UBUNTU-CVE-2022-31129

Source
https://ubuntu.com/security/CVE-2022-31129
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2022-31129
Upstream
Downstream
Related
Published
2022-07-06T18:15:00Z
Modified
2025-10-24T04:53:40Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried by default) has quadratic (N^2) complexity on specific inputs. Users may notice a noticeable slowdown is observed with inputs above 10k characters. Users who pass user-provided strings without sanity length checks to moment constructor are vulnerable to (Re)DoS attacks. The problem is patched in 2.29.4, the patch can be applied to all affected versions with minimal tweaking. Users are advised to upgrade. Users unable to upgrade should consider limiting date lengths accepted from user input.

References

Affected packages

Ubuntu:16.04:LTS

gnucash

Package

Name
gnucash
Purl
pkg:deb/ubuntu/gnucash@1:2.6.12-1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*

1:2.6.6-2ubuntu2
1:2.6.9-1ubuntu1
1:2.6.12-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:2.6.12-1",
            "binary_name": "gnucash"
        },
        {
            "binary_version": "1:2.6.12-1",
            "binary_name": "gnucash-common"
        },
        {
            "binary_version": "1:2.6.12-1",
            "binary_name": "python-gnucash"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

sabnzbdplus

Package

Name
sabnzbdplus
Purl
pkg:deb/ubuntu/sabnzbdplus@0.7.20+dfsg-1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.7.20-1
0.7.20+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.7.20+dfsg-1",
            "binary_name": "sabnzbdplus"
        },
        {
            "binary_version": "0.7.20+dfsg-1",
            "binary_name": "sabnzbdplus-theme-classic"
        },
        {
            "binary_version": "0.7.20+dfsg-1",
            "binary_name": "sabnzbdplus-theme-iphone"
        },
        {
            "binary_version": "0.7.20+dfsg-1",
            "binary_name": "sabnzbdplus-theme-mobile"
        },
        {
            "binary_version": "0.7.20+dfsg-1",
            "binary_name": "sabnzbdplus-theme-plush"
        },
        {
            "binary_version": "0.7.20+dfsg-1",
            "binary_name": "sabnzbdplus-theme-smpl"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

wordpress

Package

Name
wordpress
Purl
pkg:deb/ubuntu/wordpress@4.4.2+dfsg-1ubuntu1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.3+dfsg-1
4.3.1+dfsg-1
4.4+dfsg-1
4.4.1+dfsg-1
4.4.2+dfsg-1
4.4.2+dfsg-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress"
        },
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress-l10n"
        },
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress-theme-twentyfifteen"
        },
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress-theme-twentyfourteen"
        },
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress-theme-twentysixteen"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:18.04:LTS

node-moment

Package

Name
node-moment
Purl
pkg:deb/ubuntu/node-moment@2.20.1+ds-1ubuntu0.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.20.1+ds-1ubuntu0.1

Affected versions

2.*

2.18.1+ds-1
2.19.1+ds-1
2.19.2+ds-1
2.19.3+ds-1
2.19.4+ds-1
2.20.1+ds-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.20.1+ds-1ubuntu0.1",
            "binary_name": "libjs-moment"
        },
        {
            "binary_version": "2.20.1+ds-1ubuntu0.1",
            "binary_name": "node-moment"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

gnucash

Package

Name
gnucash
Purl
pkg:deb/ubuntu/gnucash@1:2.6.19-1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*

1:2.6.17-1ubuntu1
1:2.6.18-1
1:2.6.19-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:2.6.19-1",
            "binary_name": "gnucash"
        },
        {
            "binary_version": "1:2.6.19-1",
            "binary_name": "gnucash-common"
        },
        {
            "binary_version": "1:2.6.19-1",
            "binary_name": "python-gnucash"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

mediawiki

Package

Name
mediawiki
Purl
pkg:deb/ubuntu/mediawiki@1:1.27.4-3?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.27.3-1
1:1.27.4-1
1:1.27.4-2
1:1.27.4-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:1.27.4-3",
            "binary_name": "mediawiki"
        },
        {
            "binary_version": "1:1.27.4-3",
            "binary_name": "mediawiki-classes"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

sabnzbdplus

Package

Name
sabnzbdplus
Purl
pkg:deb/ubuntu/sabnzbdplus@2.3.2+dfsg-1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.1.1+dfsg-1

2.*

2.3.1+dfsg-1
2.3.2+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.3.2+dfsg-1",
            "binary_name": "sabnzbdplus"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

syncthing

Package

Name
syncthing
Purl
pkg:deb/ubuntu/syncthing@0.14.43+ds1-6?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.14.36+ds1-1
0.14.38+ds1-1
0.14.43+ds1-5
0.14.43+ds1-6

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.14.43+ds1-6",
            "binary_name": "golang-github-syncthing-syncthing-dev"
        },
        {
            "binary_version": "0.14.43+ds1-6",
            "binary_name": "syncthing"
        },
        {
            "binary_version": "0.14.43+ds1-6",
            "binary_name": "syncthing-discosrv"
        },
        {
            "binary_version": "0.14.43+ds1-6",
            "binary_name": "syncthing-relaysrv"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

wordpress

Package

Name
wordpress
Purl
pkg:deb/ubuntu/wordpress@4.9.5+dfsg1-1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.8.2+dfsg-2
4.8.3+dfsg-1
4.9.1+dfsg-1
4.9.2+dfsg-1
4.9.4+dfsg-1
4.9.5+dfsg1-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.9.5+dfsg1-1",
            "binary_name": "wordpress"
        },
        {
            "binary_version": "4.9.5+dfsg1-1",
            "binary_name": "wordpress-l10n"
        },
        {
            "binary_version": "4.9.5+dfsg1-1",
            "binary_name": "wordpress-theme-twentyfifteen"
        },
        {
            "binary_version": "4.9.5+dfsg1-1",
            "binary_name": "wordpress-theme-twentyseventeen"
        },
        {
            "binary_version": "4.9.5+dfsg1-1",
            "binary_name": "wordpress-theme-twentysixteen"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:20.04:LTS

node-moment

Package

Name
node-moment
Purl
pkg:deb/ubuntu/node-moment@2.24.0+ds-2ubuntu0.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.0+ds-2ubuntu0.1

Affected versions

2.*

2.24.0+ds-1
2.24.0+ds-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.24.0+ds-2ubuntu0.1",
            "binary_name": "libjs-moment"
        },
        {
            "binary_version": "2.24.0+ds-2ubuntu0.1",
            "binary_name": "node-moment"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

gnucash

Package

Name
gnucash
Purl
pkg:deb/ubuntu/gnucash@1:3.8b-1ubuntu1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:3.*

1:3.7-1ubuntu1
1:3.7-1ubuntu2
1:3.7-2ubuntu1
1:3.8b-1
1:3.8b-1build2
1:3.8b-1build3
1:3.8b-1build4
1:3.8b-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:3.8b-1ubuntu1",
            "binary_name": "gnucash"
        },
        {
            "binary_version": "1:3.8b-1ubuntu1",
            "binary_name": "gnucash-common"
        },
        {
            "binary_version": "1:3.8b-1ubuntu1",
            "binary_name": "python3-gnucash"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

mediawiki

Package

Name
mediawiki
Purl
pkg:deb/ubuntu/mediawiki@1:1.31.7-1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.31.2-1ubuntu1
1:1.31.5-1
1:1.31.5-1ubuntu1
1:1.31.5-2
1:1.31.5-3
1:1.31.5-3ubuntu1
1:1.31.6-1
1:1.31.7-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:1.31.7-1",
            "binary_name": "mediawiki"
        },
        {
            "binary_version": "1:1.31.7-1",
            "binary_name": "mediawiki-classes"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ntopng

Package

Name
ntopng
Purl
pkg:deb/ubuntu/ntopng@3.8+dfsg1-2.1build3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.8+dfsg1-2.1build3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.8+dfsg1-2.1build3",
            "binary_name": "ntopng"
        },
        {
            "binary_version": "3.8+dfsg1-2.1build3",
            "binary_name": "ntopng-data"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

omnidb

Package

Name
omnidb
Purl
pkg:deb/ubuntu/omnidb@2.17.0+ds-1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.16.0+ds-2
2.16.0+ds-2build1
2.16.0+ds-3
2.16.0+ds-4
2.16.0+ds-4build1
2.17.0+ds-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.17.0+ds-1",
            "binary_name": "omnidb-common"
        },
        {
            "binary_version": "2.17.0+ds-1",
            "binary_name": "omnidb-server"
        },
        {
            "binary_version": "2.17.0+ds-1",
            "binary_name": "postgresql-12-omnidb"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ruby-momentjs-rails

Package

Name
ruby-momentjs-rails
Purl
pkg:deb/ubuntu/ruby-momentjs-rails@2.20.1-2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.20.1-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.20.1-2",
            "binary_name": "ruby-momentjs-rails"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

sabnzbdplus

Package

Name
sabnzbdplus
Purl
pkg:deb/ubuntu/sabnzbdplus@3.0.0~0git20200408+dfsg-1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.6+dfsg-1
2.3.6+dfsg-1build1
2.3.6+dfsg-1ubuntu1

3.*

3.0.0~0git20200408+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.0~0git20200408+dfsg-1",
            "binary_name": "sabnzbdplus"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

syncthing

Package

Name
syncthing
Purl
pkg:deb/ubuntu/syncthing@1.1.4~ds1-4ubuntu1.2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.1.4~ds1-4
1.1.4~ds1-4ubuntu1
1.1.4~ds1-4ubuntu1.1
1.1.4~ds1-4ubuntu1.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.1.4~ds1-4ubuntu1.2",
            "binary_name": "golang-github-syncthing-syncthing-dev"
        },
        {
            "binary_version": "1.1.4~ds1-4ubuntu1.2",
            "binary_name": "syncthing"
        },
        {
            "binary_version": "1.1.4~ds1-4ubuntu1.2",
            "binary_name": "syncthing-discosrv"
        },
        {
            "binary_version": "1.1.4~ds1-4ubuntu1.2",
            "binary_name": "syncthing-relaysrv"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

wordpress

Package

Name
wordpress
Purl
pkg:deb/ubuntu/wordpress@5.3.2+dfsg1-1ubuntu1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.2.2+dfsg1-1
5.2.4+dfsg1-1
5.3.2+dfsg1-1
5.3.2+dfsg1-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.3.2+dfsg1-1ubuntu1",
            "binary_name": "wordpress"
        },
        {
            "binary_version": "5.3.2+dfsg1-1ubuntu1",
            "binary_name": "wordpress-l10n"
        },
        {
            "binary_version": "5.3.2+dfsg1-1ubuntu1",
            "binary_name": "wordpress-theme-twentynineteen"
        },
        {
            "binary_version": "5.3.2+dfsg1-1ubuntu1",
            "binary_name": "wordpress-theme-twentyseventeen"
        },
        {
            "binary_version": "5.3.2+dfsg1-1ubuntu1",
            "binary_name": "wordpress-theme-twentysixteen"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:22.04:LTS

gnucash

Package

Name
gnucash
Purl
pkg:deb/ubuntu/gnucash@1:4.8-1build2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:4.*

1:4.4-1ubuntu1
1:4.8-1build2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:4.8-1build2",
            "binary_name": "gnucash"
        },
        {
            "binary_version": "1:4.8-1build2",
            "binary_name": "gnucash-common"
        },
        {
            "binary_version": "1:4.8-1build2",
            "binary_name": "python3-gnucash"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

mediawiki

Package

Name
mediawiki
Purl
pkg:deb/ubuntu/mediawiki@1:1.35.6-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.35.3-1
1:1.35.4-1
1:1.35.5-1
1:1.35.5-1ubuntu1
1:1.35.5-1ubuntu2
1:1.35.5-1ubuntu3
1:1.35.6-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:1.35.6-1",
            "binary_name": "mediawiki"
        },
        {
            "binary_version": "1:1.35.6-1",
            "binary_name": "mediawiki-classes"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

node-moment

Package

Name
node-moment
Purl
pkg:deb/ubuntu/node-moment@2.29.1+ds-3ubuntu0.2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.29.1+ds-3ubuntu0.2

Affected versions

2.*

2.29.1+ds-2
2.29.1+ds-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.29.1+ds-3ubuntu0.2",
            "binary_name": "libjs-moment"
        },
        {
            "binary_version": "2.29.1+ds-3ubuntu0.2",
            "binary_name": "node-moment"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ntopng

Package

Name
ntopng
Purl
pkg:deb/ubuntu/ntopng@5.2.1+dfsg1-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.2.1+dfsg1-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.2.1+dfsg1-1",
            "binary_name": "ntopng"
        },
        {
            "binary_version": "5.2.1+dfsg1-1",
            "binary_name": "ntopng-data"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

odoo

Package

Name
odoo
Purl
pkg:deb/ubuntu/odoo@14.0.0+dfsg.3-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

14.*

14.0.0+dfsg.2-7
14.0.0+dfsg.3-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "14.0.0+dfsg.3-1",
            "binary_name": "odoo-14"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

omnidb

Package

Name
omnidb
Purl
pkg:deb/ubuntu/omnidb@3.0.3b+ds-3?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.3b+ds-2
3.0.3b+ds-2build1
3.0.3b+ds-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.3b+ds-3",
            "binary_name": "omnidb-common"
        },
        {
            "binary_version": "3.0.3b+ds-3",
            "binary_name": "omnidb-server"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ruby-momentjs-rails

Package

Name
ruby-momentjs-rails
Purl
pkg:deb/ubuntu/ruby-momentjs-rails@2.20.1-2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.20.1-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.20.1-2",
            "binary_name": "ruby-momentjs-rails"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

sabnzbdplus

Package

Name
sabnzbdplus
Purl
pkg:deb/ubuntu/sabnzbdplus@3.5.1+dfsg-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.2.1+dfsg-1
3.4.2+dfsg-1
3.4.2+dfsg-2
3.5.0+dfsg-1
3.5.0+dfsg-2
3.5.1+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.5.1+dfsg-1",
            "binary_name": "sabnzbdplus"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

wordpress

Package

Name
wordpress
Purl
pkg:deb/ubuntu/wordpress@5.8.3+dfsg1-1ubuntu1.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.7.1+dfsg1-2ubuntu1
5.8.1+dfsg1-2ubuntu1
5.8.2+dfsg1-1ubuntu1
5.8.3+dfsg1-1ubuntu1
5.8.3+dfsg1-1ubuntu1.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.8.3+dfsg1-1ubuntu1.1",
            "binary_name": "wordpress"
        },
        {
            "binary_version": "5.8.3+dfsg1-1ubuntu1.1",
            "binary_name": "wordpress-l10n"
        },
        {
            "binary_version": "5.8.3+dfsg1-1ubuntu1.1",
            "binary_name": "wordpress-theme-twentynineteen"
        },
        {
            "binary_version": "5.8.3+dfsg1-1ubuntu1.1",
            "binary_name": "wordpress-theme-twentytwenty"
        },
        {
            "binary_version": "5.8.3+dfsg1-1ubuntu1.1",
            "binary_name": "wordpress-theme-twentytwentyone"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:24.04:LTS

gnucash

Package

Name
gnucash
Purl
pkg:deb/ubuntu/gnucash@1:5.5-1.2build1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:5.*

1:5.3-1
1:5.4-2
1:5.4-2build1
1:5.5-1
1:5.5-1ubuntu1
1:5.5-1.1
1:5.5-1.2
1:5.5-1.2build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:5.5-1.2build1",
            "binary_name": "gnucash"
        },
        {
            "binary_version": "1:5.5-1.2build1",
            "binary_name": "gnucash-common"
        },
        {
            "binary_version": "1:5.5-1.2build1",
            "binary_name": "python3-gnucash"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

mediawiki

Package

Name
mediawiki
Purl
pkg:deb/ubuntu/mediawiki@1:1.39.7-1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.39.4-2
1:1.39.5-1
1:1.39.6-1
1:1.39.7-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:1.39.7-1",
            "binary_name": "mediawiki"
        },
        {
            "binary_version": "1:1.39.7-1",
            "binary_name": "mediawiki-classes"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ntopng

Package

Name
ntopng
Purl
pkg:deb/ubuntu/ntopng@5.2.1+dfsg1-1ubuntu4?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.2.1+dfsg1-1
5.2.1+dfsg1-1ubuntu1
5.2.1+dfsg1-1ubuntu3
5.2.1+dfsg1-1ubuntu4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.2.1+dfsg1-1ubuntu4",
            "binary_name": "ntopng"
        },
        {
            "binary_version": "5.2.1+dfsg1-1ubuntu4",
            "binary_name": "ntopng-data"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

odoo

Package

Name
odoo
Purl
pkg:deb/ubuntu/odoo@16.0.0+dfsg.2-2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

16.*

16.0.0+dfsg.1-3
16.0.0+dfsg.2-1.1
16.0.0+dfsg.2-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "16.0.0+dfsg.2-2",
            "binary_name": "odoo-16"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

omnidb

Package

Name
omnidb
Purl
pkg:deb/ubuntu/omnidb@3.0.3b+ds-4?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.3b+ds-4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.3b+ds-4",
            "binary_name": "omnidb-common"
        },
        {
            "binary_version": "3.0.3b+ds-4",
            "binary_name": "omnidb-server"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

postfixadmin

Package

Name
postfixadmin
Purl
pkg:deb/ubuntu/postfixadmin@3.3.13-1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.13-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.3.13-1",
            "binary_name": "postfixadmin"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ruby-momentjs-rails

Package

Name
ruby-momentjs-rails
Purl
pkg:deb/ubuntu/ruby-momentjs-rails@2.20.1-2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.20.1-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.20.1-2",
            "binary_name": "ruby-momentjs-rails"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

sabnzbdplus

Package

Name
sabnzbdplus
Purl
pkg:deb/ubuntu/sabnzbdplus@4.2.2+dfsg-3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.0.2+dfsg-1
4.1.0+dfsg-1
4.2.2+dfsg-2
4.2.2+dfsg-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.2.2+dfsg-3",
            "binary_name": "sabnzbdplus"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

wordpress

Package

Name
wordpress
Purl
pkg:deb/ubuntu/wordpress@6.4.3+dfsg1-1ubuntu1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.2+dfsg1-1ubuntu1
6.4.3+dfsg1-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.4.3+dfsg1-1ubuntu1",
            "binary_name": "wordpress"
        },
        {
            "binary_version": "6.4.3+dfsg1-1ubuntu1",
            "binary_name": "wordpress-l10n"
        },
        {
            "binary_version": "6.4.3+dfsg1-1ubuntu1",
            "binary_name": "wordpress-theme-twentytwentyfour"
        },
        {
            "binary_version": "6.4.3+dfsg1-1ubuntu1",
            "binary_name": "wordpress-theme-twentytwentythree"
        },
        {
            "binary_version": "6.4.3+dfsg1-1ubuntu1",
            "binary_name": "wordpress-theme-twentytwentytwo"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:25.04

gnucash

Package

Name
gnucash
Purl
pkg:deb/ubuntu/gnucash@1:5.10-0.1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:5.*

1:5.8-1build1
1:5.10-0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:5.10-0.1",
            "binary_name": "gnucash"
        },
        {
            "binary_version": "1:5.10-0.1",
            "binary_name": "gnucash-common"
        },
        {
            "binary_version": "1:5.10-0.1",
            "binary_name": "python3-gnucash"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

mediawiki

Package

Name
mediawiki
Purl
pkg:deb/ubuntu/mediawiki@1:1.43.1+dfsg-1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.39.10-1
1:1.43.0-0maysync3
1:1.43.0+dfsg-2
1:1.43.1+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:1.43.1+dfsg-1",
            "binary_name": "mediawiki"
        },
        {
            "binary_version": "1:1.43.1+dfsg-1",
            "binary_name": "mediawiki-classes"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ntopng

Package

Name
ntopng
Purl
pkg:deb/ubuntu/ntopng@5.2.1+dfsg1-2ubuntu1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.2.1+dfsg1-2
5.2.1+dfsg1-2ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.2.1+dfsg1-2ubuntu1",
            "binary_name": "ntopng"
        },
        {
            "binary_version": "5.2.1+dfsg1-2ubuntu1",
            "binary_name": "ntopng-data"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

odoo

Package

Name
odoo
Purl
pkg:deb/ubuntu/odoo@18.0.0+dfsg-2?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

16.*

16.0.0+dfsg.2-3

17.*

17.0.0+dfsg3-1

18.*

18.0.0+dfsg-1.1
18.0.0+dfsg-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "18.0.0+dfsg-2",
            "binary_name": "odoo-18"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

omnidb

Package

Name
omnidb
Purl
pkg:deb/ubuntu/omnidb@3.0.3b+ds-6build1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.3b+ds-6
3.0.3b+ds-6build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.3b+ds-6build1",
            "binary_name": "omnidb-common"
        },
        {
            "binary_version": "3.0.3b+ds-6build1",
            "binary_name": "omnidb-server"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

postfixadmin

Package

Name
postfixadmin
Purl
pkg:deb/ubuntu/postfixadmin@3.3.15+ds-2?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.13-1
3.3.14+ds1-1
3.3.15+ds-1
3.3.15+ds-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.3.15+ds-2",
            "binary_name": "postfixadmin"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ruby-momentjs-rails

Package

Name
ruby-momentjs-rails
Purl
pkg:deb/ubuntu/ruby-momentjs-rails@2.20.1-2?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.20.1-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.20.1-2",
            "binary_name": "ruby-momentjs-rails"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

sabnzbdplus

Package

Name
sabnzbdplus
Purl
pkg:deb/ubuntu/sabnzbdplus@4.4.1+dfsg-2?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.3.2+dfsg-1
4.3.3+dfsg-1
4.4.0+dfsg-1
4.4.1+dfsg-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.4.1+dfsg-2",
            "binary_name": "sabnzbdplus"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

syncthing

Package

Name
syncthing
Purl
pkg:deb/ubuntu/syncthing@1.29.2~ds1-1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.27.7~ds1-1
1.27.7~ds1-5
1.29.2~ds1-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.29.2~ds1-1",
            "binary_name": "golang-github-syncthing-syncthing-dev"
        },
        {
            "binary_version": "1.29.2~ds1-1",
            "binary_name": "syncthing"
        },
        {
            "binary_version": "1.29.2~ds1-1",
            "binary_name": "syncthing-discosrv"
        },
        {
            "binary_version": "1.29.2~ds1-1",
            "binary_name": "syncthing-relaysrv"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

wordpress

Package

Name
wordpress
Purl
pkg:deb/ubuntu/wordpress@6.7.2+dfsg1-1.1ubuntu1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.4.3+dfsg1-1ubuntu1
6.7.2+dfsg1-1.1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress"
        },
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress-l10n"
        },
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress-theme-twentytwentyfive"
        },
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress-theme-twentytwentyfour"
        },
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress-theme-twentytwentythree"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:25.10

gnucash

Package

Name
gnucash
Purl
pkg:deb/ubuntu/gnucash@1:5.13-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:5.*

1:5.10-0.1
1:5.10-0.1build1
1:5.13-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:5.13-1",
            "binary_name": "gnucash"
        },
        {
            "binary_version": "1:5.13-1",
            "binary_name": "gnucash-common"
        },
        {
            "binary_version": "1:5.13-1",
            "binary_name": "python3-gnucash"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

mediawiki

Package

Name
mediawiki
Purl
pkg:deb/ubuntu/mediawiki@1:1.43.3+dfsg-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.43.1+dfsg-1
1:1.43.1+dfsg-2
1:1.43.3+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:1.43.3+dfsg-1",
            "binary_name": "mediawiki"
        },
        {
            "binary_version": "1:1.43.3+dfsg-1",
            "binary_name": "mediawiki-classes"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ntopng

Package

Name
ntopng
Purl
pkg:deb/ubuntu/ntopng@5.2.1+dfsg1-2ubuntu1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.2.1+dfsg1-2ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.2.1+dfsg1-2ubuntu1",
            "binary_name": "ntopng"
        },
        {
            "binary_version": "5.2.1+dfsg1-2ubuntu1",
            "binary_name": "ntopng-data"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

odoo

Package

Name
odoo
Purl
pkg:deb/ubuntu/odoo@18.0.0+dfsg-2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

18.*

18.0.0+dfsg-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "18.0.0+dfsg-2",
            "binary_name": "odoo-18"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

omnidb

Package

Name
omnidb
Purl
pkg:deb/ubuntu/omnidb@3.0.3b+ds-6build1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.3b+ds-6build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.3b+ds-6build1",
            "binary_name": "omnidb-common"
        },
        {
            "binary_version": "3.0.3b+ds-6build1",
            "binary_name": "omnidb-server"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

postfixadmin

Package

Name
postfixadmin
Purl
pkg:deb/ubuntu/postfixadmin@3.3.15+ds-2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.15+ds-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.3.15+ds-2",
            "binary_name": "postfixadmin"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

sabnzbdplus

Package

Name
sabnzbdplus
Purl
pkg:deb/ubuntu/sabnzbdplus@4.5.0+dfsg-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.4.1+dfsg-2
4.5.0+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.5.0+dfsg-1",
            "binary_name": "sabnzbdplus"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

syncthing

Package

Name
syncthing
Purl
pkg:deb/ubuntu/syncthing@1.29.5~ds1-2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.29.2~ds1-1
1.29.5~ds1-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.29.5~ds1-2",
            "binary_name": "golang-github-syncthing-syncthing-dev"
        },
        {
            "binary_version": "1.29.5~ds1-2",
            "binary_name": "syncthing"
        },
        {
            "binary_version": "1.29.5~ds1-2",
            "binary_name": "syncthing-discosrv"
        },
        {
            "binary_version": "1.29.5~ds1-2",
            "binary_name": "syncthing-relaysrv"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

wordpress

Package

Name
wordpress
Purl
pkg:deb/ubuntu/wordpress@6.7.2+dfsg1-1.1ubuntu1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.7.2+dfsg1-1.1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress"
        },
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress-l10n"
        },
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress-theme-twentytwentyfive"
        },
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress-theme-twentytwentyfour"
        },
        {
            "binary_version": "6.7.2+dfsg1-1.1ubuntu1",
            "binary_name": "wordpress-theme-twentytwentythree"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:Pro:16.04:LTS

node-moment

Package

Name
node-moment
Purl
pkg:deb/ubuntu/node-moment@2.11.0+ds-1ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.10.6+dfsg-1
2.11.0+ds-1
2.11.0+ds-1ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.11.0+ds-1ubuntu0.1~esm1",
            "binary_name": "libjs-moment"
        },
        {
            "binary_version": "2.11.0+ds-1ubuntu0.1~esm1",
            "binary_name": "node-moment"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

ntopng

Package

Name
ntopng
Purl
pkg:deb/ubuntu/ntopng@2.2+dfsg1-1ubuntu0.1~esm2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.1+dfsg1-2ubuntu1

2.*

2.0+dfsg1-1
2.2+dfsg1-1
2.2+dfsg1-1build1
2.2+dfsg1-1ubuntu0.1~esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.2+dfsg1-1ubuntu0.1~esm2",
            "binary_name": "ntopng"
        },
        {
            "binary_version": "2.2+dfsg1-1ubuntu0.1~esm2",
            "binary_name": "ntopng-data"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:Pro:18.04:LTS

ntopng

Package

Name
ntopng
Purl
pkg:deb/ubuntu/ntopng@3.2+dfsg1-1ubuntu0.1~esm2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.4+dfsg1-3
2.4+dfsg1-4

3.*

3.2+dfsg1-1
3.2+dfsg1-1ubuntu0.1~esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.2+dfsg1-1ubuntu0.1~esm2",
            "binary_name": "ntopng"
        },
        {
            "binary_version": "3.2+dfsg1-1ubuntu0.1~esm2",
            "binary_name": "ntopng-data"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:Pro:22.04:LTS

postfixadmin

Package

Name
postfixadmin
Purl
pkg:deb/ubuntu/postfixadmin@3.3.10-2ubuntu0.1~esm1?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.10-2ubuntu0.1~esm1

Affected versions

3.*

3.3.7-1
3.3.10-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.3.10-2ubuntu0.1~esm1",
            "binary_name": "postfixadmin"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

syncthing

Package

Name
syncthing
Purl
pkg:deb/ubuntu/syncthing@1.18.0~ds1-3ubuntu0.3+esm1?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.12.1~ds1-4
1.18.0~ds1-3
1.18.0~ds1-3ubuntu0.1
1.18.0~ds1-3ubuntu0.2
1.18.0~ds1-3ubuntu0.3
1.18.0~ds1-3ubuntu0.3+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.18.0~ds1-3ubuntu0.3+esm1",
            "binary_name": "golang-github-syncthing-syncthing-dev"
        },
        {
            "binary_version": "1.18.0~ds1-3ubuntu0.3+esm1",
            "binary_name": "syncthing"
        },
        {
            "binary_version": "1.18.0~ds1-3ubuntu0.3+esm1",
            "binary_name": "syncthing-discosrv"
        },
        {
            "binary_version": "1.18.0~ds1-3ubuntu0.3+esm1",
            "binary_name": "syncthing-relaysrv"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"

Ubuntu:Pro:24.04:LTS

syncthing

Package

Name
syncthing
Purl
pkg:deb/ubuntu/syncthing@1.27.2~ds4-1ubuntu0.24.04.3+esm1?arch=source&distro=esm-apps/noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.19.2~ds1-3
1.27.2~ds4-1
1.27.2~ds4-1ubuntu0.24.04.1
1.27.2~ds4-1ubuntu0.24.04.2
1.27.2~ds4-1ubuntu0.24.04.2+esm1
1.27.2~ds4-1ubuntu0.24.04.3
1.27.2~ds4-1ubuntu0.24.04.3+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.27.2~ds4-1ubuntu0.24.04.3+esm1",
            "binary_name": "golang-github-syncthing-syncthing-dev"
        },
        {
            "binary_version": "1.27.2~ds4-1ubuntu0.24.04.3+esm1",
            "binary_name": "syncthing"
        },
        {
            "binary_version": "1.27.2~ds4-1ubuntu0.24.04.3+esm1",
            "binary_name": "syncthing-discosrv"
        },
        {
            "binary_version": "1.27.2~ds4-1ubuntu0.24.04.3+esm1",
            "binary_name": "syncthing-relaysrv"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31129.json"