{"id":"USN-4170-3","summary":"whoopsie regression","details":"USN-4170-1 fixed a vulnerability in Whoopsie and USN-4170-2 fixed a\nsubsequent regression. That update was incomplete and could still result in\nWhoopsie potentially crashing when uploading crash reports on some\narchitectures.  This update fixes the problem.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n Kevin Backhouse discovered Whoopsie incorrectly handled very large crash\n reports. A local attacker could possibly use this issue to cause a denial\n of service, expose sensitive information or execute code as the whoopsie\n user.\n","modified":"2026-04-22T10:01:39.917320Z","published":"2019-11-05T03:43:34Z","references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4170-3"},{"type":"REPORT","url":"https://launchpad.net/bugs/1850608"}],"affected":[{"package":{"name":"whoopsie","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/whoopsie@0.2.52.5ubuntu0.4?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.52.5ubuntu0.4"}]}],"versions":["0.2.49","0.2.50","0.2.51","0.2.52","0.2.52.1","0.2.52.2","0.2.52.3","0.2.52.4","0.2.52.5","0.2.52.5ubuntu0.1","0.2.52.5ubuntu0.2","0.2.52.5ubuntu0.3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"0.2.52.5ubuntu0.4","binary_name":"libwhoopsie0"},{"binary_name":"whoopsie","binary_version":"0.2.52.5ubuntu0.4"}]},"database_specific":{"cves_map":{"cves":[],"ecosystem":"Ubuntu:16.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4170-3.json"}},{"package":{"name":"whoopsie","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/whoopsie@0.2.62ubuntu0.4?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.62ubuntu0.4"}]}],"versions":["0.2.58","0.2.59","0.2.59build1","0.2.60","0.2.62","0.2.62ubuntu0.1","0.2.62ubuntu0.2","0.2.62ubuntu0.3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libwhoopsie0","binary_version":"0.2.62ubuntu0.4"},{"binary_name":"whoopsie","binary_version":"0.2.62ubuntu0.4"}]},"database_specific":{"cves_map":{"cves":[],"ecosystem":"Ubuntu:18.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4170-3.json"}}],"schema_version":"1.7.5"}