{"cves":[{"id":"CVE-2005-2536","published":"2005-08-10T04:00:00","updated_at":"2025-07-17T16:36:17.177515+00:00","description":"\npstotext before 1.8g does not properly use the \"-dSAFER\" option when\ncalling Ghostscript to extract plain text from PostScript and PDF files,\nwhich allows remote attackers to execute arbitrary commands via a malicious\nPostScript file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2536"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"pstotext","source":"https://ubuntu.com/security/cve?package=pstotext","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pstotext","debian":"https://tracker.debian.org/pkg/pstotext","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2367","published":"2005-08-10T04:00:00","updated_at":"2025-07-17T16:36:10.255799+00:00","description":"\nFormat string vulnerability in the proto_item_set_text function in Ethereal\n0.9.4 through 0.10.11, as used in multiple dissectors, allows remote\nattackers to write to arbitrary memory locations and gain privileges via a\ncrafted AFP packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2367"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2366","published":"2005-08-10T04:00:00","updated_at":"2025-07-17T16:36:10.255799+00:00","description":"\nUnknown vulnerability in the BER dissector in Ethereal 0.10.11 allows\nremote attackers to cause a denial of service (abort or infinite loop) via\nunknown attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2366"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2365","published":"2005-08-10T04:00:00","updated_at":"2025-07-17T16:36:10.255799+00:00","description":"\nUnknown vulnerability in the SMB dissector in Ethereal 0.9.0 through\n0.10.11 allows remote attackers to cause a buffer overflow or a denial of\nservice (memory consumption) via unknown attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2365"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2364","published":"2005-08-10T04:00:00","updated_at":"2025-07-17T16:36:10.255799+00:00","description":"\nUnknown vulnerability in the (1) GIOP dissector, (2) WBXML, or (3) CAMEL\ndissector in Ethereal 0.8.20 through 0.10.11 allows remote attackers to\ncause a denial of service (application crash) via certain packets that\ncause a null pointer dereference.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2364"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2363","published":"2005-08-10T04:00:00","updated_at":"2025-07-17T16:36:10.255799+00:00","description":"\nUnknown vulnerability in the (1) SMPP dissector, (2) 802.3 dissector, (3)\nDHCP, (4) MEGACO dissector, or (5) H1 dissector in Ethereal 0.8.15 through\n0.10.11 allows remote attackers to cause a denial of service (infinite\nloop) via unknown attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2363"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2362","published":"2005-08-10T04:00:00","updated_at":"2025-07-17T16:36:10.255799+00:00","description":"\nUnknown vulnerability several dissectors in Ethereal 0.9.0 through 0.10.11\nallows remote attackers to cause a denial of service (application crash) by\nreassembling certain packets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2362"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2361","published":"2005-08-10T04:00:00","updated_at":"2025-07-17T16:36:10.255799+00:00","description":"\nUnknown vulnerability in the (1) AgentX dissector, (2) PER dissector, (3)\nDOCSIS dissector, (4) SCTP graphs, (5) HTTP dissector, (6) DCERPC, (7)\nDHCP, (8) RADIUS dissector, (9) Telnet dissector, (10) IS-IS LSP dissector,\nor (11) NCP dissector in Ethereal 0.8.19 through 0.10.11 allows remote\nattackers to cause a denial of service (application crash or abort) via\nunknown attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2361"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2360","published":"2005-08-10T04:00:00","updated_at":"2025-07-17T16:36:10.255799+00:00","description":"\nUnknown vulnerability in the LDAP dissector in Ethereal 0.8.5 through\n0.10.11 allows remote attackers to cause a denial of service (free static\nmemory and application crash) via unknown attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2360"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2500","published":"2005-08-08T04:00:00","updated_at":"2025-07-17T16:36:15.584014+00:00","description":"\nBuffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel\n2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote\nattackers to cause a denial of service and possibly execute arbitrary code\nvia crafted XDR data for the nfsacl protocol.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2500"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.12","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.12","debian":"https://tracker.debian.org/pkg/linux-source-2.6.12","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2475","published":"2005-08-05T04:00:00","updated_at":"2025-07-17T16:36:13.867809+00:00","description":"\nRace condition in Unzip 5.52 allows local users to modify permissions of\narbitrary files via a hard link attack on a file while it is being\ndecompressed, whose permissions are changed by Unzip after the\ndecompression is complete.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-191-1","https://www.cve.org/CVERecord?id=CVE-2005-2475"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"unzip","source":"https://ubuntu.com/security/cve?package=unzip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unzip","debian":"https://tracker.debian.org/pkg/unzip","statuses":[{"release_codename":"dapper","status":"released","description":"5.52-6ubuntu4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.52-6ubuntu4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.52-6ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-191-1"],"notices":[{"id":"USN-191-1","title":"unzip vulnerability","summary":"unzip vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-09-30T02:00:49","description":"Imran Ghory found a race condition in the handling of output files.\nWhile a file was unpacked by unzip, a local attacker with write\npermissions to the target directory could exploit this to change the\npermissions of arbitrary files of the unzip user.","is_hidden":false,"release_packages":{"hoary":[{"name":"unzip","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"unzip","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2475"]}]},{"id":"CVE-2005-2471","published":"2005-08-05T04:00:00","updated_at":"2025-07-17T16:36:13.867809+00:00","description":"\npstopnm in netpbm does not properly use the \"-dSAFER\" option when calling\nGhostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3)\nPNM file, which allows external user-assisted attackers to execute\narbitrary commands.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-164-1","https://www.cve.org/CVERecord?id=CVE-2005-2471"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"netpbm-free","source":"https://ubuntu.com/security/cve?package=netpbm-free","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netpbm-free","debian":"https://tracker.debian.org/pkg/netpbm-free","statuses":[{"release_codename":"dapper","status":"released","description":"10.0-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"10.0-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"10.0-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-164-1"],"notices":[{"id":"USN-164-1","title":"netpbm vulnerability","summary":"netpbm vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-08-11T21:56:38","description":"Max Vozeler discovered that the the \"pstopnm\" conversion tool did not\nuse the -dSAFER option when calling ghostscript. This option prohibits\nfile operations and calling commands within PostScript code. This flaw\ncould be exploited by an attacker to execute arbitrary code if he\ntricked an user (or an automatic server) into processing a specially\ncrafted PostScript document with pstopnm.","is_hidden":false,"release_packages":{"hoary":[{"name":"netpbm","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"netpbm","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2471"]}]},{"id":"CVE-2005-2359","published":"2005-08-05T04:00:00","updated_at":"2025-07-17T16:36:10.255799+00:00","description":"\nThe AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for\nauthentication without other encryption, uses a constant key instead of the\none that was assigned by the system administrator, which can allow remote\nattackers to spoof packets to establish an IPsec session.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2359"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kfreebsd-5","source":"https://ubuntu.com/security/cve?package=kfreebsd-5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kfreebsd-5","debian":"https://tracker.debian.org/pkg/kfreebsd-5","statuses":[{"release_codename":"dapper","status":"released","description":"5.4-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.4-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.4-12","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2353","published":"2005-08-05T04:00:00","updated_at":"2025-07-17T16:36:08.613652+00:00","description":"\nrun-mozilla.sh in Thunderbird, with debugging enabled, allows local users\nto create or overwrite arbitrary files via a symlink attack on temporary\nfiles.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-157-1","https://www.cve.org/CVERecord?id=CVE-2005-2353"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-157-1"],"notices":[{"id":"USN-157-1","title":"Mozilla Thunderbird vulnerabilities","summary":"Mozilla Thunderbird vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-08-01T17:47:42","description":"Vladimir V. Perepelitsa discovered a bug in Thunderbird's handling of anonymous\nfunctions during regular expression string replacement. A malicious HTML email\ncould exploit this to capture a random block of client memory. (CAN-2005-0989)\n\nGeorgi Guninski discovered that the types of certain XPInstall related\nJavaScript objects were not sufficiently validated when they were called. This\ncould be exploited by malicious HTML email content to crash Thunderbird or even\nexecute arbitrary code with the privileges of the user. (CAN-2005-1159) \n\nThunderbird did not properly verify the values of XML DOM nodes. By tricking\nthe user to perform a common action like clicking on a link or opening the\ncontext menu, a malicious HTML email could exploit this to execute arbitrary\nJavaScript code with the full privileges of the user. (CAN-2005-1160)\n\nA variant of the attack described in CAN-2005-1160 (see USN-124-1) was\ndiscovered. Additional checks were added to make sure Javascript eval and\nscript objects are run with the privileges of the context that created them,\nnot the potentially elevated privilege of the context calling them.\n(CAN-2005-1532)\n\nScripts in XBL controls from web content continued to be run even when\nJavascript was disabled. This could be combined with most script-based exploits\nto attack people running vulnerable versions who thought disabling Javascript\nwould protect them. (CAN-2005-2261)\n\nThe function for version comparison in the addons installer did not properly\nverify the type of its argument. By passing specially crafted Javascript\nobjects to it, a malicious web site could crash Thunderbird and possibly even\nexecute arbitrary code with the privilege of the user account Thunderbird runs\nin. (CAN-2005-2265)\n\nThe XHTML DOM node handler did not take namespaces into account when verifying\nnode types based on their names. For example, an XHTML email could contain an\n
tag with malicious contents, which would then be processed as the\nstandard trusted HTML
tag. By tricking an user to view a malicious email,\nthis could be exploited to execute attacker-specified code with the full\nprivileges of the user. (CAN-2005-2269) \n\nIt was discovered that some objects were not created appropriately. This\nallowed malicious web content scripts to trace back the creation chain until\nthey found a privileged object and execute code with higher privileges than\nallowed by the current site. (CAN-2005-2270) \n\nJavier Fernández-Sanguino Peña discovered that the run-mozilla.sh script\ncreated temporary files in an unsafe way when running with 'debugging' enabled.\nThis could allow a symlink attack to create or overwrite arbitrary files with\nthe privileges of the user invoking the program.\n(CAN-2005-2353)\n\nThe update for Ubuntu 4.10 (Warty Warthog) also fixes several less\ncritical vulnerabilities which are not present in the Ubuntu 5.04\nversion. (MFSA-2005-02 to MFSA-2005-30; please see the following web\nsite for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html).\nWe apologize for the huge delay of this update; we changed our update\nstrategy for Mozilla products to make sure that such long delays will\nnot happen again.","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-thunderbird","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-thunderbird-enigmail","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"mozilla-thunderbird","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-thunderbird-enigmail","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2353","CVE-2005-1159","CVE-2005-0989","CVE-2005-1160","CVE-2005-1532","CVE-2005-2261","CVE-2005-2265","CVE-2005-2269","CVE-2005-2270"]}]},{"id":"CVE-2005-1854","published":"2005-08-05T04:00:00","updated_at":"2025-07-17T16:35:52.530432+00:00","description":"\nUnknown vulnerability in apt-cacher in Debian 3.1, related to \"missing\ninput sanitising,\" allows remote attackers to execute arbitrary commands on\nthe caching server.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-1854"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apt-cacher","source":"https://ubuntu.com/security/cve?package=apt-cacher","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apt-cacher","debian":"https://tracker.debian.org/pkg/apt-cacher","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-1767","published":"2005-08-05T04:00:00","updated_at":"2025-07-17T16:35:50.194894+00:00","description":"\ntraps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults\non an exception stack, which allows local users to cause a denial of\nservice (oops and stack fault exception).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-187-1","https://www.cve.org/CVERecord?id=CVE-2005-1767"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-187-1"],"notices":[{"id":"USN-187-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-09-25T23:50:09","description":"A Denial of Service vulnerability was detected in the stack segment\nfault handler. A local attacker could exploit this by causing stack\nfault exceptions under special circumstances (scheduling), which lead\nto a kernel crash. (CAN-2005-1767)\n\nVasiliy Averin discovered a Denial of Service vulnerability in the\n\"tiocgdev\" ioctl call and in the \"routing_ioctl\" function. By calling\nfget() and fput() in special ways, a local attacker could exploit this\nto destroy file descriptor structures and crash the kernel.\n(CAN-2005-3044)","is_hidden":false,"release_packages":{"hoary":[{"name":"linux-patch-ubuntu-2.6.10","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-386","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-itanium-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-mckinley-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power4-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-mckinley","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-itanium","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power3-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-patch-debian-2.6.8.1","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-386","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"linux-patch-ubuntu-2.6.10","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-386","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-itanium-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-mckinley-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power4-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-mckinley","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-itanium","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power3-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-patch-debian-2.6.8.1","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-386","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-1767","CVE-2005-3044"]}]},{"id":"CVE-2005-1761","published":"2005-08-05T04:00:00","updated_at":"2025-07-17T16:35:48.679189+00:00","description":"\nLinux kernel 2.6 and 2.4 on the IA64 architecture allows local users to\ncause a denial of service (kernel crash) via ptrace and the\nrestore_sigcontext function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-1761"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-1268","published":"2005-08-05T04:00:00","updated_at":"2025-07-17T16:35:34.892346+00:00","description":"\nOff-by-one error in the mod_ssl Certificate Revocation List (CRL)\nverification callback in Apache, when configured to use a CRL, allows\nremote attackers to cause a denial of service (child process crash) via a\nCRL that causes a buffer overflow of one null byte.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-160-1","https://www.cve.org/CVERecord?id=CVE-2005-1268"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.55-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-3.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-160-1"],"notices":[{"id":"USN-160-1","title":"Apache 2 vulnerabilities","summary":"Apache 2 vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-08-04T23:38:33","description":"Marc Stern discovered a buffer overflow in the SSL module's\ncertificate revocation list (CRL) handler. If Apache is configured to\nuse a malicious CRL, this could possibly lead to a server crash or\narbitrary code execution with the privileges of the Apache web server.\n(CAN-2005-1268)\n\nWatchfire discovered that Apache insufficiently verified the\n\"Transfer-Encoding\" and \"Content-Length\" headers when acting as an\nHTTP proxy. By sending a specially crafted HTTP request, a remote\nattacker who is authorized to use the proxy could exploit this to\nbypass web application firewalls, poison the HTTP proxy cache, and\nconduct cross-site scripting attacks against other proxy users.\n(CAN-2005-2088)","is_hidden":false,"release_packages":{"hoary":[{"name":"apache2-mpm-worker","version":"","is_source":false,"source_link":"","version_link":""},{"name":"apache2-mpm-perchild","version":"","is_source":false,"source_link":"","version_link":""},{"name":"apache2-mpm-prefork","version":"","is_source":false,"source_link":"","version_link":""},{"name":"apache2-mpm-threadpool","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"apache2-mpm-worker","version":"","is_source":false,"source_link":"","version_link":""},{"name":"apache2-mpm-perchild","version":"","is_source":false,"source_link":"","version_link":""},{"name":"apache2-mpm-prefork","version":"","is_source":false,"source_link":"","version_link":""},{"name":"apache2-mpm-threadpool","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-1268","CVE-2005-2088"]}]},{"id":"CVE-2005-2456","published":"2005-08-04T04:00:00","updated_at":"2025-07-17T16:36:13.867809+00:00","description":"\nArray index overflow in the xfrm_sk_policy_insert function in xfrm_user.c\nin Linux kernel 2.6 allows local users to cause a denial of service (oops\nor deadlock) and possibly execute arbitrary code via a p->dir value that is\nlarger than XFRM_POLICY_OUT, which is used as an index in the\nsock->sk_policy array.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-169-1","https://www.cve.org/CVERecord?id=CVE-2005-2456"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-169-1"],"notices":[{"id":"USN-169-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-08-19T16:50:39","description":"David Howells discovered a local Denial of Service vulnerability in\nthe key session joining function. Under certain user-triggerable\nconditions, a semaphore was not released properly, which caused\nprocesses which also attempted to join a key session to hang forever.\nThis only affects Ubuntu 5.04 (Hoary Hedgehog). (CAN-2005-2098)\n\nDavid Howells discovered a local Denial of Service vulnerability in\nthe keyring allocator. A local attacker could exploit this to crash\nthe kernel by attempting to add a specially crafted invalid keyring.\nThis only affects Ubuntu 5.04 (Hoary Hedgehog). (CAN-2005-2099)\n\nBalazs Scheidler discovered a local Denial of Service vulnerability in\nthe xfrm_compile_policy() function. By calling setsockopt() with an\ninvalid xfrm_user policy message, a local attacker could cause the\nkernel to write to an array beyond its boundaries, thus causing a\nkernel crash. (CAN-2005-2456)\n\nTim Yamin discovered that the driver for compressed ISO file systems\ndid not sufficiently validate the iput data. By tricking an user into\nmounting a malicious CD-ROM with a specially crafted compressed ISO\nfile system, he could cause a kernel crash. (CAN-2005-2457)\n\nIt was discovered that the kernel's embedded zlib compression library\nwas still vulnerable to two old vulnerabilities of the standalone zlib\nlibrary. This library is used by various drivers and can also be used\nby third party modules, so the impact varies. (CAN-2005-2458,\nCAN-2005-2459)\n\nPeter Sandstrom discovered a remote Denial of Service vulnerability in\nthe SNMP handler. Certain UDP packages lead to a function call with\nthe wrong argument, which resulted in a crash of the network stack.\nThis only affects Ubuntu 4.10 (Warty Warthog). (CAN-2005-2548)\n\nHerbert Xu discovered that the setsockopt() function was not\nrestricted to privileged users. This allowed a local attacker to\nbypass intended IPSec policies, set invalid policies to exploit flaws\nlike CAN-2005-2456, or cause a Denial of Service by adding policies\nuntil kernel memory is exhausted. Now the call is restricted to\nprocesses with the CAP_NET_ADMIN capability. (CAN-2005-2555)\n\nThe Ubuntu 5.04 kernel update also fixes a memory leak in the \"md\"\n(Software RAID) driver which eventually lead to kernel memory\nexhaustion. Ubuntu 4.10 is not affected by this.\n(http://bugs.debian.org/317787)","is_hidden":false,"release_packages":{"hoary":[{"name":"linux-patch-ubuntu-2.6.10","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-386","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-itanium-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-mckinley-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power4-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-mckinley","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-itanium","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power3-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-patch-debian-2.6.8.1","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-386","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"linux-patch-ubuntu-2.6.10","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-386","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-itanium-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-mckinley-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power4-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-mckinley","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-itanium","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power3-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-power3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-patch-debian-2.6.8.1","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-386","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-5-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2548","CVE-2005-2555","CVE-2005-2457","CVE-2005-2459","CVE-2005-2458","CVE-2005-2098","CVE-2005-2456"]}]},{"id":"CVE-2005-2452","published":"2005-08-03T04:00:00","updated_at":"2025-07-17T16:36:13.867809+00:00","description":"\nlibtiff up to 3.7.0 allows remote attackers to cause a denial of service\n(application crash) via a TIFF image header with a zero \"YCbCr subsampling\"\nvalue, which causes a divide-by-zero error in (1) tif_strip.c and (2)\ntif_tile.c, a different vulnerability than CVE-2004-0804.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2452"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"released","description":"3.7.4-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.8.2-6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.8.2-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":78340,"limit":20,"total_results":79316}