{"cves":[{"id":"CVE-2007-1717","published":"2007-03-28T00:19:00","updated_at":"2025-07-17T16:41:10.168384+00:00","description":"\nThe mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1\ntruncates e-mail messages at the first ASCIIZ ('\\0') byte, which might\nallow context-dependent attackers to prevent intended information from\nbeing delivered in e-mail messages. NOTE: this issue might be\nsecurity-relevant in cases when the trailing contents of e-mail messages\nare important, such as logging information or if the message is expected to\nbe well-formed.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1717"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7176","published":"2007-03-27T23:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nThe version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and\nearlier does not reject the \"localhost.localdomain\" domain name for e-mail\nmessages that come from external hosts, which might allow remote attackers\nto spoof messages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7176"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sendmail","source":"https://ubuntu.com/security/cve?package=sendmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sendmail","debian":"https://tracker.debian.org/pkg/sendmail","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7175","published":"2007-03-27T23:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nThe version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and\nearlier does not allow the administrator to disable SSLv2 encryption, which\ncould cause less secure channels to be used than desired.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7175"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sendmail","source":"https://ubuntu.com/security/cve?package=sendmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sendmail","debian":"https://tracker.debian.org/pkg/sendmail","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1711","published":"2007-03-27T01:19:00","updated_at":"2025-07-17T16:41:10.168384+00:00","description":"\nDouble free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows\ncontext-dependent attackers to execute arbitrary code by overwriting\nvariables pointing to (1) the GLOBALS array or (2) the session data in\n_SESSION. NOTE: this issue was introduced when attempting to patch\nCVE-2007-1701 (MOPB-31-2007).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1711"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1710","published":"2007-03-27T01:19:00","updated_at":"2025-07-17T16:41:10.168384+00:00","description":"\nThe readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows\ncontext-dependent attackers to bypass safe_mode restrictions and read\narbitrary files by referring to local files with a certain URL syntax\ninstead of a pathname syntax, as demonstrated by a filename preceded a\n\"php://../../\" sequence.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1710"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1701","published":"2007-03-27T01:19:00","updated_at":"2025-07-17T16:41:10.168384+00:00","description":"\nPHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is\nenabled, allows context-dependent attackers to execute arbitrary code via\ndeserialization of session data, which overwrites arbitrary global\nvariables, as demonstrated by calling session_decode on a string beginning\nwith \"_SESSION|s:39:\".","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1701"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1700","published":"2007-03-27T01:19:00","updated_at":"2025-07-17T16:41:10.168384+00:00","description":"\nThe session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1,\ncalculates the reference count for the session variables without\nconsidering the internal pointer from the session globals, which allows\ncontext-dependent attackers to execute arbitrary code via a crafted string\nin the session_register after unsetting HTTP_SESSION_VARS and _SESSION,\nwhich destroys the session data Hashtable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-455-1","https://www.cve.org/CVERecord?id=CVE-2007-1700"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-455-1"],"notices":[{"id":"USN-455-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-04-27T21:10:26","description":"Stefan Esser discovered multiple vulnerabilities in the \"Month of PHP\nbugs\".\n\nThe substr_compare() function did not sufficiently verify its length\nargument. This might be exploited to read otherwise unaccessible\nmemory, which might lead to information disclosure. (CVE-2007-1375)\n\nThe shared memory (shmop) functions did not verify resource types,\nthus they could be called with a wrong resource type that might\ncontain user supplied data. This could be exploited to read and write\narbitrary memory addresses of the PHP interpreter. This issue does\nnot affect Ubuntu 7.04. (CVE-2007-1376)\n\nThe php_binary handler of the session extension was missing a boundary\ncheck. When unserializing overly long variable names this could be\nexploited to read up to 126 bytes of memory, which might lead to\ninformation disclosure. (CVE-2007-1380)\n\nThe internal array_user_key_compare() function, as used for example by\nthe PHP function uksort(), incorrectly handled memory unreferencing of\nits arguments. This could have been exploited to execute arbitrary\ncode with the privileges of the PHP interpreter, and thus\ncircumventing any disable_functions, open_basedir, or safe_mode\nrestrictions. (CVE-2007-1484)\n\nThe session_regenerate_id() function did not properly clean up the\nformer session identifier variable. This could be exploited to crash\nthe PHP interpreter, possibly also remotely. (CVE-2007-1521)\n\nUnder certain conditions the mb_parse_str() could cause the\nregister_globals configuration option to become permanently enabled.\nThis opened an attack vector for a large and common class of\nvulnerabilities. (CVE-2007-1583)\n\nThe session extension did not set the correct reference count value\nfor the session variables. By unsetting _SESSION and HTTP_SESSION_VARS\n(or tricking a PHP script into doing that) this could be exploited to\nexecute arbitrary code with the privileges of the PHP interpreter. This\nissue does not affect Ubuntu 7.04. (CVE-2007-1700)\n\nThe mail() function did not correctly escape control characters in\nmultiline email headers. This could be remotely exploited to inject\narbitrary email headers. (CVE-2007-1718)\n\nThe php_stream_filter_create() function had an off-by-one buffer\noverflow in the handling of wildcards. This could be exploited to\nremotely crash the PHP interpreter. This issue does not affect Ubuntu\n7.04. (CVE-2007-1824)\n\nWhen calling the sqlite_udf_decode_binary() with special arguments, a\nbuffer overflow happened. Depending on the application this could be\nlocally or remotely exploited to execute arbitrary code with the\nprivileges of the PHP interpreter. (CVE-2007-1887 CVE-2007-1888)\n\nThe FILTER_VALIDATE_EMAIL filter extension used a wrong\nregular expression that allowed injecting a newline character at the\nend of the email string. This could be exploited to inject \narbitrary email headers. This issue only affects Ubuntu 7.04.\n(CVE-2007-1900)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"php5-cli","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1888","CVE-2007-1700","CVE-2007-1380","CVE-2007-1900","CVE-2007-1375","CVE-2007-1887","CVE-2007-1521","CVE-2007-1718","CVE-2007-1484","CVE-2007-1376","CVE-2007-1824","CVE-2007-1583"]}]},{"id":"CVE-2007-1695","published":"2007-03-27T01:19:00","updated_at":"2025-08-04T19:18:40.336969+00:00","description":"\nPHP remote file inclusion vulnerability in includes/usercp_register.php in\nphpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a\nURL in the phpbb_root_path parameter. NOTE: this issue has been disputed\nby third-party researchers, stating that the file checks for a global\nconstant and cannot be accessed directly","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Requires register globals."},{"author":"mdeslaur","note":"disputed, let's ignore"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1695"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1679","published":"2007-03-26T23:19:00","updated_at":"2025-08-04T19:18:40.336969+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Horde Groupware\nWebmail 1.0 allow remote authenticated users to inject arbitrary web script\nor HTML via unspecified vectors in (1) imp/search.php and (2)\ningo/rule.php. NOTE: this issue has been disputed by the vendor, noting\nthat the search.php issue was resolved in CVE-2006-4255, and attackers can\nonly use rule.php to inject XSS into their own pages","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Allegedly a duplicate of CVE-2006-4255."}],"codename":null,"priority":"negligible","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1679"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"horde3","source":"https://ubuntu.com/security/cve?package=horde3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=horde3","debian":"https://tracker.debian.org/pkg/horde3","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1667","published":"2007-03-24T21:19:00","updated_at":"2025-07-17T16:41:08.582117+00:00","description":"\nMultiple integer overflows in (1) the XGetPixel function in ImUtil.c in\nX.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for\nImageMagick, allow user-assisted remote attackers to cause a denial of\nservice (crash) or obtain sensitive information via crafted images with\nlarge or negative values that trigger a buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-453-1","https://ubuntu.com/security/notices/USN-481-1","https://www.cve.org/CVERecord?id=CVE-2007-1667"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.8-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.8-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"dapper","status":"released","description":"6.2.4.5-0.6ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"6.2.4.5.dfsg1-0.10ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"6.2.4.5.dfsg1-0.14ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"6.2.4.5.dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.2.4.5.dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libx11","source":"https://ubuntu.com/security/cve?package=libx11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libx11","debian":"https://tracker.debian.org/pkg/libx11","statuses":[{"release_codename":"dapper","status":"released","description":"1.0.0-0ubuntu9.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.0.3-0ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-453-1","USN-481-1"],"notices":[{"id":"USN-453-1","title":"X.org vulnerability","summary":"X.org vulnerability","instructions":"After a standard system upgrade you need to restart your session or \nreboot your computer to effect the necessary changes.","references":[],"published":"2007-04-18T22:41:20","description":"Multiple integer overflows were found in the XGetPixel function of \nlibx11. If a user were tricked into opening a specially crafted XWD \nimage, remote attackers could execute arbitrary code with user \nprivileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libx11-6","version":"2:1.0.0-0ubuntu9.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libx11-6","version":"2:1.0.3-0ubuntu4.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1667"]},{"id":"USN-481-1","title":"ImageMagick vulnerabilities","summary":"ImageMagick vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-07-10T13:32:46","description":"Multiple vulnerabilities were found in ImageMagick's handling of DCM and\nWXD image files. By tricking a user into processing a specially crafted\nimage with an application that uses imagemagick, an attacker could\nexecute arbitrary code with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libmagick9","version":"6:6.2.4.5-0.6ubuntu0.6","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"libmagick9","version":"7:6.2.4.5.dfsg1-0.14ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libmagick9","version":"7:6.2.4.5.dfsg1-0.10ubuntu0.3","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1667","CVE-2007-1797"]}]},{"id":"CVE-2007-1657","published":"2007-03-24T01:19:00","updated_at":"2025-07-17T16:41:08.582117+00:00","description":"\nStack-based buffer overflow in the file_compress function in minigzip\n(Modules/zlib) in Python 2.5 allows context-dependent attackers to execute\narbitrary code via a long file argument.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1657"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"python2.5","source":"https://ubuntu.com/security/cve?package=python2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.5","debian":"https://tracker.debian.org/pkg/python2.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1655","published":"2007-03-24T00:19:00","updated_at":"2025-07-17T16:41:08.582117+00:00","description":"\nBuffer overflow in the fun_ladd function in funmath.cpp in TinyMUX before\n20070126 might allow remote attackers to cause a denial of service (crash)\nor possibly execute arbitrary code via unspecified vectors related to lists\nof numbers.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1655"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tinymux","source":"https://ubuntu.com/security/cve?package=tinymux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tinymux","debian":"https://tracker.debian.org/pkg/tinymux","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.2.27-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.4.3.31-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.4.3.31-1.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.4.3.31-1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.4.3.31-1.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.4.3.31-1.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.4.3.31-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1649","published":"2007-03-24T00:19:00","updated_at":"2025-07-17T16:41:08.582117+00:00","description":"\nPHP 5.2.1 allows context-dependent attackers to read portions of heap\nmemory by executing certain scripts with a serialized data input string\nbeginning with S:, which does not properly track the number of input bytes\nbeing processed.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1649"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1647","published":"2007-03-24T00:19:00","updated_at":"2025-07-17T16:41:08.582117+00:00","description":"\nMoodle 1.5.2 and earlier stores sensitive information under the web root\nwith insufficient access control, and provides directory listings, which\nallows remote attackers to obtain user names, password hashes, and other\nsensitive information via a direct request for session (sess_*) files in\nmoodledata/sessions/.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1647"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1622","published":"2007-03-23T00:19:00","updated_at":"2025-07-17T16:41:07.073037+00:00","description":"\nCross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress\nbefore 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote\nauthenticated users with theme privileges to inject arbitrary web script or\nHTML via the PATH_INFO in the administration interface, related to loose\nregular expression processing of PHP_SELF.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1622"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1614","published":"2007-03-23T00:19:00","updated_at":"2025-07-17T16:41:07.073037+00:00","description":"\nStack-based buffer overflow in the zzip_open_shared_io function in\nzzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote\nattackers to cause a denial of service (application crash) or execute\narbitrary code via a long filename.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1614"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"zziplib","source":"https://ubuntu.com/security/cve?package=zziplib","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zziplib","debian":"https://tracker.debian.org/pkg/zziplib","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.13.49-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.13.49-2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.13.49-2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.13.49-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.13.49-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1599","published":"2007-03-22T23:19:00","updated_at":"2025-07-17T16:41:07.073037+00:00","description":"\nwp-login.php in WordPress allows remote attackers to redirect authenticated\nusers to other websites and potentially obtain sensitive information via\nthe redirect_to parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1599"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1595","published":"2007-03-22T23:19:00","updated_at":"2025-07-17T16:41:07.073037+00:00","description":"\nThe Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not\nproperly generate extensions, which allows remote attackers to execute\narbitrary extensions and have an unknown impact by specifying an invalid\nextension in a certain form.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1595"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1594","published":"2007-03-22T23:19:00","updated_at":"2025-07-17T16:41:07.073037+00:00","description":"\nThe handle_response function in chan_sip.c in Asterisk before 1.2.17 and\n1.4.x before 1.4.2 allows remote attackers to cause a denial of service\n(crash) via a SIP Response code 0 in a SIP packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1594"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.4.11~dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1592","published":"2007-03-22T19:19:00","updated_at":"2025-07-17T16:41:07.073037+00:00","description":"\nnet/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently\ncopies the ipv6_fl_socklist from a listening TCP socket to child sockets,\nwhich allows local users to cause a denial of service (OOPS) or double free\nby opening a listening IPv6 socket, attaching a flow label, and connecting\nto that socket.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-464-1","https://www.cve.org/CVERecord?id=CVE-2007-1592"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-464-1"],"notices":[{"id":"USN-464-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-05-24T21:48:40","description":"Philipp Richter discovered that the AppleTalk protocol handler did\nnot sufficiently verify the length of packets. By sending a crafted\nAppleTalk packet, a remote attacker could exploit this to crash the\nkernel. (CVE-2007-1357)\n\nGabriel Campana discovered that the do_ipv6_setsockopt() function did\nnot sufficiently verifiy option values for IPV6_RTHDR. A local\nattacker could exploit this to trigger a kernel crash. (CVE-2007-1388)\n\nA Denial of Service vulnerability was discovered in the\nnfnetlink_log() netfilter function. A remote attacker could exploit\nthis to trigger a kernel crash. (CVE-2007-1496)\n\nThe connection tracking module for IPv6 did not properly handle the\nstatus field when reassembling fragmented packets, so that the final\npacket always had the 'established' state. A remote attacker could\nexploit this to bypass intended firewall rules. (CVE-2007-1497)\n\nMasayuki Nakagawa discovered an error in the flowlabel handling of\nIPv6 network sockets. A local attacker could exploit this to crash\nthe kernel. (CVE-2007-1592)\n\nThe do_dccp_getsockopt() function did not sufficiently verify the\noptlen argument. A local attacker could exploit this to read kernel\nmemory (which might expose sensitive data) or cause a kernel crash.\nThis only affects Ubuntu 7.04. (CVE-2007-1730)\n\nThe IPv4 and DECnet network protocol handlers incorrectly declared\nan array variable so that it became smaller than intended. By sending\ncrafted packets over a netlink socket, a local attacker could exploit\nthis to crash the kernel. (CVE-2007-2172)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-image-2.6.15-28-amd64-generic","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc64-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-hppa32-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-386","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-hppa64-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-itanium-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-mckinley-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-itanium","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-server","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc-smp","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-k8","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server-bigiron","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-hppa64","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-686","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-hppa32","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-mckinley","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-k7","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-xeon","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64","version":"2.6.15-28.55","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.28","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"linux-image-2.6.17-11-mckinley","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-generic","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-hppa32","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-server-bigiron","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-sparc64-smp","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-itanium","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-386","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc-smp","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-sparc64","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-server","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc64-smp","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-hppa64","version":"2.6.17.1-11.38","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1357","CVE-2007-1388","CVE-2007-1496","CVE-2007-1497","CVE-2007-1592","CVE-2007-1730","CVE-2007-2172"]}]}],"offset":76700,"limit":20,"total_results":79316}