Canonical Security Advisories · May 2013 — Canonical Security Advisories
53 advisories 53 CVEs 3 EXPLOITED

Ubuntu Security Notices (USN-NNNN-N) for 2013-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

UBUNTU-CVE-2013-2094

USNExploitedCISA KEV listedHIGH2013-05-14

CVEs:CVE-2013-2094

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:16.04:LTS linux
linux affected Ubuntu:14.04:LTS linux
linux-aws affected Ubuntu:14.04:LTS linux-aws
linux-aws affected Ubuntu:16.04:LTS linux-aws
linux-flo affected Ubuntu:16.04:LTS linux-flo
linux-gke affected Ubuntu:16.04:LTS linux-gke
linux-goldfish affected Ubuntu:16.04:LTS linux-goldfish
linux-hwe affected Ubuntu:16.04:LTS linux-hwe
linux-lts-utopic affected Ubuntu:14.04:LTS linux-lts-utopic
linux-lts-vivid affected Ubuntu:14.04:LTS linux-lts-vivid
linux-lts-wily affected Ubuntu:14.04:LTS linux-lts-wily
linux-lts-xenial affected Ubuntu:14.04:LTS linux-lts-xenial
linux-mako affected Ubuntu:16.04:LTS linux-mako
linux-raspi2 affected Ubuntu:16.04:LTS linux-raspi2
linux-snapdragon affected Ubuntu:16.04:LTS linux-snapdragon
Upstream advisory

UBUNTU-CVE-2013-2850

USNExploitedCISA KEV listedHIGH2013-05-30

CVEs:CVE-2013-2850

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:16.04:LTS linux
linux affected Ubuntu:14.04:LTS linux
linux-aws affected Ubuntu:14.04:LTS linux-aws
linux-aws affected Ubuntu:16.04:LTS linux-aws
linux-flo affected Ubuntu:16.04:LTS linux-flo
linux-gke affected Ubuntu:16.04:LTS linux-gke
linux-goldfish affected Ubuntu:16.04:LTS linux-goldfish
linux-hwe affected Ubuntu:16.04:LTS linux-hwe
linux-lts-utopic affected Ubuntu:14.04:LTS linux-lts-utopic
linux-lts-vivid affected Ubuntu:14.04:LTS linux-lts-vivid
linux-lts-wily affected Ubuntu:14.04:LTS linux-lts-wily
linux-lts-xenial affected Ubuntu:14.04:LTS linux-lts-xenial
linux-mako affected Ubuntu:16.04:LTS linux-mako
linux-raspi2 affected Ubuntu:16.04:LTS linux-raspi2
linux-snapdragon affected Ubuntu:16.04:LTS linux-snapdragon
Upstream advisory

UBUNTU-CVE-2013-0992

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-0992

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-0997

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-0997

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-0999

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-0999

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1000

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1000

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1001

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1001

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1002

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1002

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1003

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1003

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1004

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1004

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1005

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1005

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1006

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1006

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1007

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1007

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1008

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1008

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1010

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1010

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-0994

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-0994

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-0991

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-0991

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-0993

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-0993

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-0995

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-0995

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-0996

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-0996

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-0998

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-0998

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-1011

USNPoC exploitMEDIUM2013-05-19

CVEs:CVE-2013-1011

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2013-2058

USNEPSS <= 49%MEDIUM2013-05-07

CVEs:CVE-2013-2058

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:14.04:LTS linux
linux affected Ubuntu:16.04:LTS linux
linux-aws affected Ubuntu:16.04:LTS linux-aws
linux-aws affected Ubuntu:14.04:LTS linux-aws
linux-gke affected Ubuntu:16.04:LTS linux-gke
linux-hwe affected Ubuntu:16.04:LTS linux-hwe
linux-lts-utopic affected Ubuntu:14.04:LTS linux-lts-utopic
linux-lts-vivid affected Ubuntu:14.04:LTS linux-lts-vivid
linux-lts-wily affected Ubuntu:14.04:LTS linux-lts-wily
linux-lts-xenial affected Ubuntu:14.04:LTS linux-lts-xenial
linux-raspi2 affected Ubuntu:16.04:LTS linux-raspi2
linux-snapdragon affected Ubuntu:16.04:LTS linux-snapdragon
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.