{"cves":[{"id":"CVE-2005-0176","published":"2005-02-15T05:00:00","updated_at":"2025-07-17T16:34:50.252240+00:00","description":"\nThe shmctl function in Linux 2.6.9 and earlier allows local users to unlock\nthe memory of other processes, which could cause sensitive memory to be\nswapped to disk, which could allow it to be read by other users once it has\nbeen released.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-82-1","https://www.cve.org/CVERecord?id=CVE-2005-0176"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-82-1"],"notices":[{"id":"USN-82-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":["http://oss.sgi.com/archives/netdev/2005-01/msg01036.html"],"published":"2005-02-15T18:21:50","description":"CAN-2004-0176:\n\n  Michael Kerrisk noticed an insufficient permission checking in the\n  shmctl() function. Any process was permitted to lock/unlock any\n  System V shared memory segment that fell within the the\n  RLIMIT_MEMLOCK limit (that is the maximum size of shared memory that\n  unprivileged users can acquire). This allowed am unprivileged user\n  process to unlock locked memory of other processes, thereby allowing\n  them to be swapped out.  Usually locked shared memory is used to\n  store passphrases and other sensitive content which must not be\n  written to the swap space (where it could be read out even after a\n  reboot).\n\nCAN-2005-0177:\n\n  OGAWA Hirofumi noticed that the table sizes in nls_ascii.c were\n  incorrectly set to 128 instead of 256. This caused a buffer overflow\n  in some cases which could be exploited to crash the kernel.\n\nCAN-2005-0178:\n\n  A race condition was found in the terminal handling of the\n  \"setsid()\" function, which is used to start new process sessions.\n\nhttp://oss.sgi.com/archives/netdev/2005-01/msg01036.html:\n\n  David Coulson noticed a design flaw in the netfilter/iptables module.\n  By sending specially crafted packets, a remote attacker could exploit\n  this to crash the kernel or to bypass firewall rules.\n\n  Fixing this vulnerability required a change in the Application\n  Binary Interface (ABI) of the kernel. This means that third party\n  user installed modules might not work any more with the new kernel,\n  so this fixed kernel has a new ABI version number. You have to\n  recompile and reinstall all third party modules.","is_hidden":false,"release_packages":{"warty":[{"name":"linux-image-2.6.8.1-5-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-power4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-source-2.6.8.1","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.8.1-5-386","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0178","CVE-2005-0176","CVE-2005-0177"]}]},{"id":"CVE-2005-0149","published":"2005-02-15T05:00:00","updated_at":"2025-07-17T16:34:48.773814+00:00","description":"\nThunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the\nnetwork.cookie.disableCookieForMailNews preference, which could allow\nremote attackers to bypass the user's intended privacy and security policy\nby using cookies in e-mail messages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0149"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla","source":"https://ubuntu.com/security/cve?package=mozilla","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla","debian":"https://tracker.debian.org/pkg/mozilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0406","published":"2005-02-14T05:00:00","updated_at":"2025-07-17T16:33:15.537828+00:00","description":"\nA design flaw in image processing software that modifies JPEG images might\nnot modify the original EXIF thumbnail, which could lead to an information\nleak of potentially sensitive visual information that had been removed from\nthe main JPEG image.","ubuntu_description":"","notes":[{"author":"kees","note":"very general issue, and not presently addressed."}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0406"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0074","published":"2005-02-11T05:00:00","updated_at":"2025-07-17T16:34:42.165154+00:00","description":"\nBuffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute\narbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0074"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xpcd","source":"https://ubuntu.com/security/cve?package=xpcd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xpcd","debian":"https://tracker.debian.org/pkg/xpcd","statuses":[{"release_codename":"dapper","status":"released","description":"2.08-11.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.08-11.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0362","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:57.486667+00:00","description":"\nawstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary\ncommands via shell metacharacters in the (1) \"pluginmode\", (2)\n\"loadplugin\", or (3) \"noloadplugin\" parameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0362"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"awstats","source":"https://ubuntu.com/security/cve?package=awstats","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=awstats","debian":"https://tracker.debian.org/pkg/awstats","statuses":[{"release_codename":"dapper","status":"released","description":"6.5-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"6.5-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"6.5-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0982","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:12.843204+00:00","description":"\nBuffer overflow in the getauthfromURL function in httpget.c in mpg123\npre0.59s and mpg123 0.59r could allow remote attackers or local users to\nexecute arbitrary code via an mp3 file that contains a long string before\nthe @ (at sign) in a URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0982"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mpg123","source":"https://ubuntu.com/security/cve?package=mpg123","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mpg123","debian":"https://tracker.debian.org/pkg/mpg123","statuses":[{"release_codename":"dapper","status":"released","description":"0.59r-21","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.59r-21","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.59r-21","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0981","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:12.843204+00:00","description":"\nBuffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0\nallows remote attackers to execute arbitrary code via a certain image file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-10-1","https://ubuntu.com/security/notices/USN-7-1","https://ubuntu.com/security/notices/USN-7-1","https://www.cve.org/CVERecord?id=CVE-2004-0981"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.7-8","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.7-8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"dapper","status":"released","description":"6.2.4.5-0.6ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"6.2.4.5.dfsg1-0.10ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"6.2.4.5.dfsg1-0.14ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-7-1","USN-10-1"],"notices":[{"id":"USN-7-1","title":"imagemagick vulnerability","summary":"imagemagick vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-10-27T09:52:42","description":"A buffer overflow in imagemagick's EXIF parsing routine has been\ndiscovered in imagemagick versions prior to 6.1.0. Trying to query\nEXIF information of a malicious image file might result in execution\nof arbitrary code with the user's privileges.\n\nSince imagemagick can be used in custom printing systems, this also\nmight lead to privilege escalation (execute code with the printer\nspooler's privileges). However, Ubuntu's standard printing system does\nnot use imagemagick, thus there is no risk of privilege escalation in\na standard installation.","is_hidden":false,"release_packages":{"warty":[{"name":"libmagick6","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0981","CVE-2004-0981"]},{"id":"USN-10-1","title":"XML library vulnerabilities","summary":"XML library vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-10-30T04:52:49","description":"Several buffer overflows have been discovered in libxml2's FTP connection\nand DNS resolution functions. Supplying very long FTP URLs or IP\naddresses might result in execution of arbitrary code with the\nprivileges of the process using libxml2.\n\nSince libxml2 is used in packages like php4-imagick, the vulnerability\nalso might lead to privilege escalation, like executing attacker\nsupplied code with a web server's privileges.\n\nHowever, this does not affect the core XML parsing code, which is what\nthe majority of programs use this library for.","is_hidden":false,"release_packages":{"warty":[{"name":"libxml2","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0981"]}]},{"id":"CVE-2004-0980","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:12.843204+00:00","description":"\nFormat string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through\n3.0.11b8, when running in daemon mode with certain service types in use,\nallows remote servers to execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0980"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ez-ipupdate","source":"https://ubuntu.com/security/cve?package=ez-ipupdate","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ez-ipupdate","debian":"https://tracker.debian.org/pkg/ez-ipupdate","statuses":[{"release_codename":"dapper","status":"released","description":"3.0.11b8-10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.0.11b8-10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.0.11b8-10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0977","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:12.843204+00:00","description":"\nThe make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local\nusers to overwrite files via a symlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6-1","https://www.cve.org/CVERecord?id=CVE-2004-0977"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"postgresql","source":"https://ubuntu.com/security/cve?package=postgresql","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql","debian":"https://tracker.debian.org/pkg/postgresql","statuses":[{"release_codename":"dapper","status":"released","description":"7.5.16.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"7.5.16.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-7.4","source":"https://ubuntu.com/security/cve?package=postgresql-7.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-7.4","debian":"https://tracker.debian.org/pkg/postgresql-7.4","statuses":[{"release_codename":"dapper","status":"released","description":"7.4.12-3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"7.4.12-3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.0","source":"https://ubuntu.com/security/cve?package=postgresql-8.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-8.0","debian":"https://tracker.debian.org/pkg/postgresql-8.0","statuses":[{"release_codename":"dapper","status":"released","description":"8.0.7-2build1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.1","source":"https://ubuntu.com/security/cve?package=postgresql-8.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-8.1","debian":"https://tracker.debian.org/pkg/postgresql-8.1","statuses":[{"release_codename":"dapper","status":"released","description":"8.1.9-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"8.1.9-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"8.1.8-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"8.2.4-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6-1"],"notices":[{"id":"USN-6-1","title":"postgresql contributed script vulnerability","summary":"postgresql contributed script vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-10-27T09:52:20","description":"Recently, Trustix Secure Linux discovered a vulnerability in the\npostgresql-contrib package. The script \"make_oidjoins_check\" created\ntemporary files in an insecure way, which allowed a symlink attack to\ncreate or overwrite arbitrary files with the privileges of the user\ninvoking the script.","is_hidden":false,"release_packages":{"warty":[{"name":"postgresql-contrib","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0977"]}]},{"id":"CVE-2004-0976","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:12.843204+00:00","description":"\nMultiple scripts in the perl package in Trustix Secure Linux 1.5 through\n2.1 and other operating systems allows local users to overwrite files via a\nsymlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-16-1","https://www.cve.org/CVERecord?id=CVE-2004-0976"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"perl","source":"https://ubuntu.com/security/cve?package=perl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=perl","debian":"https://tracker.debian.org/pkg/perl","statuses":[{"release_codename":"dapper","status":"released","description":"5.8.7-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.8.7-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.8.7-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-16-1"],"notices":[{"id":"USN-16-1","title":"perl vulnerabilities","summary":"perl vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-03T07:49:29","description":"Recently, Trustix Secure Linux discovered some vulnerabilities in the\nperl package. The utility \"instmodsh\", the Perl package \"PPPort.pm\",\nand several test scripts (which are not shipped and only used during\nbuild) created temporary files in an insecure way, which could allow a\nsymlink attack to create or overwrite arbitrary files with the\nprivileges of the user invoking the program, or building the perl\npackage, respectively.","is_hidden":false,"release_packages":{"warty":[{"name":"perl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0976"]}]},{"id":"CVE-2004-0975","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:12.843204+00:00","description":"\nThe der_chop script in the openssl package in Trustix Secure Linux 1.5\nthrough 2.1 and other operating systems allows local users to overwrite\nfiles via a symlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-24-1","https://www.cve.org/CVERecord?id=CVE-2004-0975"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"dapper","status":"released","description":"0.9.8a-7ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.9.8b-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.9.8b-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openssl097","source":"https://ubuntu.com/security/cve?package=openssl097","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl097","debian":"https://tracker.debian.org/pkg/openssl097","statuses":[{"release_codename":"dapper","status":"released","description":"0.9.7g-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.9.7k-3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.9.7k-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-24-1"],"notices":[{"id":"USN-24-1","title":"openssl script vulnerability","summary":"openssl script vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-12T06:58:36","description":"Recently, Trustix Secure Linux discovered a vulnerability in the\nopenssl package. The auxiliary script \"der_chop\" created temporary\nfiles in an insecure way, which could allow a symlink attack to create\nor overwrite arbitrary files with the privileges of the user invoking\nthe program.","is_hidden":false,"release_packages":{"warty":[{"name":"openssl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0975"]}]},{"id":"CVE-2004-0974","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:12.843204+00:00","description":"\nThe netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly\nother operating systems, allows local users to overwrite files via a\nsymlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0974"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"netatalk","source":"https://ubuntu.com/security/cve?package=netatalk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=netatalk","debian":"https://tracker.debian.org/pkg/netatalk","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.3-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.3-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.3-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0972","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:10.947748+00:00","description":"\nThe lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5\nthrough 2.1, and possibly other operating systems, allows local users to\noverwrite files via a symlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-15-1","https://www.cve.org/CVERecord?id=CVE-2004-0972"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lvm10","source":"https://ubuntu.com/security/cve?package=lvm10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lvm10","debian":"https://tracker.debian.org/pkg/lvm10","statuses":[{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"1.0.8-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.0.8-12","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-15-1"],"notices":[{"id":"USN-15-1","title":"lvm10 vulnerability","summary":"lvm10 vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-02T07:52:52","description":"Recently, Trustix Secure Linux discovered a vulnerability in a\nsupplemental script of the lvm10 package. The program\n\"lvmcreate_initrd\" created a temporary directory in an insecure way,\nwhich could allow a symlink attack to create or overwrite arbitrary\nfiles with the privileges of the user invoking the program.","is_hidden":false,"release_packages":{"warty":[{"name":"lvm10","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0972"]}]},{"id":"CVE-2004-0970","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:10.947748+00:00","description":"\nThe (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used\nby other packages such as ncompress, allows local users to overwrite files\nvia a symlink attack on temporary files.  NOTE: the znew vulnerability may\noverlap CVE-2003-0367.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0970"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cscope","source":"https://ubuntu.com/security/cve?package=cscope","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cscope","debian":"https://tracker.debian.org/pkg/cscope","statuses":[{"release_codename":"dapper","status":"released","description":"15.5+cvs20050816-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"15.5+cvs20050816-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"15.5+cvs20050816-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0969","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:10.947748+00:00","description":"\nThe groffer script in the Groff package 1.18 and later versions, as used in\nTrustix Secure Linux 1.5 through 2.1, and possibly other operating systems,\nallows local users to overwrite files via a symlink attack on temporary\nfiles.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-13-1","https://www.cve.org/CVERecord?id=CVE-2004-0969"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"groff","source":"https://ubuntu.com/security/cve?package=groff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=groff","debian":"https://tracker.debian.org/pkg/groff","statuses":[{"release_codename":"dapper","status":"released","description":"1.18.1.1-11","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.18.1.1-11","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.18.1.1-11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-13-1"],"notices":[{"id":"USN-13-1","title":"groff utility vulnerability","summary":"groff utility vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-02T02:24:40","description":"Recently, Trustix Secure Linux discovered a vulnerability in the groff\npackage. The utility \"groffer\" created a temporary directory in an\ninsecure way, which allowed exploitation of a race condition to create\nor overwrite files with the privileges of the user invoking the\nprogram.","is_hidden":false,"release_packages":{"warty":[{"name":"groff","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0969"]}]},{"id":"CVE-2004-0968","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:10.947748+00:00","description":"\nThe catchsegv script in glibc 2.3.2 and earlier allows local users to\noverwrite files via a symlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4-1","https://www.cve.org/CVERecord?id=CVE-2004-0968"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"dapper","status":"released","description":"2.3.6-0ubuntu20","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.3.6-0ubuntu20","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.3.6-0ubuntu20","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4-1"],"notices":[{"id":"USN-4-1","title":"Standard C library script vulnerabilities","summary":"Standard C library script vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":["CVE-2004-0968"],"published":"2004-10-28T15:06:43","description":"Recently, Trustix Secure Linux discovered some vulnerabilities in the\nlibc6 package. The utilities \"catchsegv\" and \"glibcbug\" created\ntemporary files in an insecure way, which allowed a symlink attack to\ncreate or overwrite arbitrary files with the privileges of the user\ninvoking the program.","is_hidden":false,"release_packages":{"warty":[{"name":"libc6","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0968"]}]},{"id":"CVE-2004-0967","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:10.947748+00:00","description":"\nThe (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the\nESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1,\nand other operating systems, allow local users to overwrite files via a\nsymlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3-1","https://www.cve.org/CVERecord?id=CVE-2004-0967"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gs-common","source":"https://ubuntu.com/security/cve?package=gs-common","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gs-common","debian":"https://tracker.debian.org/pkg/gs-common","statuses":[{"release_codename":"dapper","status":"released","description":"0.3.9ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.3.9ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.3.9ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3-1"],"notices":[{"id":"USN-3-1","title":"GhostScript utility script vulnerabilities","summary":"GhostScript utility script vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-10-27T09:42:05","description":"Recently, Trustix Secure Linux discovered some vulnerabilities in the\ngs-common package. The utilities \"pv.sh\" and \"ps2epsi\" created\ntemporary files in an insecure way, which allowed a symlink attack to\ncreate or overwrite arbitrary files with the privileges of the user\ninvoking the program.","is_hidden":false,"release_packages":{"warty":[{"name":"gs-common","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0967"]}]},{"id":"CVE-2004-0966","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:10.947748+00:00","description":"\nThe (1) autopoint and (2) gettextize scripts in the GNU gettext package\n1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1\nand other operating systems, allows local users to overwrite files via a\nsymlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-5-1","https://www.cve.org/CVERecord?id=CVE-2004-0966"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gettext","source":"https://ubuntu.com/security/cve?package=gettext","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gettext","debian":"https://tracker.debian.org/pkg/gettext","statuses":[{"release_codename":"dapper","status":"released","description":"0.14.5-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.14.5-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.14.5-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5-1"],"notices":[{"id":"USN-5-1","title":"gettext vulnerabilities","summary":"gettext vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-10-27T09:45:55","description":"Recently, Trustix Secure Linux discovered some vulnerabilities in the\ngettext package. The programs \"autopoint\" and \"gettextize\" created\ntemporary files in an insecure way, which allowed a symlink attack to\ncreate or overwrite arbitrary files with the privileges of the user\ninvoking the program.","is_hidden":false,"release_packages":{"warty":[{"name":"gettext","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0966"]}]},{"id":"CVE-2004-0957","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:10.947748+00:00","description":"\nUnknown vulnerability in MySQL 3.23.58 and earlier, when a local user has\nprivileges for a database whose name includes a \"_\" (underscore), grants\nprivileges to other databases that have similar names, which can allow the\nuser to conduct unauthorized activities.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-109-1","https://ubuntu.com/security/notices/USN-32-1","https://www.cve.org/CVERecord?id=CVE-2004-0957"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mysql-dfsg","source":"https://ubuntu.com/security/cve?package=mysql-dfsg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg","debian":"https://tracker.debian.org/pkg/mysql-dfsg","statuses":[{"release_codename":"dapper","status":"released","description":"4.0.24-10ubuntu2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.0.24-10ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-4.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-4.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-4.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-4.1","statuses":[{"release_codename":"dapper","status":"released","description":"4.1.15-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.1.15-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"dapper","status":"released","description":"5.0.22-0ubuntu6.06.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.0.24a-9ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.0.38-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-109-1","USN-32-1"],"notices":[{"id":"USN-109-1","title":"MySQL vulnerability","summary":"MySQL vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-04-06T19:49:33","description":"USN-32-1 fixed a database privilege escalation vulnerability; original\nadvisory text:\n\n  \"If a user was granted privileges to a database with a name\n  containing an underscore (\"_\"), the user also gained the ability to\n  grant privileges to other databases with similar names.\n  (CAN-2004-0957)\"\n\nRecently a corner case was discovered where this vulnerability can\nstill be exploited, so another update is necessary.","is_hidden":false,"release_packages":{"warty":[{"name":"mysql-server","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0957"]},{"id":"USN-32-1","title":"mysql vulnerabilities","summary":"mysql vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-25T21:15:20","description":"Several vulnerabilities have been discovered in the MySQL database\nserver.\n\nLukasz Wojtow discovered a potential buffer overflow in the function\nmysql_real_connect(). A malicious name server could send specially\ncrafted DNS packages which might result in execution of arbitrary code\nwith the database server's privileges. However, it is believed that\nthis bug cannot be exploited with the C Standard library (glibc) that\nUbuntu uses. (CAN-2004-0836).\n\nDean Ellis noticed a flaw that allows an authorized MySQL user to\ncause a denial of service (crash or hang) via concurrent execution of\ncertain statements (ALTER TABLE ... UNION=, FLUSH TABLES) on tables of\ntype MERGE (CAN-2004-0837)\n\nSome query strings containing a double quote (like MATCH ... AGAINST\n(' some \" query' IN BOOLEAN MODE) ) that did not have a matching\nclosing double quote caused a denial of service (server crash). Again,\nthis is only exploitable by authorized mysql users.  (CAN-2004-0956)\n\nIf a user was granted privileges to a database with a name containing\nan underscore (\"_\"), the user also gained the ability to grant\nprivileges to other databases with similar names. (CAN-2004-0957)","is_hidden":false,"release_packages":{"warty":[{"name":"mysql-server","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0837","CVE-2004-0956","CVE-2004-0836","CVE-2004-0957"]}]},{"id":"CVE-2004-0942","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:08.912939+00:00","description":"\nApache webserver 2.0.52 and earlier allows remote attackers to cause a\ndenial of service (CPU consumption) via an HTTP GET request with a MIME\nheader containing multiple lines with a large number of space characters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-23-1","https://www.cve.org/CVERecord?id=CVE-2004-0942"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"edgy","status":"released","description":"2.0.55-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-3.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-23-1"],"notices":[{"id":"USN-23-1","title":"apache2 vulnerability","summary":"apache2 vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-12T06:56:14","description":"Chintan Trivedi discovered a Denial of Service vulnerability in\napache2. The field length limit was not enforced for certain malicious\nrequests. This could allow a remote attacker who is able to send large\namounts of data to a server to cause HTTP server instances to consume\nproportional amounts of memory, which can render the service\nunavailable.","is_hidden":false,"release_packages":{"warty":[{"name":"apache2-mpm-worker","version":"","is_source":false,"source_link":"","version_link":""},{"name":"apache2-mpm-perchild","version":"","is_source":false,"source_link":"","version_link":""},{"name":"apache2-mpm-prefork","version":"","is_source":false,"source_link":"","version_link":""},{"name":"apache2-mpm-threadpool","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0942"]}]}],"offset":78860,"limit":20,"total_results":79316}