{"cves":[{"id":"CVE-2006-4144","published":"2006-08-15T23:04:00","updated_at":"2025-07-17T16:39:31.007247+00:00","description":"\nInteger overflow in the ReadSGIImage function in sgi.c in ImageMagick\nbefore 6.2.9 allows user-assisted attackers to cause a denial of service\n(crash) and possibly execute arbitrary code via large (1) bytes_per_pixel,\n(2) columns, and (3) rows values, which trigger a heap-based buffer\noverflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-337-1","https://www.cve.org/CVERecord?id=CVE-2006-4144"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.7-8","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.7-8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"dapper","status":"released","description":"6.2.4.5-0.6ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"6.2.4.5.dfsg1-0.10ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"6.2.4.5.dfsg1-0.14ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-337-1"],"notices":[{"id":"USN-337-1","title":"imagemagick vulnerability","summary":"imagemagick vulnerability","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2006-08-17T15:21:57","description":"Damian Put discovered a buffer overflow in imagemagick's SGI file\nformat decoder. By tricking an user or automated system into\nprocessing a specially crafted SGI image, this could be exploited to\nexecute arbitrary code with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libmagick9","version":"6:6.2.4.5-0.6ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"libmagick6","version":"6:6.0.6.2-2.1ubuntu1.3","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libmagick6","version":"6:6.2.3.4-1ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-4144"]}]},{"id":"CVE-2006-2446","published":"2006-08-15T22:04:00","updated_at":"2025-07-17T16:38:46.188028+00:00","description":"\nRace condition between the kfree_skb and __skb_unlink functions in the\nsocket buffer handling in Linux kernel 2.6.9, and possibly other versions,\nallows remote attackers to cause a denial of service (crash), as\ndemonstrated using the TCP stress tests from the LTP test suite.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2446"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4124","published":"2006-08-14T23:04:00","updated_at":"2025-07-17T16:39:31.007247+00:00","description":"\nThe libXm library in LessTif 0.95.0 and earlier allows local users to gain\nprivileges via the DEBUG_FILE environment variable, which is used to create\nworld-writable files when libXm is run from a setuid program.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4124"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lesstif1-1","source":"https://ubuntu.com/security/cve?package=lesstif1-1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lesstif1-1","debian":"https://tracker.debian.org/pkg/lesstif1-1","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4112","published":"2006-08-14T21:04:00","updated_at":"2025-07-17T16:39:31.007247+00:00","description":"\nUnspecified vulnerability in the \"dependency resolution mechanism\" in Ruby\non Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary\nRuby code via a URL that is not properly handled in the routing code, which\nleads to a denial of service (application hang) or \"data loss,\" a different\nvulnerability than CVE-2006-4111.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4112"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4111","published":"2006-08-14T21:04:00","updated_at":"2025-07-17T16:39:31.007247+00:00","description":"\nRuby on Rails before 1.1.5 allows remote attackers to execute Ruby code\nwith \"severe\" or \"serious\" impact via a File Upload request with an HTTP\nheader that modifies the LOAD_PATH variable, a different vulnerability than\nCVE-2006-4112.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4111"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1168","published":"2006-08-14T20:04:00","updated_at":"2025-07-17T16:37:55.243598+00:00","description":"\nThe decompress function in compress42.c in (1) ncompress 4.2.4 and (2)\nliblzw allows remote attackers to cause a denial of service (crash), and\npossibly execute arbitrary code, via crafted data that leads to a buffer\nunderflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1168"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ncompress","source":"https://ubuntu.com/security/cve?package=ncompress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ncompress","debian":"https://tracker.debian.org/pkg/ncompress","statuses":[{"release_codename":"dapper","status":"released","description":"4.2.4-15sarge2build0.6.06.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.2.4-15sarge2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.2.4-15sarge2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"4.2.4-15sarge2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4.2.4-15sarge2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4.2.4-15sarge2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4.2.4-15sarge2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4019","published":"2006-08-11T21:04:00","updated_at":"2025-07-17T16:39:29.406732+00:00","description":"\nDynamic variable evaluation vulnerability in compose.php in SquirrelMail\n1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program\nvariables and read or write the attachments and preferences of other users.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4019"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.9a-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4089","published":"2006-08-11T10:04:00","updated_at":"2025-07-17T16:39:29.406732+00:00","description":"\nMultiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier\nallow remote attackers to cause a denial of service (application crash), or\nhave other unknown impact, via (1) a long Location field sent by a web\nserver, which triggers an overflow in the reconnect function in\nreader/http/http.c; (2) a long URL sent by a web server when AlsaPlayer is\nseeking a media file for the playlist, which triggers overflows in\nnew_list_item and CbUpdated in interface/gtk/PlaylistWindow.cpp; and (3) a\nlong response sent by a CDDB server, which triggers an overflow in\ncddb_lookup in input/ccda/cdda_engine.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4089"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"alsaplayer","source":"https://ubuntu.com/security/cve?package=alsaplayer","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=alsaplayer","debian":"https://tracker.debian.org/pkg/alsaplayer","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.76-9","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.99.76-9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.99.76-9","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.99.76-9","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.99.76-9","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.99.76-9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4041","published":"2006-08-09T23:04:00","updated_at":"2025-07-17T16:39:29.406732+00:00","description":"\nSQL injection vulnerability in Pike before 7.6.86, when using a Postgres\ndatabase server, allows remote attackers to execute arbitrary SQL commands\nvia unspecified attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-367-1","https://www.cve.org/CVERecord?id=CVE-2006-4041"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"pike7.6","source":"https://ubuntu.com/security/cve?package=pike7.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pike7.6","debian":"https://tracker.debian.org/pkg/pike7.6","statuses":[{"release_codename":"dapper","status":"released","description":"7.6.61-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-367-1"],"notices":[{"id":"USN-367-1","title":"Pike vulnerability","summary":"Pike vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2006-10-18T23:13:17","description":"An SQL injection was discovered in Pike's PostgreSQL module. \nApplications using a PostgreSQL database and uncommon character \nencodings could be fooled into running arbitrary SQL commands, which \ncould result in privilege escalation within the application, application \ndata exposure, or denial of service.\n\nPlease refer to http://www.ubuntu.com/usn/usn-288-1 for more detailled \ninformation.","is_hidden":false,"release_packages":{"hoary":[{"name":"pike7.6-pg","version":"7.6.13-1ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-4041"]}]},{"id":"CVE-2006-4031","published":"2006-08-09T22:04:00","updated_at":"2025-07-17T16:39:29.406732+00:00","description":"\nMySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access\na table through a previously created MERGE table, even after the user's\nprivileges are revoked for the original table, which might violate intended\nsecurity policy.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-338-1","https://www.cve.org/CVERecord?id=CVE-2006-4031"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"dapper","status":"released","description":"5.0.22-0ubuntu6.06.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.0.24a-9ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.0.38-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-338-1"],"notices":[{"id":"USN-338-1","title":"MySQL vulnerabilities","summary":"MySQL vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2006-09-05T21:45:19","description":"Dmitri Lenev discovered that arguments of setuid SQL functions were\nevaluated in the security context of the functions' definer instead of\nits caller. An authenticated user with the privilege to call such a\nfunction could exploit this to execute arbitrary statements with the\nprivileges of the definer of that function. (CVE-2006-4227)\n\nPeter Gulutzan reported a potentially confusing situation of the MERGE\ntable engine. If an user creates a merge table, and the administrator\nlater revokes privileges on the original table only (without changing\nthe privileges on the merge table), that user still has access to the\ndata by using the merge table. This is intended behaviour, but might\nbe undesirable in some installations; this update introduces a new\nserver option \"--skip-merge\" which disables the MERGE engine\ncompletely. (CVE-2006-4031)","is_hidden":false,"release_packages":{"dapper":[{"name":"mysql-server-5.0","version":"5.0.22-0ubuntu6.06.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-4031","CVE-2006-4227"]}]},{"id":"CVE-2006-3122","published":"2006-08-09T22:04:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5\nallows remote attackers to cause a denial of service (application crash)\nvia a DHCPDISCOVER packet with a 32 byte client-identifier, which causes\nthe packet to be interpreted as a corrupt uid and causes the server to exit\nwith \"corrupt lease uid.\"","ubuntu_description":"","notes":[{"author":"kees","note":"server denial-of-service"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3122"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=380273"],"patches":{},"tags":{},"packages":[{"name":"dhcp","source":"https://ubuntu.com/security/cve?package=dhcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dhcp","debian":"https://tracker.debian.org/pkg/dhcp","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0pl5-19.5ubuntu2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0pl5-19.5ubuntu2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4028","published":"2006-08-09T20:04:00","updated_at":"2025-07-17T16:39:29.406732+00:00","description":"\nMultiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown\nimpact and remote attack vectors. NOTE: due to lack of details, it is not\nclear how these issues are different from CVE-2006-3389 and CVE-2006-3390,\nalthough it is likely that 2.0.4 addresses an unspecified issue related to\n\"Anyone can register\" functionality (user registration for guests).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4028"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3084","published":"2006-08-09T10:04:00","updated_at":"2025-07-17T16:39:05.252305+00:00","description":"\nThe (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5,\nand 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check\nreturn codes for setuid calls, which might allow local users to gain\nprivileges by causing setuid to fail to drop privileges. NOTE: as of\n20060808, it is not known whether an exploitable attack scenario exists for\nthese issues.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-334-1","https://www.cve.org/CVERecord?id=CVE-2006-3084"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-334-1"],"notices":[{"id":"USN-334-1","title":"krb5 vulnerabilities","summary":"krb5 vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2006-08-16T16:47:28","description":"Michael Calmer and Marcus Meissner discovered that several krb5 tools \ndid not check the return values from setuid() system calls. On systems \nthat have configured user process limits, it may be possible for an \nattacker to cause setuid() to fail via resource starvation. In that \nsituation, the tools will not reduce their privilege levels, and will \ncontinue operation as the root user.\n\nBy default, Ubuntu does not ship with user process limits.\n\nPlease note that these packages are not officially supported by Ubuntu\n(they are in the 'universe' component of the archive).","is_hidden":false,"release_packages":{"dapper":[{"name":"krb5-clients","version":"1.4.3-5ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-rsh-server","version":"1.4.3-5ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-ftpd","version":"1.4.3-5ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-user","version":"1.4.3-5ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"krb5-clients","version":"1.3.6-1ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"krb5-rsh-server","version":"1.3.6-1ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"krb5-ftpd","version":"1.3.6-1ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"krb5-user","version":"1.3.6-1ubuntu0.2","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"krb5-clients","version":"1.3.6-4ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-rsh-server","version":"1.3.6-4ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-ftpd","version":"1.3.6-4ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-user","version":"1.3.6-4ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-3084","CVE-2006-3083"]}]},{"id":"CVE-2006-3083","published":"2006-08-09T10:04:00","updated_at":"2025-07-17T16:39:05.252305+00:00","description":"\nThe (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to\n1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal\n0.7.2 and earlier, do not check return codes for setuid calls, which allows\nlocal users to gain privileges by causing setuid to fail to drop privileges\nusing attacks such as resource exhaustion.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-334-1","https://www.cve.org/CVERecord?id=CVE-2006-3083"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-334-1"],"notices":[{"id":"USN-334-1","title":"krb5 vulnerabilities","summary":"krb5 vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2006-08-16T16:47:28","description":"Michael Calmer and Marcus Meissner discovered that several krb5 tools \ndid not check the return values from setuid() system calls. On systems \nthat have configured user process limits, it may be possible for an \nattacker to cause setuid() to fail via resource starvation. In that \nsituation, the tools will not reduce their privilege levels, and will \ncontinue operation as the root user.\n\nBy default, Ubuntu does not ship with user process limits.\n\nPlease note that these packages are not officially supported by Ubuntu\n(they are in the 'universe' component of the archive).","is_hidden":false,"release_packages":{"dapper":[{"name":"krb5-clients","version":"1.4.3-5ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-rsh-server","version":"1.4.3-5ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-ftpd","version":"1.4.3-5ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-user","version":"1.4.3-5ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"krb5-clients","version":"1.3.6-1ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"krb5-rsh-server","version":"1.3.6-1ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"krb5-ftpd","version":"1.3.6-1ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"krb5-user","version":"1.3.6-1ubuntu0.2","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"krb5-clients","version":"1.3.6-4ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-rsh-server","version":"1.3.6-4ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-ftpd","version":"1.3.6-4ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"krb5-user","version":"1.3.6-4ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-3084","CVE-2006-3083"]}]},{"id":"CVE-2006-4023","published":"2006-08-09T00:04:00","updated_at":"2025-07-17T16:39:29.406732+00:00","description":"\nThe ip2long function in PHP 5.1.4 and earlier may incorrectly validate an\narbitrary string and return a valid network IP address, which allows remote\nattackers to obtain network information and facilitate other attacks, as\ndemonstrated using SQL injection in the X-FORWARDED-FOR Header in index.php\nin MiniBB 2.0. NOTE: it could be argued that the ip2long behavior\nrepresents a risk for security-relevant issues in a way that is similar to\nstrcpy's role in buffer overflows, in which case this would be a class of\nimplementation bugs that would require separate CVE items for each PHP\napplication that uses ip2long in a security-relevant manner.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4023"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4020","published":"2006-08-08T20:04:00","updated_at":"2025-07-17T16:39:29.406732+00:00","description":"\nscanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows\ncontext-dependent attackers to execute arbitrary code via a sscanf PHP\nfunction call that performs argument swapping, which increments an index\npast the end of an array and triggers a buffer over-read.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-342-1","https://www.cve.org/CVERecord?id=CVE-2006-4020"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-342-1"],"notices":[{"id":"USN-342-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2006-09-07T23:45:44","description":"The sscanf() function did not properly check array boundaries. In\napplications which use sscanf() with argument swapping, a remote attacker\ncould potentially exploit this to crash the affected web application\nor even execute arbitrary code with the application's privileges.\n(CVE-2006-4020)\n\nThe file_exists() and imap_reopen() functions did not perform\nproper open_basedir and safe_mode checks which could allow local\nscripts to bypass intended restrictions. (CVE-2006-4481)\n\nOn 64 bit systems the str_repeat() and wordwrap() functions did not\nproperly check buffer boundaries. Depending on the application, this\ncould potentially be exploited to execute arbitrary code with the\napplications' privileges. This only affects the amd64 and sparc\nplatforms. (CVE-2006-4482)\n\nA buffer overflow was discovered in the LWZReadByte_() function of the\nGIF image file parser. By tricking a PHP application into processing a\nspecially crafted GIF image, a remote attacker could exploit this to\nexecute arbitrary code with the application's privileges.\n(CVE-2006-4484)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.2","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-curl","version":"5.1.2-1ubuntu3.2","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"libapache2-mod-php4","version":"4:4.3.10-10ubuntu4.7","is_source":false,"source_link":"","version_link":""},{"name":"php4-cgi","version":"4:4.3.10-10ubuntu4.7","is_source":false,"source_link":"","version_link":""},{"name":"php4-cli","version":"4:4.3.10-10ubuntu4.7","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"php5-cli","version":"5.0.5-2ubuntu1.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.0.5-2ubuntu1.4","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.0.5-2ubuntu1.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-curl","version":"5.0.5-2ubuntu1.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-4020","CVE-2006-4481","CVE-2006-4482","CVE-2006-4484"]}]},{"id":"CVE-2006-4018","published":"2006-08-08T20:04:00","updated_at":"2025-07-17T16:39:29.406732+00:00","description":"\nHeap-based buffer overflow in the pefromupx function in libclamav/upx.c in\nClam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to\nexecute arbitrary code via a crafted UPX packed file containing sections\nwith large rsize values.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4018"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"released","description":"0.88.2-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.90.2-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.91.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4006","published":"2006-08-07T19:04:00","updated_at":"2025-07-17T16:39:29.406732+00:00","description":"\nThe do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly\nother functions, does not reset the packet data size, which causes the\nsend_pkg function (packets.c) to use this data size when sending a reply,\nand allows remote attackers to read portions of server memory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4006"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bomberclone","source":"https://ubuntu.com/security/cve?package=bomberclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bomberclone","debian":"https://tracker.debian.org/pkg/bomberclone","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4005","published":"2006-08-07T19:04:00","updated_at":"2025-07-17T16:39:28.048053+00:00","description":"\nBomberClone 0.11.6 and earlier allows remote attackers to cause a denial of\nservice (daemon crash) via (1) a certain malformed PKGF_ackreq packet,\nwhich triggers a crash in the rscache_add() function in pkgcache.c; and (2)\nan error packet, which is intended to be received by clients and force\nclient shutdown, but also triggers server shutdown.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4005"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bomberclone","source":"https://ubuntu.com/security/cve?package=bomberclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bomberclone","debian":"https://tracker.debian.org/pkg/bomberclone","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.11.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4002","published":"2006-08-07T19:04:00","updated_at":"2025-07-17T16:39:28.048053+00:00","description":"\nCross-site scripting (XSS) vulnerability in user.module in Drupal 4.6\nbefore 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject\narbitrary web script or HTML via the msg parameter. NOTE: portions of\nthese details are obtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-4002"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"drupal","source":"https://ubuntu.com/security/cve?package=drupal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal","debian":"https://tracker.debian.org/pkg/drupal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.5.8-2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":77320,"limit":20,"total_results":79316}