UBUNTU-CVE-2025-9165

Source
https://ubuntu.com/security/CVE-2025-9165
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2025-9165
Upstream
Downstream
Related
Published
2025-08-19T20:15:00Z
Modified
2025-10-24T05:16:35Z
Severity
  • 2.5 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 1.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

A flaw has been found in LibTIFF 4.7.0. This affects the function TIFFmallocExt/TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".

References

Affected packages

Ubuntu:16.04:LTS

gdal

Package

Name
gdal
Purl
pkg:deb/ubuntu/gdal@1.11.3+dfsg-3build2?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.11.2+dfsg-3ubuntu3
1.11.2+dfsg-3ubuntu4
1.11.3+dfsg-2build1
1.11.3+dfsg-2build2
1.11.3+dfsg-2build3
1.11.3+dfsg-3
1.11.3+dfsg-3build1
1.11.3+dfsg-3build2

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "gdal-bin",
            "binary_version": "1.11.3+dfsg-3build2"
        },
        {
            "binary_name": "libgdal-dev",
            "binary_version": "1.11.3+dfsg-3build2"
        },
        {
            "binary_name": "libgdal-java",
            "binary_version": "1.11.3+dfsg-3build2"
        },
        {
            "binary_name": "libgdal-perl",
            "binary_version": "1.11.3+dfsg-3build2"
        },
        {
            "binary_name": "libgdal1-dev",
            "binary_version": "1.11.3+dfsg-3build2"
        },
        {
            "binary_name": "libgdal1i",
            "binary_version": "1.11.3+dfsg-3build2"
        },
        {
            "binary_name": "python-gdal",
            "binary_version": "1.11.3+dfsg-3build2"
        },
        {
            "binary_name": "python3-gdal",
            "binary_version": "1.11.3+dfsg-3build2"
        }
    ]
}

texmaker

Package

Name
texmaker
Purl
pkg:deb/ubuntu/texmaker@4.4.1-1.1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.4.1-1
4.4.1-1.1

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "texmaker",
            "binary_version": "4.4.1-1.1"
        },
        {
            "binary_name": "texmaker-data",
            "binary_version": "4.4.1-1.1"
        }
    ]
}

Ubuntu:18.04:LTS

neuron

Package

Name
neuron
Purl
pkg:deb/ubuntu/neuron@7.5-1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.5-1

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "neuron",
            "binary_version": "7.5-1"
        },
        {
            "binary_name": "neuron-dev",
            "binary_version": "7.5-1"
        },
        {
            "binary_name": "python3-neuron",
            "binary_version": "7.5-1"
        }
    ]
}

qtwebengine-opensource-src

Package

Name
qtwebengine-opensource-src
Purl
pkg:deb/ubuntu/qtwebengine-opensource-src@5.9.5+dfsg-0ubuntu2?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.9.1+dfsg-4
5.9.1+dfsg-4ubuntu1
5.9.2+dfsg-2ubuntu1
5.9.3+dfsg-0ubuntu1
5.9.4+dfsg-0ubuntu1
5.9.5+dfsg-0ubuntu2

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "libqt5webengine-data",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        },
        {
            "binary_name": "libqt5webengine5",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        },
        {
            "binary_name": "libqt5webenginecore5",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        },
        {
            "binary_name": "libqt5webenginewidgets5",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        },
        {
            "binary_name": "qml-module-qtwebengine",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        },
        {
            "binary_name": "qtwebengine5-dev",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        },
        {
            "binary_name": "qtwebengine5-dev-tools",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        },
        {
            "binary_name": "qtwebengine5-doc-html",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        },
        {
            "binary_name": "qtwebengine5-examples",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        },
        {
            "binary_name": "qtwebengine5-private-dev",
            "binary_version": "5.9.5+dfsg-0ubuntu2"
        }
    ]
}

texmaker

Package

Name
texmaker
Purl
pkg:deb/ubuntu/texmaker@5.0.2-1build2?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.5-1

5.*

5.0.2-1
5.0.2-1build1
5.0.2-1build2

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "texmaker",
            "binary_version": "5.0.2-1build2"
        },
        {
            "binary_name": "texmaker-data",
            "binary_version": "5.0.2-1build2"
        }
    ]
}

Ubuntu:20.04:LTS

neuron

Package

Name
neuron
Purl
pkg:deb/ubuntu/neuron@7.6.3-1build4?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.6.3-1build2
7.6.3-1build3
7.6.3-1build4

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "neuron",
            "binary_version": "7.6.3-1build4"
        },
        {
            "binary_name": "neuron-dev",
            "binary_version": "7.6.3-1build4"
        },
        {
            "binary_name": "python3-neuron",
            "binary_version": "7.6.3-1build4"
        }
    ]
}

qtwebengine-opensource-src

Package

Name
qtwebengine-opensource-src
Purl
pkg:deb/ubuntu/qtwebengine-opensource-src@5.12.8+dfsg-0ubuntu1.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.12.4+dfsg-1ubuntu1
5.12.4+dfsg-1ubuntu3
5.12.5+dfsg-3ubuntu1
5.12.5+dfsg-6ubuntu2
5.12.5+dfsg-7
5.12.5+dfsg-7build1
5.12.8+dfsg-0ubuntu1
5.12.8+dfsg-0ubuntu1.1

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "libqt5webengine-data",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "libqt5webengine5",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "libqt5webenginecore5",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "libqt5webenginewidgets5",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "qml-module-qtwebengine",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "qtwebengine5-dev",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "qtwebengine5-dev-tools",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "qtwebengine5-doc-html",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "qtwebengine5-examples",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "qtwebengine5-private-dev",
            "binary_version": "5.12.8+dfsg-0ubuntu1.1"
        }
    ]
}

texmaker

Package

Name
texmaker
Purl
pkg:deb/ubuntu/texmaker@5.0.3-1build5?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.0.3-1build2
5.0.3-1build3
5.0.3-1build4
5.0.3-1build5

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "texmaker",
            "binary_version": "5.0.3-1build5"
        },
        {
            "binary_name": "texmaker-data",
            "binary_version": "5.0.3-1build5"
        }
    ]
}

Ubuntu:22.04:LTS

neuron

Package

Name
neuron
Purl
pkg:deb/ubuntu/neuron@7.6.3-1build6?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.6.3-1build5
7.6.3-1build6

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "neuron",
            "binary_version": "7.6.3-1build6"
        },
        {
            "binary_name": "neuron-dev",
            "binary_version": "7.6.3-1build6"
        },
        {
            "binary_name": "python3-neuron",
            "binary_version": "7.6.3-1build6"
        }
    ]
}

qtwebengine-opensource-src

Package

Name
qtwebengine-opensource-src
Purl
pkg:deb/ubuntu/qtwebengine-opensource-src@5.15.9+dfsg-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.15.6+dfsg-1
5.15.6+dfsg-2
5.15.7+dfsg-2
5.15.8+dfsg-1
5.15.8+dfsg-1build1
5.15.8+dfsg-1build2
5.15.8+dfsg-2
5.15.9+dfsg-1

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "libqt5pdf5",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "libqt5pdfwidgets5",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "libqt5webengine-data",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "libqt5webengine5",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "libqt5webenginecore5",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "libqt5webenginewidgets5",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qml-module-qtquick-pdf",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qml-module-qtwebengine",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qt5-image-formats-plugin-pdf",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qtpdf5-dev",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qtpdf5-doc-html",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qtpdf5-examples",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qtwebengine5-dev",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qtwebengine5-dev-tools",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qtwebengine5-doc-html",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qtwebengine5-examples",
            "binary_version": "5.15.9+dfsg-1"
        },
        {
            "binary_name": "qtwebengine5-private-dev",
            "binary_version": "5.15.9+dfsg-1"
        }
    ]
}

texmaker

Package

Name
texmaker
Purl
pkg:deb/ubuntu/texmaker@5.0.3-1build9?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.0.3-1build8
5.0.3-1build9

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "texmaker",
            "binary_version": "5.0.3-1build9"
        },
        {
            "binary_name": "texmaker-data",
            "binary_version": "5.0.3-1build9"
        }
    ]
}

tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.3.0-6ubuntu0.12?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.0-6ubuntu0.12

Affected versions

4.*

4.3.0-1
4.3.0-2
4.3.0-3
4.3.0-3build1
4.3.0-4
4.3.0-5
4.3.0-6
4.3.0-6ubuntu0.1
4.3.0-6ubuntu0.2
4.3.0-6ubuntu0.3
4.3.0-6ubuntu0.4
4.3.0-6ubuntu0.5
4.3.0-6ubuntu0.6
4.3.0-6ubuntu0.7
4.3.0-6ubuntu0.8
4.3.0-6ubuntu0.9
4.3.0-6ubuntu0.10
4.3.0-6ubuntu0.11

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.3.0-6ubuntu0.12"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.3.0-6ubuntu0.12"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.3.0-6ubuntu0.12"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.3.0-6ubuntu0.12"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.3.0-6ubuntu0.12"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.3.0-6ubuntu0.12"
        }
    ]
}

Ubuntu:24.04:LTS

qtwebengine-opensource-src

Package

Name
qtwebengine-opensource-src
Purl
pkg:deb/ubuntu/qtwebengine-opensource-src@5.15.16+dfsg-3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.15.15+dfsg-2
5.15.15+dfsg-2build2
5.15.15+dfsg-2ubuntu1
5.15.16+dfsg-1
5.15.16+dfsg-1ubuntu2
5.15.16+dfsg-1ubuntu4
5.15.16+dfsg-3

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "libqt5pdf5",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "libqt5pdfwidgets5",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "libqt5webengine-data",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "libqt5webengine5",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "libqt5webenginecore5",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "libqt5webenginewidgets5",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qml-module-qtquick-pdf",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qml-module-qtwebengine",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qt5-image-formats-plugin-pdf",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qtpdf5-dev",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qtpdf5-doc-html",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qtpdf5-examples",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qtwebengine5-dev",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qtwebengine5-dev-tools",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qtwebengine5-doc-html",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qtwebengine5-examples",
            "binary_version": "5.15.16+dfsg-3"
        },
        {
            "binary_name": "qtwebengine5-private-dev",
            "binary_version": "5.15.16+dfsg-3"
        }
    ]
}

texmaker

Package

Name
texmaker
Purl
pkg:deb/ubuntu/texmaker@5.1.3+dfsg-1build8?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.1.3+dfsg-1build4
5.1.3+dfsg-1build5
5.1.3+dfsg-1build6
5.1.3+dfsg-1build7
5.1.3+dfsg-1build8

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "texmaker",
            "binary_version": "5.1.3+dfsg-1build8"
        },
        {
            "binary_name": "texmaker-data",
            "binary_version": "5.1.3+dfsg-1build8"
        }
    ]
}

tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.5.1+git230720-4ubuntu2.4?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.1+git230720-4ubuntu2.4

Affected versions

4.*

4.5.1+git230720-1ubuntu1
4.5.1+git230720-3ubuntu1
4.5.1+git230720-4ubuntu1
4.5.1+git230720-4ubuntu2
4.5.1+git230720-4ubuntu2.1
4.5.1+git230720-4ubuntu2.2
4.5.1+git230720-4ubuntu2.3

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.5.1+git230720-4ubuntu2.4"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.5.1+git230720-4ubuntu2.4"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.5.1+git230720-4ubuntu2.4"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.5.1+git230720-4ubuntu2.4"
        },
        {
            "binary_name": "libtiff6",
            "binary_version": "4.5.1+git230720-4ubuntu2.4"
        },
        {
            "binary_name": "libtiffxx6",
            "binary_version": "4.5.1+git230720-4ubuntu2.4"
        }
    ]
}

Ubuntu:25.04

qtwebengine-opensource-src

Package

Name
qtwebengine-opensource-src
Purl
pkg:deb/ubuntu/qtwebengine-opensource-src@5.15.18+dfsg-2?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.15.17+dfsg-4
5.15.17+dfsg-5
5.15.17+dfsg2-1
5.15.17+dfsg2-2
5.15.17+dfsg2-3
5.15.18+dfsg-1
5.15.18+dfsg-2

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "libqt5pdf5",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "libqt5pdfwidgets5",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "libqt5webengine-data",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "libqt5webengine5",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "libqt5webenginecore5",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "libqt5webenginewidgets5",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qml-module-qtquick-pdf",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qml-module-qtwebengine",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qt5-image-formats-plugin-pdf",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qtpdf5-dev",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qtpdf5-doc-html",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qtpdf5-examples",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qtwebengine5-dev",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qtwebengine5-dev-tools",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qtwebengine5-doc-html",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qtwebengine5-examples",
            "binary_version": "5.15.18+dfsg-2"
        },
        {
            "binary_name": "qtwebengine5-private-dev",
            "binary_version": "5.15.18+dfsg-2"
        }
    ]
}

texmaker

Package

Name
texmaker
Purl
pkg:deb/ubuntu/texmaker@5.1.3+dfsg-3?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.1.3+dfsg-2build1
5.1.3+dfsg-3

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "texmaker",
            "binary_version": "5.1.3+dfsg-3"
        },
        {
            "binary_name": "texmaker-data",
            "binary_version": "5.1.3+dfsg-3"
        }
    ]
}

tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.5.1+git230720-4ubuntu4.2?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.1+git230720-4ubuntu4.2

Affected versions

4.*

4.5.1+git230720-4ubuntu4
4.5.1+git230720-4ubuntu4.1

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.5.1+git230720-4ubuntu4.2"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.5.1+git230720-4ubuntu4.2"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.5.1+git230720-4ubuntu4.2"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.5.1+git230720-4ubuntu4.2"
        },
        {
            "binary_name": "libtiff6",
            "binary_version": "4.5.1+git230720-4ubuntu4.2"
        },
        {
            "binary_name": "libtiffxx6",
            "binary_version": "4.5.1+git230720-4ubuntu4.2"
        }
    ]
}

Ubuntu:25.10

qtwebengine-opensource-src

Package

Name
qtwebengine-opensource-src
Purl
pkg:deb/ubuntu/qtwebengine-opensource-src@5.15.19+dfsg2-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.15.18+dfsg-2
5.15.18+dfsg-2build1
5.15.19+dfsg-1
5.15.19+dfsg2-1

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "libqt5pdf5",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "libqt5pdfwidgets5",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "libqt5webengine-data",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "libqt5webengine5",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "libqt5webenginecore5",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "libqt5webenginewidgets5",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qml-module-qtquick-pdf",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qml-module-qtwebengine",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qt5-image-formats-plugin-pdf",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qtpdf5-dev",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qtpdf5-doc-html",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qtpdf5-examples",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qtwebengine5-dev",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qtwebengine5-dev-tools",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qtwebengine5-doc-html",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qtwebengine5-examples",
            "binary_version": "5.15.19+dfsg2-1"
        },
        {
            "binary_name": "qtwebengine5-private-dev",
            "binary_version": "5.15.19+dfsg2-1"
        }
    ]
}

texmaker

Package

Name
texmaker
Purl
pkg:deb/ubuntu/texmaker@5.1.3+dfsg-3build1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.1.3+dfsg-3
5.1.3+dfsg-3build1

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "texmaker",
            "binary_version": "5.1.3+dfsg-3build1"
        },
        {
            "binary_name": "texmaker-data",
            "binary_version": "5.1.3+dfsg-3build1"
        }
    ]
}

tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.7.0-3ubuntu3?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.7.0-3ubuntu3

Affected versions

4.*

4.5.1+git230720-4ubuntu4
4.7.0-3ubuntu1
4.7.0-3ubuntu2

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.7.0-3ubuntu3"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.7.0-3ubuntu3"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.7.0-3ubuntu3"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.7.0-3ubuntu3"
        },
        {
            "binary_name": "libtiff6",
            "binary_version": "4.7.0-3ubuntu3"
        },
        {
            "binary_name": "libtiffxx6",
            "binary_version": "4.7.0-3ubuntu3"
        }
    ]
}

Ubuntu:Pro:14.04:LTS

gdal

Package

Name
gdal
Purl
pkg:deb/ubuntu/gdal@1.10.1+dfsg-5ubuntu1+esm1?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.9.0-3.1ubuntu4
1.9.0-3.1ubuntu6
1.10.1+dfsg-2
1.10.1+dfsg-2build1
1.10.1+dfsg-3
1.10.1+dfsg-3build1
1.10.1+dfsg-3build2
1.10.1+dfsg-3ubuntu1
1.10.1+dfsg-3ubuntu2
1.10.1+dfsg-5ubuntu1
1.10.1+dfsg-5ubuntu1+esm1

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "binaries": [
        {
            "binary_name": "gdal-bin",
            "binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
        },
        {
            "binary_name": "libgdal-dev",
            "binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
        },
        {
            "binary_name": "libgdal-java",
            "binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
        },
        {
            "binary_name": "libgdal-perl",
            "binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
        },
        {
            "binary_name": "libgdal1-dev",
            "binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
        },
        {
            "binary_name": "libgdal1h",
            "binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
        },
        {
            "binary_name": "python-gdal",
            "binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
        },
        {
            "binary_name": "python3-gdal",
            "binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
        }
    ]
}

tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.0.3-7ubuntu0.11+esm16?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.3-7ubuntu0.11+esm16

Affected versions

4.*

4.0.2-4ubuntu3
4.0.3-5ubuntu1
4.0.3-6
4.0.3-6ubuntu1
4.0.3-7
4.0.3-7ubuntu0.1
4.0.3-7ubuntu0.2
4.0.3-7ubuntu0.3
4.0.3-7ubuntu0.4
4.0.3-7ubuntu0.6
4.0.3-7ubuntu0.7
4.0.3-7ubuntu0.8
4.0.3-7ubuntu0.9
4.0.3-7ubuntu0.10
4.0.3-7ubuntu0.11
4.0.3-7ubuntu0.11+esm1
4.0.3-7ubuntu0.11+esm2
4.0.3-7ubuntu0.11+esm3
4.0.3-7ubuntu0.11+esm4
4.0.3-7ubuntu0.11+esm5
4.0.3-7ubuntu0.11+esm6
4.0.3-7ubuntu0.11+esm7
4.0.3-7ubuntu0.11+esm8
4.0.3-7ubuntu0.11+esm9
4.0.3-7ubuntu0.11+esm10
4.0.3-7ubuntu0.11+esm11
4.0.3-7ubuntu0.11+esm12
4.0.3-7ubuntu0.11+esm13
4.0.3-7ubuntu0.11+esm14
4.0.3-7ubuntu0.11+esm15

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.0.3-7ubuntu0.11+esm16"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.0.3-7ubuntu0.11+esm16"
        },
        {
            "binary_name": "libtiff4-dev",
            "binary_version": "4.0.3-7ubuntu0.11+esm16"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.0.3-7ubuntu0.11+esm16"
        },
        {
            "binary_name": "libtiff5-alt-dev",
            "binary_version": "4.0.3-7ubuntu0.11+esm16"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.0.3-7ubuntu0.11+esm16"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.0.3-7ubuntu0.11+esm16"
        }
    ]
}

Ubuntu:Pro:16.04:LTS

tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.0.6-1ubuntu0.8+esm19?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.6-1ubuntu0.8+esm19

Affected versions

4.*

4.0.3-12.3ubuntu2
4.0.5-1
4.0.6-1
4.0.6-1ubuntu0.1
4.0.6-1ubuntu0.2
4.0.6-1ubuntu0.3
4.0.6-1ubuntu0.4
4.0.6-1ubuntu0.5
4.0.6-1ubuntu0.6
4.0.6-1ubuntu0.7
4.0.6-1ubuntu0.8
4.0.6-1ubuntu0.8+esm1
4.0.6-1ubuntu0.8+esm2
4.0.6-1ubuntu0.8+esm3
4.0.6-1ubuntu0.8+esm4
4.0.6-1ubuntu0.8+esm6
4.0.6-1ubuntu0.8+esm7
4.0.6-1ubuntu0.8+esm8
4.0.6-1ubuntu0.8+esm9
4.0.6-1ubuntu0.8+esm10
4.0.6-1ubuntu0.8+esm11
4.0.6-1ubuntu0.8+esm12
4.0.6-1ubuntu0.8+esm13
4.0.6-1ubuntu0.8+esm14
4.0.6-1ubuntu0.8+esm15
4.0.6-1ubuntu0.8+esm16
4.0.6-1ubuntu0.8+esm17
4.0.6-1ubuntu0.8+esm18

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.0.6-1ubuntu0.8+esm19"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.0.6-1ubuntu0.8+esm19"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.0.6-1ubuntu0.8+esm19"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.0.6-1ubuntu0.8+esm19"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.0.6-1ubuntu0.8+esm19"
        }
    ]
}

Ubuntu:Pro:18.04:LTS

tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.0.9-5ubuntu0.10+esm9?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.9-5ubuntu0.10+esm9

Affected versions

4.*

4.0.8-5
4.0.8-6
4.0.9-1
4.0.9-2
4.0.9-3
4.0.9-4
4.0.9-4ubuntu1
4.0.9-5
4.0.9-5ubuntu0.1
4.0.9-5ubuntu0.2
4.0.9-5ubuntu0.3
4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.5
4.0.9-5ubuntu0.6
4.0.9-5ubuntu0.7
4.0.9-5ubuntu0.8
4.0.9-5ubuntu0.9
4.0.9-5ubuntu0.10
4.0.9-5ubuntu0.10+esm1
4.0.9-5ubuntu0.10+esm2
4.0.9-5ubuntu0.10+esm3
4.0.9-5ubuntu0.10+esm4
4.0.9-5ubuntu0.10+esm5
4.0.9-5ubuntu0.10+esm6
4.0.9-5ubuntu0.10+esm7
4.0.9-5ubuntu0.10+esm8

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.0.9-5ubuntu0.10+esm9"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.0.9-5ubuntu0.10+esm9"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.0.9-5ubuntu0.10+esm9"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.0.9-5ubuntu0.10+esm9"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.0.9-5ubuntu0.10+esm9"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.0.9-5ubuntu0.10+esm9"
        }
    ]
}

Ubuntu:Pro:20.04:LTS

tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.1.0+git191117-2ubuntu0.20.04.14+esm2?arch=source&distro=esm-infra/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.0+git191117-2ubuntu0.20.04.14+esm2

Affected versions

4.*

4.0.10+git191003-1
4.1.0+git191117-1
4.1.0+git191117-2
4.1.0+git191117-2build1
4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.4
4.1.0+git191117-2ubuntu0.20.04.5
4.1.0+git191117-2ubuntu0.20.04.6
4.1.0+git191117-2ubuntu0.20.04.7
4.1.0+git191117-2ubuntu0.20.04.8
4.1.0+git191117-2ubuntu0.20.04.9
4.1.0+git191117-2ubuntu0.20.04.10
4.1.0+git191117-2ubuntu0.20.04.11
4.1.0+git191117-2ubuntu0.20.04.12
4.1.0+git191117-2ubuntu0.20.04.13
4.1.0+git191117-2ubuntu0.20.04.14
4.1.0+git191117-2ubuntu0.20.04.14+esm1

Ecosystem specific

{
    "priority_reason": "Only a memory leak in a command line tool",
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm2"
        }
    ]
}