2007-09-08T01:17:00","updated_at":"2025-07-17T16:42:11.785903+00:00","description":"\nFormat string vulnerability in the safe_bprintf function in\nacesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote\nattackers to cause a denial of service (daemon crash) via format string\nspecifiers in a nickname.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4754"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"alien-arena","source":"https://ubuntu.com/security/cve?package=alien-arena","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=alien-arena","debian":"https://tracker.debian.org/pkg/alien-arena","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4743","published":"2007-09-06T22:17:00","updated_at":"2025-07-17T16:42:11.785903+00:00","description":"\nThe original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS\nRPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the\nKerberos administration daemon (kadmind) and other applications that use\nkrb5, does not correctly check the buffer length in some environments and\narchitectures, which might allow remote attackers to conduct a buffer\noverflow attack.","ubuntu_description":"","notes":[{"author":"kees","note":"Debian package is missing mention of CVE-2007-4743 (and CVE-2007-4000)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-511-2","https://www.cve.org/CVERecord?id=CVE-2007-4743"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5, 1.6.3","component":null,"pocket":"security"}]},{"name":"librpcsecgss","source":"https://ubuntu.com/security/cve?package=librpcsecgss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=librpcsecgss","debian":"https://tracker.debian.org/pkg/librpcsecgss","statuses":[{"release_codename":"dapper","status":"released","description":"0.7-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.13-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.14-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.16","component":null,"pocket":"security"}]}],"notices_ids":["USN-511-2"],"notices":[{"id":"USN-511-2","title":"Kerberos vulnerability","summary":"Kerberos vulnerability","instructions":"In general, a standard system upgrade is sufficient to affect the\nnecessary changes.\n","references":[],"published":"2007-09-07T15:34:27.058759","description":"USN-511-1 fixed vulnerabilities in krb5 and librpcsecgss. The fixes were\nincomplete, and only reduced the scope of the vulnerability, without fully\nsolving it. This update fixes the problem.\n\nOriginal advisory details:\n\n It was discovered that the libraries handling RPCSEC_GSS did not correctly\n validate the size of certain packet structures. An unauthenticated remote\n user could send a specially crafted request and execute arbitrary code\n with root privileges.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"krb5","version":"1.4.3-5ubuntu0.6","description":"","is_source":true},{"name":"librpcsecgss","version":"0.7-0ubuntu1.2","description":"","is_source":true},{"name":"librpcsecgss1","version":"0.7-0ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/librpcsecgss","version_link":"https://launchpad.net/ubuntu/+source/librpcsecgss/0.7-0ubuntu1.2"},{"name":"libkadm55","version":"1.4.3-5ubuntu0.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.4.3-5ubuntu0.6"}],"feisty":[{"name":"krb5","version":"1.4.4-5ubuntu3.3","description":"","is_source":true},{"name":"librpcsecgss","version":"0.14-2ubuntu1.2","description":"","is_source":true},{"name":"librpcsecgss3","version":"0.14-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/librpcsecgss","version_link":"https://launchpad.net/ubuntu/+source/librpcsecgss/0.14-2ubuntu1.2"},{"name":"libkadm55","version":"1.4.4-5ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.4.4-5ubuntu3.3"}],"edgy":[{"name":"krb5","version":"1.4.3-9ubuntu1.5","description":"","is_source":true},{"name":"librpcsecgss","version":"0.13-2ubuntu0.2","description":"","is_source":true},{"name":"librpcsecgss2","version":"0.13-2ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/librpcsecgss","version_link":"https://launchpad.net/ubuntu/+source/librpcsecgss/0.13-2ubuntu0.2"},{"name":"libkadm55","version":"1.4.3-9ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.4.3-9ubuntu1.5"}]},"type":"USN","cves_ids":["CVE-2007-4743"]}]},{"id":"CVE-2007-3913","published":"2007-09-06T22:17:00","updated_at":"2025-07-17T16:41:55.483691+00:00","description":"\nSQL injection vulnerability in Gforge before 3.1 allows remote attackers to\nexecute arbitrary SQL commands via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3913"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gforge","source":"https://ubuntu.com/security/cve?package=gforge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gforge","debian":"https://tracker.debian.org/pkg/gforge","statuses":[{"release_codename":"dapper","status":"released","description":"3.1-31ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.1-31sarge1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.5.14-22ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4739","published":"2007-09-06T19:17:00","updated_at":"2025-07-17T16:42:09.648205+00:00","description":"\nreprepro 1.3.0 through 2.2.3 does not properly verify signatures when\nupdating repositories, which allows remote attackers to construct and\ndistribute an ostensibly valid Release.gpg file by signing it with an\nunknown key, related to the update command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4739"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"reprepro","source":"https://ubuntu.com/security/cve?package=reprepro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=reprepro","debian":"https://tracker.debian.org/pkg/reprepro","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.2.4-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.2.4-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.2.4-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.2.4-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.2.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4724","published":"2007-09-05T19:17:00","updated_at":"2025-07-17T16:42:09.648205+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar\nexamples application in Apache Tomcat 4.1.31 allows remote attackers to add\nevents as arbitrary users via the time and description parameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4724"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4721","published":"2007-09-05T19:17:00","updated_at":"2025-08-04T19:20:54.977947+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2007-6113. Reason: This candidate is a duplicate of CVE-2007-6113.\nNotes: All CVE users should reference CVE-2007-6113 instead of this\ncandidate. All references and descriptions in this candidate have been\nremoved to prevent accidental usage","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4721"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/wireshark/+bug/132915"],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.4-6ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.99.6rel-3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.99.6rel-3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.99.6rel-3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.99.6rel-3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.99.6rel-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4000","published":"2007-09-05T10:17:00","updated_at":"2025-07-17T16:41:58.173645+00:00","description":"\nThe kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in\nthe Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5\nthrough 1.6.2 does not properly check return values when the policy does\nnot exist, which might allow remote authenticated users with the \"modify\npolicy\" privilege to execute arbitrary code via unspecified vectors that\ntrigger a write to an uninitialized pointer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4000"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3999","published":"2007-09-05T10:17:00","updated_at":"2025-07-17T16:41:58.173645+00:00","description":"\nStack-based buffer overflow in the svcauth_gss_validate function in\nlib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT\nKerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration\ndaemon (kadmind) and some third-party applications that use krb5, allows\nremote attackers to cause a denial of service (daemon crash) and probably\nexecute arbitrary code via a long string in an RPC message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-511-1","https://www.cve.org/CVERecord?id=CVE-2007-3999"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"librpcsecgss","source":"https://ubuntu.com/security/cve?package=librpcsecgss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=librpcsecgss","debian":"https://tracker.debian.org/pkg/librpcsecgss","statuses":[{"release_codename":"dapper","status":"released","description":"0.7-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.13-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.14-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-511-1"],"notices":[{"id":"USN-511-1","title":"Kerberos vulnerability","summary":"Kerberos vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-09-04T22:45:47.420214","description":"It was discovered that the libraries handling RPCSEC_GSS did not correctly\nvalidate the size of certain packet structures. An unauthenticated remote\nuser could send a specially crafted request and execute arbitrary code\nwith root privileges.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"krb5","version":"1.4.3-5ubuntu0.5","description":"","is_source":true},{"name":"librpcsecgss","version":"0.7-0ubuntu1.1","description":"","is_source":true},{"name":"librpcsecgss1","version":"0.7-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/librpcsecgss","version_link":"https://launchpad.net/ubuntu/+source/librpcsecgss/0.7-0ubuntu1.1"},{"name":"libkadm55","version":"1.4.3-5ubuntu0.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.4.3-5ubuntu0.5"}],"feisty":[{"name":"krb5","version":"1.4.4-5ubuntu3.2","description":"","is_source":true},{"name":"librpcsecgss","version":"0.14-2ubuntu1.1","description":"","is_source":true},{"name":"librpcsecgss3","version":"0.14-2ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/librpcsecgss","version_link":"https://launchpad.net/ubuntu/+source/librpcsecgss/0.14-2ubuntu1.1"},{"name":"libkadm55","version":"1.4.4-5ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.4.4-5ubuntu3.2"}],"edgy":[{"name":"krb5","version":"1.4.3-9ubuntu1.4","description":"","is_source":true},{"name":"librpcsecgss","version":"0.13-2ubuntu0.1","description":"","is_source":true},{"name":"librpcsecgss2","version":"0.13-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/librpcsecgss","version_link":"https://launchpad.net/ubuntu/+source/librpcsecgss/0.13-2ubuntu0.1"},{"name":"libkadm55","version":"1.4.3-9ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.4.3-9ubuntu1.4"}]},"type":"USN","cves_ids":["CVE-2007-3999"]}]},{"id":"CVE-2007-4476","published":"2007-09-05T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the safer_name_suffix function in GNU tar has\nunspecified attack vectors and impact, resulting in a \"crashing stack.\"","ubuntu_description":"","notes":[{"author":"jdstrand","note":"1.19 has the fixes, 1.18 as included in Gutsy does not"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=441444","https://bugzilla.redhat.com/show_bug.cgi?id=280961","https://ubuntu.com/security/notices/USN-650-1","https://ubuntu.com/security/notices/USN-709-1","https://www.cve.org/CVERecord?id=CVE-2007-4476"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/cpio/+bug/161173","https://bugs.launchpad.net/ubuntu/+source/cpio/+bug/163831","https://bugs.launchpad.net/ubuntu/+source/tar/+bug/180299"],"patches":{"tar":["vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;filename=tar-paxlib-owl-alloca.patch;att=1;bug=441444"],"cpio":["other: https://bugs.launchpad.net/ubuntu/+source/cpio/+bug/161173","vendor: http://www.debian.org/security/2008/dsa-1566"]},"tags":{},"packages":[{"name":"cpio","source":"https://ubuntu.com/security/cve?package=cpio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cpio","debian":"https://tracker.debian.org/pkg/cpio","statuses":[{"release_codename":"dapper","status":"released","description":"2.6-10ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6-17ubuntu0.7.04.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.8-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.9-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.9-13ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9-5","component":null,"pocket":"security"}]},{"name":"tar","source":"https://ubuntu.com/security/cve?package=tar","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tar","debian":"https://tracker.debian.org/pkg/tar","statuses":[{"release_codename":"dapper","status":"released","description":"1.15.1-2ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.18-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.18-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-709-1","USN-650-1"],"notices":[{"id":"USN-709-1","title":"tar vulnerability","summary":"tar vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-01-15T21:56:48.409157","description":"Dmitry V. Levin discovered a buffer overflow in tar. If a user or automated\nsystem were tricked into opening a specially crafted tar file, an attacker\ncould crash tar or possibly execute arbitrary code with the privileges of the\nuser invoking the program.\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"tar","version":"1.18-2ubuntu1.1","description":"","is_source":true},{"name":"tar","version":"1.18-2ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tar","version_link":"https://launchpad.net/ubuntu/+source/tar/1.18-2ubuntu1.1"}],"dapper":[{"name":"tar","version":"1.15.1-2ubuntu2.3","description":"","is_source":true},{"name":"tar","version":"1.15.1-2ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tar","version_link":"https://launchpad.net/ubuntu/+source/tar/1.15.1-2ubuntu2.3"}]},"type":"USN","cves_ids":["CVE-2007-4476"]},{"id":"USN-650-1","title":"cpio vulnerability","summary":"cpio vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-10-02T17:12:46.828690","description":"A buffer overflow was discovered in cpio. If a user were tricked into\nopening a crafted cpio archive, an attacker could cause a denial of\nservice via application crash, or possibly execute code with the\nprivileges of the user invoking the program. (CVE-2007-4476)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"cpio","version":"2.8-1ubuntu2.2","description":"","is_source":true},{"name":"cpio","version":"2.8-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cpio","version_link":"https://launchpad.net/ubuntu/+source/cpio/2.8-1ubuntu2.2"}],"dapper":[{"name":"cpio","version":"2.6-10ubuntu0.3","description":"","is_source":true},{"name":"cpio","version":"2.6-10ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cpio","version_link":"https://launchpad.net/ubuntu/+source/cpio/2.6-10ubuntu0.3"}],"feisty":[{"name":"cpio","version":"2.6-17ubuntu0.7.04.1","description":"","is_source":true},{"name":"cpio","version":"2.6-17ubuntu0.7.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cpio","version_link":"https://launchpad.net/ubuntu/+source/cpio/2.6-17ubuntu0.7.04.1"}]},"type":"USN","cves_ids":["CVE-2007-4476"]}]},{"id":"CVE-2007-4135","published":"2007-09-05T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return\nvalues from the getpwnam_r function when performing a username lookup,\nwhich can cause it to report a file as being owned by \"root\" instead of\n\"nobody\" if the file exists on the server but not on the client.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"fix in RHSA-2007:0951-01"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4135"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/libnfsidmap/+bug/175317"],"patches":{},"tags":{},"packages":[{"name":"libnfsidmap","source":"https://ubuntu.com/security/cve?package=libnfsidmap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libnfsidmap","debian":"https://tracker.debian.org/pkg/libnfsidmap","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.18-0build1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.19-0","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.19-0","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.19-0","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.19-0","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.19-0","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.19-0","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.19-0","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"0.19-0","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.17","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4670","published":"2007-09-05T00:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in PHP before 5.2.4 has unknown impact and attack\nvectors, related to an \"Improved fix for MOPB-03-2007,\" probably a variant\nof CVE-2007-1285.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-549-1","https://www.cve.org/CVERecord?id=CVE-2007-4670"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-549-1"],"notices":[{"id":"USN-549-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-11-29T22:38:09.391050","description":"It was discovered that the wordwrap function did not correctly\ncheck lengths. Remote attackers could exploit this to cause\na crash or monopolize CPU resources, resulting in a denial of\nservice. (CVE-2007-3998)\n\nInteger overflows were discovered in the strspn and strcspn functions.\nAttackers could exploit this to read arbitrary areas of memory, possibly\ngaining access to sensitive information. (CVE-2007-4657)\n\nStanislav Malyshev discovered that money_format function did not correctly\nhandle certain tokens. If a PHP application were tricked into processing\na bad format string, a remote attacker could execute arbitrary code with\napplication privileges. (CVE-2007-4658)\n\nIt was discovered that the php_openssl_make_REQ function did not\ncorrectly check buffer lengths. A remote attacker could send a\nspecially crafted message and execute arbitrary code with application\nprivileges. (CVE-2007-4662)\n\nIt was discovered that certain characters in session cookies were not\nhandled correctly. A remote attacker could injection values which could\nlead to altered application behavior, potentially gaining additional\nprivileges. (CVE-2007-3799)\n\nGerhard Wagner discovered that the chunk_split function did not\ncorrectly handle long strings. A remote attacker could exploit this\nto execute arbitrary code with application privileges. (CVE-2007-2872,\nCVE-2007-4660, CVE-2007-4661)\n\nStefan Esser discovered that deeply nested arrays could be made to\nfill stack space. A remote attacker could exploit this to cause a\ncrash or monopolize CPU resources, resulting in a denial of service.\n(CVE-2007-1285, CVE-2007-4670)\n\nRasmus Lerdorf discovered that the htmlentities and htmlspecialchars\nfunctions did not correctly stop when handling partial multibyte\nsequences. A remote attacker could exploit this to read certain areas of\nmemory, possibly gaining access to sensitive information. (CVE-2007-5898)\n\nIt was discovered that the output_add_rewrite_var fucntion would\nsometimes leak session id information to forms targeting remote URLs.\nMalicious remote sites could use this information to gain access to a\nPHP application user's login credentials. (CVE-2007-5899)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.1"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.10","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.10"}],"feisty":[{"name":"php5","version":"5.2.1-0ubuntu1.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.1-0ubuntu1.5"}],"edgy":[{"name":"php5","version":"5.1.6-1ubuntu2.7","description":"","is_source":true},{"name":"php5-cli","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.6-1ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2007-1285","CVE-2007-2872","CVE-2007-3799","CVE-2007-3998","CVE-2007-4657","CVE-2007-4658","CVE-2007-4660","CVE-2007-4661","CVE-2007-4662","CVE-2007-4670","CVE-2007-5898","CVE-2007-5899"]}]},{"id":"CVE-2007-4669","published":"2007-09-04T22:17:00","updated_at":"2025-07-17T16:42:09.648205+00:00","description":"\nThe Services API in Firebird before 2.0.2 allows remote authenticated users\nwithout SYSDBA privileges to read the server log (firebird.log), aka\nCORE-1148.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4669"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firebird2.0","source":"https://ubuntu.com/security/cve?package=firebird2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2.0","debian":"https://tracker.debian.org/pkg/firebird2.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":76180,"limit":20,"total_results":79316}