{"cves":[{"id":"CVE-2007-4405","published":"2007-08-18T21:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nircu 2.10.12.02 through 2.10.12.04 allows remote attackers to cause a\ndenial of service (memory and bandwidth consumption) by creating a large\nnumber of unused channels (zannels).","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Only affects >= 2.10.12.01."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4405"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ircd-ircu","source":"https://ubuntu.com/security/cve?package=ircd-ircu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ircd-ircu","debian":"https://tracker.debian.org/pkg/ircd-ircu","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4404","published":"2007-08-18T21:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nircu 2.10.12.01 allows remote attackers to (1) cause a denial of service\n(flood wallops) by joining two channels with certain long names that differ\nin the final character, which triggers a protocol violation and (2) cause a\ndenial of service (daemon crash) via a \"J 0:#channel\" message on a channel\nwithout an apass; and (3) allows remote authenticated operators to cause a\ndenial of service (daemon crash) via a remote \"names -D\" command.","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Only affects >= 2.10.12.01."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4404"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ircd-ircu","source":"https://ubuntu.com/security/cve?package=ircd-ircu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ircd-ircu","debian":"https://tracker.debian.org/pkg/ircd-ircu","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4400","published":"2007-08-18T21:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCRLF injection vulnerability in the included media script in Konversation\nallows user-assisted remote attackers to execute arbitrary IRC commands via\nCRLF sequences in the name of the song in a .mp3 file.","ubuntu_description":"","notes":[{"author":"kees","note":"requires a malicious MP3 get played while id3 display plugin is running"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://svn.debian.org/wsvn/pkg-kde/kde-extras/konversation/trunk/debian/patches/15_CVE-2007-4400.diff?op=file&rev=0&sc=0","https://www.cve.org/CVERecord?id=CVE-2007-4400"],"bugs":[""],"patches":{"konversation":["vendor: http://svn.debian.org/wsvn/pkg-kde/kde-extras/konversation/trunk/debian/patches/15_CVE-2007-4400.diff?op=file&rev=0&sc=0"]},"tags":{},"packages":[{"name":"konversation","source":"https://ubuntu.com/security/cve?package=konversation","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=konversation","debian":"https://tracker.debian.org/pkg/konversation","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.0.1-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.0.1-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0.1-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.1-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4398","published":"2007-08-18T21:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nMultiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2)\nxmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to\nexecute arbitrary IRC commands via CRLF sequences in the name of the song\nin a .mp3 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4398"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"weechat-scripts","source":"https://ubuntu.com/security/cve?package=weechat-scripts","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=weechat-scripts","debian":"https://tracker.debian.org/pkg/weechat-scripts","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"20070425-0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"20070425-0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4396","published":"2007-08-18T21:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nMultiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2)\nl33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0,\n(6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before\n0.8.11 allow user-assisted remote attackers to execute arbitrary IRC\ncommands via CRLF sequences in the name of the song in a .mp3 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4396"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"irssi-scripts","source":"https://ubuntu.com/security/cve?package=irssi-scripts","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=irssi-scripts","debian":"https://tracker.debian.org/pkg/irssi-scripts","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"20070925","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"20070925","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"20070925","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"20070925","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"20070925","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4381","published":"2007-08-17T21:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nUnspecified vulnerability in the font parsing implementation in Sun JDK and\nJRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows\nremote attackers to perform unauthorized actions via an applet that grants\ncertain privileges to itself.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4381"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4091","published":"2007-08-16T00:17:00","updated_at":"2025-07-17T16:41:59.706330+00:00","description":"\nMultiple off-by-one errors in the sender.c in rsync 2.6.9 might allow\nremote attackers to execute arbitrary code via directory names that are not\nproperly handled when calling the f_name function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-500-1","https://www.cve.org/CVERecord?id=CVE-2007-4091"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"rsync","source":"https://ubuntu.com/security/cve?package=rsync","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rsync","debian":"https://tracker.debian.org/pkg/rsync","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.6-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.8-2ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.9-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-500-1"],"notices":[{"id":"USN-500-1","title":"rsync vulnerability","summary":"rsync vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-08-20T22:37:44","description":"Sebastian Krahmer discovered that rsync contained an off-by-one\nmiscalculation when handling certain file paths.  By creating a specially\ncrafted tree of files and tricking an rsync server into processing them,\na remote attacker could write a single NULL to stack memory, possibly\nleading to arbitrary code execution.","is_hidden":false,"release_packages":{"dapper":[{"name":"rsync","version":"2.6.6-1ubuntu2.1","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"rsync","version":"2.6.9-3ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"rsync","version":"2.6.8-2ubuntu3.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-4091"]}]},{"id":"CVE-2007-4367","published":"2007-08-15T23:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nOpera before 9.23 allows remote attackers to execute arbitrary code via\ncrafted Javascript that triggers a \"virtual function call on an invalid\npointer.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4367"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"opera","source":"https://ubuntu.com/security/cve?package=opera","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=opera","debian":"https://tracker.debian.org/pkg/opera","statuses":[{"release_codename":"dapper","status":"released","description":"9.23-20070809.6dapper1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"9.23-20070809.6edgy1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"9.23-20070809.6feisty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.23","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4366","published":"2007-08-15T19:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nWengoPhone 2.1 allows remote attackers to cause a denial of service (device\ncrash) via a SIP INVITE message without a Content-Type header.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4366"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wengophone","source":"https://ubuntu.com/security/cve?package=wengophone","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wengophone","debian":"https://tracker.debian.org/pkg/wengophone","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.1.1.dfsg0-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.1.1.dfsg0-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.1.1.dfsg0-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4357","published":"2007-08-15T00:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the\ncontents of the status bar via a link to a data: URI containing an encoded\nURL.  NOTE: the severity of this issue has been disputed by a reliable\nthird party, since the intended functionality of the status bar allows it\nto be modified.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"disputed, let's ignore"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4357"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3386","published":"2007-08-14T22:17:00","updated_at":"2025-07-17T16:41:43.741697+00:00","description":"\nCross-site scripting (XSS) vulnerability in the Host Manager Servlet for\nApache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers\nto inject arbitrary HTML and web script via crafted requests, as\ndemonstrated using the aliases parameter to an html/add action.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3386"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/tomcat5/+bug/175505"],"patches":{},"tags":{},"packages":[{"name":"tomcat5","source":"https://ubuntu.com/security/cve?package=tomcat5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5","debian":"https://tracker.debian.org/pkg/tomcat5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3385","published":"2007-08-14T22:17:00","updated_at":"2025-07-17T16:41:43.741697+00:00","description":"\nApache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to\n4.1.36, and 3.3 to 3.3.2 does not properly handle the \\\" character sequence\nin a cookie value, which might cause sensitive information such as session\nIDs to be leaked to remote attackers and enable session hijacking attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3385"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/tomcat5/+bug/175505"],"patches":{},"tags":{},"packages":[{"name":"tomcat5","source":"https://ubuntu.com/security/cve?package=tomcat5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5","debian":"https://tracker.debian.org/pkg/tomcat5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.25","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3382","published":"2007-08-14T22:17:00","updated_at":"2025-07-17T16:41:43.741697+00:00","description":"\nApache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to\n4.1.36, and 3.3 to 3.3.2 treats single quotes (\"'\") as delimiters in\ncookies, which might cause sensitive information such as session IDs to be\nleaked and allow remote attackers to conduct session hijacking attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3382"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/tomcat5/+bug/175505"],"patches":{},"tags":{},"packages":[{"name":"tomcat5","source":"https://ubuntu.com/security/cve?package=tomcat5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5","debian":"https://tracker.debian.org/pkg/tomcat5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.5.25-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.25","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4337","published":"2007-08-14T18:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nMultiple buffer overflows in the httplib_parse_sc_header function in\nlib/http.c in Streamripper before 1.62.2 allow remote attackers to execute\narbitrary code via long (1) Location and (2) Server HTTP headers, a\ndifferent vulnerability than CVE-2006-3124.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4337"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"streamripper","source":"https://ubuntu.com/security/cve?package=streamripper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=streamripper","debian":"https://tracker.debian.org/pkg/streamripper","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3852","published":"2007-08-14T18:17:00","updated_at":"2025-07-17T16:41:54.036995+00:00","description":"\nThe init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates\n/tmp/sysstat.run insecurely, which allows local users to execute arbitrary\ncode.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3852"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sysstat","source":"https://ubuntu.com/security/cve?package=sysstat","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sysstat","debian":"https://tracker.debian.org/pkg/sysstat","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3848","published":"2007-08-14T17:17:00","updated_at":"2025-07-17T16:41:54.036995+00:00","description":"\nLinux kernel 2.4.35 and other versions allows local users to send arbitrary\nsignals to a child process that is running at higher privileges by causing\na setuid-root parent process to die, which delivers an attacker-controlled\nparent process death signal (PR_SET_PDEATHSIG).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-510-1","https://ubuntu.com/security/notices/USN-509-1","https://ubuntu.com/security/notices/USN-508-1","https://www.cve.org/CVERecord?id=CVE-2007-3848"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-510-1","USN-509-1","USN-508-1"],"notices":[{"id":"USN-510-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-31T17:39:43.796283","description":"A flaw was discovered in the PPP over Ethernet implementation.  Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem.  If mounted,\nlocal attackers could obtain kernel memory using large file offsets while\nreading the tasks file. This could disclose sensitive data. (CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states.  A remote attacker could send a specially crafted\npacket causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems.  A local attacker could corrupt a kernel_dirent struct and cause\na denial of service. (CVE-2007-2878)\n\nA flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator.  In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver.  A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nZhongling Wen discovered that the h323 conntrack handler did not correctly\nhandle certain bitfields.  A remote attacker could send a specially crafted\npacket and cause a denial of service. (CVE-2007-3642)\n\nA flaw was discovered in the CIFS mount security checking.  Remote attackers\ncould spoof CIFS network traffic, which could lead a client to trust the\nconnection. (CVE-2007-3843)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers.  A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations.  An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls.  A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-16.31","description":"","is_source":true},{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"}]},"type":"USN","cves_ids":["CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878","CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3642","CVE-2007-3843","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]},{"id":"USN-509-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-30T23:55:46.418455","description":"A flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator.  In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver.  A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers.  A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations.  An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls.  A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"edgy":[{"name":"linux-source-2.6.17","version":"2.6.17.1-12.40","description":"","is_source":true},{"name":"linux-image-2.6.17-12-mckinley","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc64-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-hppa32","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-hppa64","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-sparc64-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-generic","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-386","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-server-bigiron","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-itanium","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-sparc64","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-server","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"}]},"type":"USN","cves_ids":["CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]},{"id":"USN-508-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2007-08-31T04:16:11.939627","description":"A buffer overflow was discovered in the Moxa serial driver.  Local\nattackers could execute arbitrary code and gain root privileges.\n(CVE-2005-0504)\n\nA flaw was discovered in the IPv6 stack's handling of type 0 route headers.\nBy sending a specially crafted IPv6 packet, a remote attacker could cause\na denial of service between two IPv6 hosts. (CVE-2007-2242)\n\nA flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator.  In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers.  A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls.  A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-29.58","description":"","is_source":true},{"name":"linux-image-2.6.15-29-amd64-xeon","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa32-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-server-bigiron","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-386","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-686","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-powerpc","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-sparc64","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-amd64-k8","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa32","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-k7","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa64-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-mckinley-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-amd64-generic","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-itanium-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-amd64-server","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-itanium","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-powerpc-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-powerpc64-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-server","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-mckinley","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa64","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-sparc64-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"}]},"type":"USN","cves_ids":["CVE-2005-0504","CVE-2007-2242","CVE-2007-3104","CVE-2007-3105","CVE-2007-3848","CVE-2007-4308"]}]},{"id":"CVE-2007-4324","published":"2007-08-14T00:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and\nother 9.0.124.0 and earlier versions, allows remote attackers to bypass the\nSecurity Sandbox Model, obtain sensitive information, and port scan\narbitrary hosts via a Flash (SWF) movie that specifies a connection to\nmake, then uses timing discrepancies from the SecurityErrorEvent error to\ndetermine whether a port is open or not.  NOTE: 9.0.115.0 introduces\nsupport for a workaround, but does not fix the vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4324"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/flashplugin-nonfree/+bug/177777"],"patches":{},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"released","description":"10.0.12.36","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.0.246.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"10.0.32.18ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.0.32.18ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4323","published":"2007-08-14T00:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDenyHosts 2.6 does not properly parse sshd log files, which allows remote\nattackers to add arbitrary hosts to the /etc/hosts.deny file and cause a\ndenial of service by adding arbitrary IP addresses to the sshd log file, as\ndemonstrated by logging in via ssh with a client protocol version\nidentification containing an IP address string, a different vector than\nCVE-2006-6301.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4323"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/denyhosts/+bug/162406"],"patches":{},"tags":{},"packages":[{"name":"denyhosts","source":"https://ubuntu.com/security/cve?package=denyhosts","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=denyhosts","debian":"https://tracker.debian.org/pkg/denyhosts","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.5-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6-2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4321","published":"2007-08-14T00:17:00","updated_at":"2025-07-17T16:42:03.031378+00:00","description":"\nfail2ban 0.8 and earlier does not properly parse sshd log files, which\nallows remote attackers to add arbitrary hosts to the /etc/hosts.deny file\nand cause a denial of service by adding arbitrary IP addresses to the sshd\nlog file, as demonstrated by logging in via ssh with a client protocol\nversion identification containing an IP address string, a different vector\nthan CVE-2006-6302.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4321"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/fail2ban/+bug/181722"],"patches":{"fail2ban":["vendor: http://www.debian.org/security/2008/dsa-1456"]},"tags":{},"packages":[{"name":"fail2ban","source":"https://ubuntu.com/security/cve?package=fail2ban","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=fail2ban","debian":"https://tracker.debian.org/pkg/fail2ban","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.8.0-4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.8.0-4","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.8.0-4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.8.0-4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.8.0-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4308","published":"2007-08-13T21:17:00","updated_at":"2025-07-17T16:42:01.322060+00:00","description":"\nThe (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer\nioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check\npermissions for ioctls, which might allow local users to cause a denial of\nservice or gain privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-510-1","https://ubuntu.com/security/notices/USN-509-1","https://ubuntu.com/security/notices/USN-508-1","https://www.cve.org/CVERecord?id=CVE-2007-4308"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-510-1","USN-509-1","USN-508-1"],"notices":[{"id":"USN-510-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-31T17:39:43.796283","description":"A flaw was discovered in the PPP over Ethernet implementation.  Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem.  If mounted,\nlocal attackers could obtain kernel memory using large file offsets while\nreading the tasks file. This could disclose sensitive data. (CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states.  A remote attacker could send a specially crafted\npacket causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems.  A local attacker could corrupt a kernel_dirent struct and cause\na denial of service. (CVE-2007-2878)\n\nA flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator.  In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver.  A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nZhongling Wen discovered that the h323 conntrack handler did not correctly\nhandle certain bitfields.  A remote attacker could send a specially crafted\npacket and cause a denial of service. (CVE-2007-3642)\n\nA flaw was discovered in the CIFS mount security checking.  Remote attackers\ncould spoof CIFS network traffic, which could lead a client to trust the\nconnection. (CVE-2007-3843)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers.  A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations.  An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls.  A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-16.31","description":"","is_source":true},{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"}]},"type":"USN","cves_ids":["CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878","CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3642","CVE-2007-3843","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]},{"id":"USN-509-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-30T23:55:46.418455","description":"A flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator.  In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver.  A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers.  A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations.  An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls.  A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"edgy":[{"name":"linux-source-2.6.17","version":"2.6.17.1-12.40","description":"","is_source":true},{"name":"linux-image-2.6.17-12-mckinley","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc64-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-hppa32","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-hppa64","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-sparc64-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-generic","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-386","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-server-bigiron","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-itanium","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-sparc64","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-server","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"}]},"type":"USN","cves_ids":["CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]},{"id":"USN-508-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2007-08-31T04:16:11.939627","description":"A buffer overflow was discovered in the Moxa serial driver.  Local\nattackers could execute arbitrary code and gain root privileges.\n(CVE-2005-0504)\n\nA flaw was discovered in the IPv6 stack's handling of type 0 route headers.\nBy sending a specially crafted IPv6 packet, a remote attacker could cause\na denial of service between two IPv6 hosts. (CVE-2007-2242)\n\nA flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator.  In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers.  A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls.  A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-29.58","description":"","is_source":true},{"name":"linux-image-2.6.15-29-amd64-xeon","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa32-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-server-bigiron","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-386","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-686","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-powerpc","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-sparc64","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-amd64-k8","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa32","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-k7","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa64-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-mckinley-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-amd64-generic","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-itanium-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-amd64-server","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-itanium","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-powerpc-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-powerpc64-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-server","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-mckinley","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa64","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-sparc64-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"}]},"type":"USN","cves_ids":["CVE-2005-0504","CVE-2007-2242","CVE-2007-3104","CVE-2007-3105","CVE-2007-3848","CVE-2007-4308"]}]}],"offset":76260,"limit":20,"total_results":79316}