{"cves":[{"id":"CVE-2007-1825","published":"2007-04-02T23:19:00","updated_at":"2025-07-17T16:41:11.950899+00:00","description":"\nBuffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1,\nand PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code\nvia a long boundary string in a type.parameters field. NOTE: as of\n20070411, it appears that this issue might be subsumed by CVE-2007-0906.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1825"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1824","published":"2007-04-02T23:19:00","updated_at":"2025-07-17T16:41:11.950899+00:00","description":"\nBuffer overflow in the php_stream_filter_create function in PHP 5 before\n5.2.1 allows remote attackers to cause a denial of service (application\ncrash) via a php://filter/ URL that has a name ending in the '.' character.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-455-1","https://www.cve.org/CVERecord?id=CVE-2007-1824"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-455-1"],"notices":[{"id":"USN-455-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-04-27T21:10:26","description":"Stefan Esser discovered multiple vulnerabilities in the \"Month of PHP\nbugs\".\n\nThe substr_compare() function did not sufficiently verify its length\nargument. This might be exploited to read otherwise unaccessible\nmemory, which might lead to information disclosure. (CVE-2007-1375)\n\nThe shared memory (shmop) functions did not verify resource types,\nthus they could be called with a wrong resource type that might\ncontain user supplied data. This could be exploited to read and write\narbitrary memory addresses of the PHP interpreter. This issue does\nnot affect Ubuntu 7.04. (CVE-2007-1376)\n\nThe php_binary handler of the session extension was missing a boundary\ncheck. When unserializing overly long variable names this could be\nexploited to read up to 126 bytes of memory, which might lead to\ninformation disclosure. (CVE-2007-1380)\n\nThe internal array_user_key_compare() function, as used for example by\nthe PHP function uksort(), incorrectly handled memory unreferencing of\nits arguments. This could have been exploited to execute arbitrary\ncode with the privileges of the PHP interpreter, and thus\ncircumventing any disable_functions, open_basedir, or safe_mode\nrestrictions. (CVE-2007-1484)\n\nThe session_regenerate_id() function did not properly clean up the\nformer session identifier variable. This could be exploited to crash\nthe PHP interpreter, possibly also remotely. (CVE-2007-1521)\n\nUnder certain conditions the mb_parse_str() could cause the\nregister_globals configuration option to become permanently enabled.\nThis opened an attack vector for a large and common class of\nvulnerabilities. (CVE-2007-1583)\n\nThe session extension did not set the correct reference count value\nfor the session variables. By unsetting _SESSION and HTTP_SESSION_VARS\n(or tricking a PHP script into doing that) this could be exploited to\nexecute arbitrary code with the privileges of the PHP interpreter. This\nissue does not affect Ubuntu 7.04. (CVE-2007-1700)\n\nThe mail() function did not correctly escape control characters in\nmultiline email headers. This could be remotely exploited to inject\narbitrary email headers. (CVE-2007-1718)\n\nThe php_stream_filter_create() function had an off-by-one buffer\noverflow in the handling of wildcards. This could be exploited to\nremotely crash the PHP interpreter. This issue does not affect Ubuntu\n7.04. (CVE-2007-1824)\n\nWhen calling the sqlite_udf_decode_binary() with special arguments, a\nbuffer overflow happened. Depending on the application this could be\nlocally or remotely exploited to execute arbitrary code with the\nprivileges of the PHP interpreter. (CVE-2007-1887 CVE-2007-1888)\n\nThe FILTER_VALIDATE_EMAIL filter extension used a wrong\nregular expression that allowed injecting a newline character at the\nend of the email string. This could be exploited to inject \narbitrary email headers. This issue only affects Ubuntu 7.04.\n(CVE-2007-1900)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"php5-cli","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1888","CVE-2007-1700","CVE-2007-1380","CVE-2007-1900","CVE-2007-1375","CVE-2007-1887","CVE-2007-1521","CVE-2007-1718","CVE-2007-1484","CVE-2007-1376","CVE-2007-1824","CVE-2007-1583"]}]},{"id":"CVE-2007-1804","published":"2007-04-02T23:19:00","updated_at":"2025-07-17T16:41:11.950899+00:00","description":"\nPulseAudio 0.9.5 allows remote attackers to cause a denial of service\n(daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of\nFRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export\nassertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0\nsent on TCP port 9875, which triggers a length assertion failure in\npa_memblock_new; or (3) an empty packet on UDP port 9875, which triggers a\nt assertion failure in pa_sdp_parse; and allows remote authenticated users\nto cause a denial of service (daemon crash) via a crafted packet on TCP\nport 9875 that (4) triggers a maxlength assertion failure in\npa_memblockq_new, (5) triggers a size assertion failure in pa_xmalloc, or\n(6) plays a certain sound file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-465-1","https://www.cve.org/CVERecord?id=CVE-2007-1804"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"pulseaudio","source":"https://ubuntu.com/security/cve?package=pulseaudio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pulseaudio","debian":"https://tracker.debian.org/pkg/pulseaudio","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.9.5-5ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-465-1"],"notices":[{"id":"USN-465-1","title":"PulseAudio vulnerability","summary":"PulseAudio vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-05-25T23:33:44","description":"Luigi Auriemma discovered multiple flaws in pulseaudio's network\nprocessing code. If an unauthenticated attacker sent specially crafted\nrequests to the pulseaudio daemon, it would crash, resulting in a denial\nof service.","is_hidden":false,"release_packages":{"feisty":[{"name":"pulseaudio","version":"0.9.5-5ubuntu4.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1804"]}]},{"id":"CVE-2007-1799","published":"2007-04-02T22:19:00","updated_at":"2025-07-17T16:41:11.950899+00:00","description":"\nDirectory traversal vulnerability in torrent.cpp in KTorrent before 2.1.3\nonly checks for the \"..\" string, which allows remote attackers to overwrite\narbitrary files via modified \"..\" sequences in a torrent filename, as\ndemonstrated by \"../\" sequences, due to an incomplete fix for\nCVE-2007-1384.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-436-2","https://www.cve.org/CVERecord?id=CVE-2007-1799"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ktorrent","source":"https://ubuntu.com/security/cve?package=ktorrent","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ktorrent","debian":"https://tracker.debian.org/pkg/ktorrent","statuses":[{"release_codename":"dapper","status":"released","description":"1.2-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.3+dfsg1-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.1-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-436-2"],"notices":[{"id":"USN-436-2","title":"KTorrent vulnerability","summary":"KTorrent vulnerability","instructions":"After a standard system upgrade you need to restart KTorrent to effect \nthe necessary changes.","references":[],"published":"2007-05-18T21:52:32","description":"USN-436-1 fixed a vulnerability in KTorrent. The original fix for path \ntraversal was incomplete, allowing for alternate vectors of attack. \nThis update solves the problem.\n\nOriginal advisory details:\n\n Bryan Burns of Juniper Networks discovered that KTorrent did not \n correctly validate the destination file paths nor the HAVE statements \n sent by torrent peers. A malicious remote peer could send specially \n crafted messages to overwrite files or execute arbitrary code with user \n privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"ktorrent","version":"1.2-0ubuntu5.2","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"ktorrent","version":"2.1-0ubuntu2.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"ktorrent","version":"2.0.3+dfsg1-0ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1799"]}]},{"id":"CVE-2007-1797","published":"2007-04-02T22:19:00","updated_at":"2025-07-17T16:41:11.950899+00:00","description":"\nMultiple integer overflows in ImageMagick before 6.3.3-5 allow remote\nattackers to execute arbitrary code via (1) a crafted DCM image, which\nresults in a heap-based overflow in the ReadDCMImage function, or (2) the\n(a) colors or (b) comments field in a crafted XWD image, which results in a\nheap-based overflow in the ReadXWDImage function, different issues than\nCVE-2007-1667.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-481-1","https://www.cve.org/CVERecord?id=CVE-2007-1797"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.8-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.8-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"dapper","status":"released","description":"6.2.4.5-0.6ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"6.2.4.5.dfsg1-0.10ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"6.2.4.5.dfsg1-0.14ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"6.2.4.5.dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.2.4.5.dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-481-1"],"notices":[{"id":"USN-481-1","title":"ImageMagick vulnerabilities","summary":"ImageMagick vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-07-10T13:32:46","description":"Multiple vulnerabilities were found in ImageMagick's handling of DCM and\nWXD image files. By tricking a user into processing a specially crafted\nimage with an application that uses imagemagick, an attacker could\nexecute arbitrary code with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libmagick9","version":"6:6.2.4.5-0.6ubuntu0.6","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"libmagick9","version":"7:6.2.4.5.dfsg1-0.14ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libmagick9","version":"7:6.2.4.5.dfsg1-0.10ubuntu0.3","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1667","CVE-2007-1797"]}]},{"id":"CVE-2007-1789","published":"2007-03-31T10:19:00","updated_at":"2025-07-17T16:41:11.950899+00:00","description":"\nFlyspray 0.9.9 allows remote attackers to obtain sensitive information\n(private project summaries) via direct requests.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1789"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"flyspray","source":"https://ubuntu.com/security/cve?package=flyspray","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flyspray","debian":"https://tracker.debian.org/pkg/flyspray","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1788","published":"2007-03-31T10:19:00","updated_at":"2025-07-17T16:41:11.950899+00:00","description":"\nFlyspray 0.9.9, when output_buffering is disabled or \"set to a low value,\"\nallows remote attackers to bypass authentication via a crafted post\nrequest.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1788"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"flyspray","source":"https://ubuntu.com/security/cve?package=flyspray","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flyspray","debian":"https://tracker.debian.org/pkg/flyspray","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.9.8-10","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.9.8-10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1777","published":"2007-03-30T01:19:00","updated_at":"2025-07-17T16:41:11.950899+00:00","description":"\nInteger overflow in the zip_read_entry function in PHP 4 before 4.4.5\nallows remote attackers to execute arbitrary code via a ZIP archive that\ncontains an entry with a length value of 0xffffffff, which is incremented\nbefore use in an emalloc call, triggering a heap overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1777"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7180","published":"2007-03-30T01:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nieee80211_output.c in MadWifi before 0.9.3 sends unencrypted packets before\nWPA authentication succeeds, which allows remote attackers to obtain\nsensitive information (related to network structure), and possibly cause a\ndenial of service (disrupted authentication) and conduct spoofing attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-479-1","https://www.cve.org/CVERecord?id=CVE-2006-7180"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-restricted-modules-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.15","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15.12-29.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-restricted-modules-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.17","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.8-12.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-restricted-modules-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.20","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20.5-16.29","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-479-1"],"notices":[{"id":"USN-479-1","title":"MadWifi vulnerabilities","summary":"MadWifi vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-06-29T05:37:26","description":"Multiple flaws in the MadWifi driver were discovered that could lead\nto a system crash. A physically near-by attacker could generate\nspecially crafted wireless network traffic and cause a denial of\nservice. (CVE-2006-7177, CVE-2006-7178, CVE-2006-7179, CVE-2007-2829,\nCVE-2007-2830)\n\nA flaw was discovered in the MadWifi driver that would allow unencrypted\nnetwork traffic to be sent prior to finishing WPA authentication.\nA physically near-by attacker could capture this, leading to a loss of\nprivacy, denial of service, or network spoofing. (CVE-2006-7180)\n\nA flaw was discovered in the MadWifi driver's ioctl handling. A local\nattacker could read kernel memory, or crash the system, leading to a\ndenial of service. (CVE-2007-2831)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-restricted-modules-2.6.15-28-686","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-k8","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-xeon","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-k7","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-sparc64","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-sparc64-smp","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-powerpc-smp","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-generic","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-386","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-powerpc","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"linux-restricted-modules-2.6.20-16-powerpc64-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-386","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-lowlatency","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-sparc64-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-sparc64","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-powerpc","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-generic","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-powerpc-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"linux-restricted-modules-2.6.17-11-sparc64","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-sparc64-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc64-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-generic","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-386","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-7177","CVE-2006-7178","CVE-2006-7179","CVE-2006-7180","CVE-2007-2829","CVE-2007-2830","CVE-2007-2831"]}]},{"id":"CVE-2006-7179","published":"2007-03-30T01:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nieee80211_input.c in MadWifi before 0.9.3 does not properly process Channel\nSwitch Announcement Information Elements (CSA IEs), which allows remote\nattackers to cause a denial of service (loss of communication) via a\nChannel Switch Count less than or equal to one, triggering a channel\nchange.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-479-1","https://www.cve.org/CVERecord?id=CVE-2006-7179"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-restricted-modules-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.17","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.17","statuses":[{"release_codename":"edgy","status":"released","description":"2.6.17.8-12.3","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-restricted-modules-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.20","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20.5-16.29","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-479-1"],"notices":[{"id":"USN-479-1","title":"MadWifi vulnerabilities","summary":"MadWifi vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-06-29T05:37:26","description":"Multiple flaws in the MadWifi driver were discovered that could lead\nto a system crash. A physically near-by attacker could generate\nspecially crafted wireless network traffic and cause a denial of\nservice. (CVE-2006-7177, CVE-2006-7178, CVE-2006-7179, CVE-2007-2829,\nCVE-2007-2830)\n\nA flaw was discovered in the MadWifi driver that would allow unencrypted\nnetwork traffic to be sent prior to finishing WPA authentication.\nA physically near-by attacker could capture this, leading to a loss of\nprivacy, denial of service, or network spoofing. (CVE-2006-7180)\n\nA flaw was discovered in the MadWifi driver's ioctl handling. A local\nattacker could read kernel memory, or crash the system, leading to a\ndenial of service. (CVE-2007-2831)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-restricted-modules-2.6.15-28-686","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-k8","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-xeon","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-k7","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-sparc64","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-sparc64-smp","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-powerpc-smp","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-generic","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-386","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-powerpc","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"linux-restricted-modules-2.6.20-16-powerpc64-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-386","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-lowlatency","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-sparc64-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-sparc64","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-powerpc","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-generic","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-powerpc-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"linux-restricted-modules-2.6.17-11-sparc64","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-sparc64-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc64-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-generic","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-386","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-7177","CVE-2006-7178","CVE-2006-7179","CVE-2006-7180","CVE-2007-2829","CVE-2007-2830","CVE-2007-2831"]}]},{"id":"CVE-2006-7178","published":"2007-03-30T01:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nMadWifi before 0.9.3 does not properly handle reception of an AUTH frame by\nan IBSS node, which allows remote attackers to cause a denial of service\n(system crash) via a certain AUTH frame.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-479-1","https://www.cve.org/CVERecord?id=CVE-2006-7178"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-restricted-modules-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.15","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15.12-29.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-restricted-modules-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.17","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.8-12.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-restricted-modules-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.20","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20.5-16.29","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-479-1"],"notices":[{"id":"USN-479-1","title":"MadWifi vulnerabilities","summary":"MadWifi vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-06-29T05:37:26","description":"Multiple flaws in the MadWifi driver were discovered that could lead\nto a system crash. A physically near-by attacker could generate\nspecially crafted wireless network traffic and cause a denial of\nservice. (CVE-2006-7177, CVE-2006-7178, CVE-2006-7179, CVE-2007-2829,\nCVE-2007-2830)\n\nA flaw was discovered in the MadWifi driver that would allow unencrypted\nnetwork traffic to be sent prior to finishing WPA authentication.\nA physically near-by attacker could capture this, leading to a loss of\nprivacy, denial of service, or network spoofing. (CVE-2006-7180)\n\nA flaw was discovered in the MadWifi driver's ioctl handling. A local\nattacker could read kernel memory, or crash the system, leading to a\ndenial of service. (CVE-2007-2831)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-restricted-modules-2.6.15-28-686","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-k8","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-xeon","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-k7","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-sparc64","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-sparc64-smp","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-powerpc-smp","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-generic","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-386","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-powerpc","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"linux-restricted-modules-2.6.20-16-powerpc64-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-386","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-lowlatency","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-sparc64-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-sparc64","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-powerpc","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-generic","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-powerpc-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"linux-restricted-modules-2.6.17-11-sparc64","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-sparc64-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc64-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-generic","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-386","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-7177","CVE-2006-7178","CVE-2006-7179","CVE-2006-7180","CVE-2007-2829","CVE-2007-2830","CVE-2007-2831"]}]},{"id":"CVE-2006-7177","published":"2007-03-30T01:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nMadWifi, when Ad-Hoc mode is used, allows remote attackers to cause a\ndenial of service (system crash) via unspecified vectors that lead to a\nkernel panic in the ieee80211_input function, related to \"packets coming\nfrom a 'malicious' WinXP system.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-479-1","https://www.cve.org/CVERecord?id=CVE-2006-7177"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-restricted-modules-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.15","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15.12-29.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-restricted-modules-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.17","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.8-12.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-restricted-modules-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.20","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20.5-16.29","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-479-1"],"notices":[{"id":"USN-479-1","title":"MadWifi vulnerabilities","summary":"MadWifi vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-06-29T05:37:26","description":"Multiple flaws in the MadWifi driver were discovered that could lead\nto a system crash. A physically near-by attacker could generate\nspecially crafted wireless network traffic and cause a denial of\nservice. (CVE-2006-7177, CVE-2006-7178, CVE-2006-7179, CVE-2007-2829,\nCVE-2007-2830)\n\nA flaw was discovered in the MadWifi driver that would allow unencrypted\nnetwork traffic to be sent prior to finishing WPA authentication.\nA physically near-by attacker could capture this, leading to a loss of\nprivacy, denial of service, or network spoofing. (CVE-2006-7180)\n\nA flaw was discovered in the MadWifi driver's ioctl handling. A local\nattacker could read kernel memory, or crash the system, leading to a\ndenial of service. (CVE-2007-2831)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-restricted-modules-2.6.15-28-686","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-k8","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-xeon","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-k7","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-sparc64","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-sparc64-smp","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-powerpc-smp","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-amd64-generic","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-386","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.15-28-powerpc","version":"2.6.15.12-28.2","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"linux-restricted-modules-2.6.20-16-powerpc64-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-386","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-lowlatency","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-sparc64-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-sparc64","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-powerpc","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-generic","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.20-16-powerpc-smp","version":"2.6.20.5-16.29","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"linux-restricted-modules-2.6.17-11-sparc64","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-sparc64-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc64-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-generic","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-powerpc-smp","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""},{"name":"linux-restricted-modules-2.6.17-11-386","version":"2.6.17.8-11.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-7177","CVE-2006-7178","CVE-2006-7179","CVE-2006-7180","CVE-2007-2829","CVE-2007-2830","CVE-2007-2831"]}]},{"id":"CVE-2007-1762","published":"2007-03-30T00:19:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before\nchecking them against the phishing site blacklist, which allows remote\nattackers to bypass phishing protection via multiple / (slash) characters\nin the URL.","ubuntu_description":"","notes":[{"author":"kees","note":"phishing filter bypass"},{"author":"mdeslaur","note":"no impact, ignoring"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1762"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=445515"],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1349","published":"2007-03-30T00:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\nPerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in\nmod_perl 2.x, does not properly escape PATH_INFO before use in a regular\nexpression, which allows remote attackers to cause a denial of service\n(resource consumption) via a crafted URI.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-488-1","https://www.cve.org/CVERecord?id=CVE-2007-1349"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libapache2-mod-perl2","source":"https://ubuntu.com/security/cve?package=libapache2-mod-perl2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache2-mod-perl2","debian":"https://tracker.debian.org/pkg/libapache2-mod-perl2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.2-2ubuntu1.6.06.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.2-2ubuntu1.6.10.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.2-2.3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-488-1"],"notices":[{"id":"USN-488-1","title":"mod_perl vulnerability","summary":"mod_perl vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-07-18T00:03:16","description":"Alex Solovey discovered that mod_perl did not correctly validate certain\nregular expression matches. A remote attacker could send a specially\ncrafted request to a web application using mod_perl, causing the web\nserver to monopolize CPU resources. This could lead to a remote denial\nof service.","is_hidden":false,"release_packages":{"dapper":[{"name":"libapache2-mod-perl2","version":"2.0.2-2ubuntu1.6.06.1","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"libapache2-mod-perl2","version":"2.0.2-2.3ubuntu1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libapache2-mod-perl2","version":"2.0.2-2ubuntu1.6.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1349"]}]},{"id":"CVE-2007-1737","published":"2007-03-28T22:19:00","updated_at":"2025-07-17T16:41:10.168384+00:00","description":"\nOpera 9.10 does not check URLs embedded in (1) object or (2) iframe HTML\ntags against the phishing site blacklist, which allows remote attackers to\nbypass phishing protection.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1737"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"opera","source":"https://ubuntu.com/security/cve?package=opera","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=opera","debian":"https://tracker.debian.org/pkg/opera","statuses":[{"release_codename":"dapper","status":"released","description":"9.23-20070809.6dapper1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"9.23-20070809.6edgy1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"9.23-20070809.6feisty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.21","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1736","published":"2007-03-28T22:19:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2)\niframe HTML tags against the phishing site blacklist, which allows remote\nattackers to bypass phishing protection.","ubuntu_description":"","notes":[{"author":"kees","note":"phishing filter bypass"},{"author":"mdeslaur","note":"no impact, ignoring"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1736"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1734","published":"2007-03-28T22:19:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in\nLinux kernel 2.6.20 and later does not verify the upper bounds of the\noptlen value, which allows local users running on certain architectures to\nread kernel memory or cause a denial of service (oops), a related issue to\nCVE-2007-1730.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1734"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"released","description":"2.6.21","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"feisty","status":"released","description":"2.6.20-16.28","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.20.5","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"upstream","status":"released","description":"2.6.20.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1732","published":"2007-03-28T20:19:00","updated_at":"2025-08-04T19:18:40.336969+00:00","description":"\nCross-site scripting (XSS) vulnerability in an mt import in\nwp-admin/admin.php in WordPress 2.1.2 allows remote authenticated\nadministrators to inject arbitrary web script or HTML via the demo\nparameter. NOTE: the provenance of this information is unknown; the\ndetails are obtained solely from third party information. NOTE: another\nresearcher disputes this issue, stating that this is legitimate\nfunctionality for administrators. However, it has been patched by at least\none vendor","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Administrators can post HTML. Terrible."},{"author":"mdeslaur","note":"disputed. Let's ignore"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1732"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1730","published":"2007-03-28T10:19:00","updated_at":"2025-07-17T16:41:10.168384+00:00","description":"\nInteger signedness error in the DCCP support in the do_dccp_getsockopt\nfunction in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local\nusers to read kernel memory or cause a denial of service (oops) via a\nnegative optlen value.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-464-1","https://www.cve.org/CVERecord?id=CVE-2007-1730"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-464-1"],"notices":[{"id":"USN-464-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-05-24T21:48:40","description":"Philipp Richter discovered that the AppleTalk protocol handler did\nnot sufficiently verify the length of packets. By sending a crafted\nAppleTalk packet, a remote attacker could exploit this to crash the\nkernel. (CVE-2007-1357)\n\nGabriel Campana discovered that the do_ipv6_setsockopt() function did\nnot sufficiently verifiy option values for IPV6_RTHDR. A local\nattacker could exploit this to trigger a kernel crash. (CVE-2007-1388)\n\nA Denial of Service vulnerability was discovered in the\nnfnetlink_log() netfilter function. A remote attacker could exploit\nthis to trigger a kernel crash. (CVE-2007-1496)\n\nThe connection tracking module for IPv6 did not properly handle the\nstatus field when reassembling fragmented packets, so that the final\npacket always had the 'established' state. A remote attacker could\nexploit this to bypass intended firewall rules. (CVE-2007-1497)\n\nMasayuki Nakagawa discovered an error in the flowlabel handling of\nIPv6 network sockets. A local attacker could exploit this to crash\nthe kernel. (CVE-2007-1592)\n\nThe do_dccp_getsockopt() function did not sufficiently verify the\noptlen argument. A local attacker could exploit this to read kernel\nmemory (which might expose sensitive data) or cause a kernel crash.\nThis only affects Ubuntu 7.04. (CVE-2007-1730)\n\nThe IPv4 and DECnet network protocol handlers incorrectly declared\nan array variable so that it became smaller than intended. By sending\ncrafted packets over a netlink socket, a local attacker could exploit\nthis to crash the kernel. (CVE-2007-2172)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-image-2.6.15-28-amd64-generic","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc64-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-hppa32-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-386","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-hppa64-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-itanium-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-mckinley-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-itanium","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-server","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-k8","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server-bigiron","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-hppa64","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-686","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-hppa32","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-mckinley","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-k7","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-xeon","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"linux-image-2.6.17-11-mckinley","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-generic","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-hppa32","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-server-bigiron","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-sparc64-smp","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-itanium","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-386","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc-smp","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-sparc64","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-server","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc64-smp","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-hppa64","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1357","CVE-2007-1388","CVE-2007-1496","CVE-2007-1497","CVE-2007-1592","CVE-2007-1730","CVE-2007-2172"]}]},{"id":"CVE-2007-1718","published":"2007-03-28T00:19:00","updated_at":"2025-07-17T16:41:10.168384+00:00","description":"\nCRLF injection vulnerability in the mail function in PHP 4.0.0 through\n4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary\ne-mail headers and possibly conduct spam attacks via a control character\nimmediately following folding of the (1) Subject or (2) To parameter, as\ndemonstrated by a parameter containing a \"\\r\\n\\t\\n\" sequence, related to an\nincrement bug in the SKIP_LONG_HEADER_SEP macro.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-455-1","https://www.cve.org/CVERecord?id=CVE-2007-1718"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-455-1"],"notices":[{"id":"USN-455-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-04-27T21:10:26","description":"Stefan Esser discovered multiple vulnerabilities in the \"Month of PHP\nbugs\".\n\nThe substr_compare() function did not sufficiently verify its length\nargument. This might be exploited to read otherwise unaccessible\nmemory, which might lead to information disclosure. (CVE-2007-1375)\n\nThe shared memory (shmop) functions did not verify resource types,\nthus they could be called with a wrong resource type that might\ncontain user supplied data. This could be exploited to read and write\narbitrary memory addresses of the PHP interpreter. This issue does\nnot affect Ubuntu 7.04. (CVE-2007-1376)\n\nThe php_binary handler of the session extension was missing a boundary\ncheck. When unserializing overly long variable names this could be\nexploited to read up to 126 bytes of memory, which might lead to\ninformation disclosure. (CVE-2007-1380)\n\nThe internal array_user_key_compare() function, as used for example by\nthe PHP function uksort(), incorrectly handled memory unreferencing of\nits arguments. This could have been exploited to execute arbitrary\ncode with the privileges of the PHP interpreter, and thus\ncircumventing any disable_functions, open_basedir, or safe_mode\nrestrictions. (CVE-2007-1484)\n\nThe session_regenerate_id() function did not properly clean up the\nformer session identifier variable. This could be exploited to crash\nthe PHP interpreter, possibly also remotely. (CVE-2007-1521)\n\nUnder certain conditions the mb_parse_str() could cause the\nregister_globals configuration option to become permanently enabled.\nThis opened an attack vector for a large and common class of\nvulnerabilities. (CVE-2007-1583)\n\nThe session extension did not set the correct reference count value\nfor the session variables. By unsetting _SESSION and HTTP_SESSION_VARS\n(or tricking a PHP script into doing that) this could be exploited to\nexecute arbitrary code with the privileges of the PHP interpreter. This\nissue does not affect Ubuntu 7.04. (CVE-2007-1700)\n\nThe mail() function did not correctly escape control characters in\nmultiline email headers. This could be remotely exploited to inject\narbitrary email headers. (CVE-2007-1718)\n\nThe php_stream_filter_create() function had an off-by-one buffer\noverflow in the handling of wildcards. This could be exploited to\nremotely crash the PHP interpreter. This issue does not affect Ubuntu\n7.04. (CVE-2007-1824)\n\nWhen calling the sqlite_udf_decode_binary() with special arguments, a\nbuffer overflow happened. Depending on the application this could be\nlocally or remotely exploited to execute arbitrary code with the\nprivileges of the PHP interpreter. (CVE-2007-1887 CVE-2007-1888)\n\nThe FILTER_VALIDATE_EMAIL filter extension used a wrong\nregular expression that allowed injecting a newline character at the\nend of the email string. This could be exploited to inject \narbitrary email headers. This issue only affects Ubuntu 7.04.\n(CVE-2007-1900)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"php5-cli","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1888","CVE-2007-1700","CVE-2007-1380","CVE-2007-1900","CVE-2007-1375","CVE-2007-1887","CVE-2007-1521","CVE-2007-1718","CVE-2007-1484","CVE-2007-1376","CVE-2007-1824","CVE-2007-1583"]}]}],"offset":76680,"limit":20,"total_results":79316}