Ubuntu alert USN-7958-1 (angular.js)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-7958-1] AngularJS vulnerabilities | |
| Date: | Wed, 14 Jan 2026 11:41:01 +0000 | |
| Message-ID: | <E1vfzFF-0004d7-VF@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-7958-1 January 14, 2026 angular.js vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in AngularJS. Software Description: - angular.js: JavaScript-based web framework Details: It was discovered that AngularJS did not properly sanitize certain `xlink:href` attributes. A remote attacker could possibly use this issue to perform cross site scripting. This issue only affected Ubuntu 16.04 LTS. (CVE-2019-14863) It was discovered that AngularJS incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause AngularJS to consume resources, leading to a regular expression denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.04. (CVE-2022-25844) It was discovered that AngularJS incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause AngularJS to consume resources, leading to a regular expression denial of service. (CVE-2023-26116, CVE-2023-26117) It was discovered that AngularJS incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause AngularJS to consume resources, leading to a regular expression denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.04. (CVE-2023-26118, CVE-2024-21490) It was discovered that AngularJS did not properly sanitize certain inputs in HTML elements. A remote attacker could possibly use this issue to perform spoofing and obtain sensitive information. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.04. (CVE-2024-8372, CVE-2024-8373, CVE-2025-2336) It was discovered that AngularJS did not properly sanitize certain inputs in HTML elements. A remote attacker could possibly use this issue to perform spoofing and obtain sensitive information. (CVE-2025-0716) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libjs-angularjs 1.8.3-1ubuntu0.25.04.1 Ubuntu 24.04 LTS libjs-angularjs 1.8.3-1ubuntu0.24.04.1 Ubuntu 22.04 LTS libjs-angularjs 1.8.2-2ubuntu0.1 Ubuntu 20.04 LTS libjs-angularjs 1.7.9-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libjs-angularjs 1.5.10-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libjs-angularjs 1.2.28-1ubuntu2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7958-1 CVE-2019-14863, CVE-2022-25844, CVE-2023-26116, CVE-2023-26117, CVE-2023-26118, CVE-2024-21490, CVE-2024-8372, CVE-2024-8373, CVE-2025-0716, CVE-2025-2336 Package Information: https://launchpad.net/ubuntu/+source/angular.js/1.8.3-1ub... https://launchpad.net/ubuntu/+source/angular.js/1.8.3-1ub... https://launchpad.net/ubuntu/+source/angular.js/1.8.2-2ub...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmlngLEACgkQcpJm3tlz hgHyHRAA1aP/T+IhNcdI1c1z+KgSyqEZqsgpbgUNOHds7xnlkn8xIdfj1fn0fA0f jocg4SnJDNqyqnlaYhC0kjYA9AagUwQWzzJ//bvBXqIO1hAZqlbEsOoVIG2IaPbg 8ZR3fYh8PCzrAFl2I3cLvMd2kjceC11SmnmFwib20F95rqxeFH8ys4c05U5tLSnD aZA4Rw0A0il6Cvs2mgGdbUjpGQA/33VZ9r3p0N+S+QHQOAgCd1j0KgKbrpnRqN/e LzgvL33JswZSFn5bBIT9SQ3/zLaPBhRq2q3JJm0h0wYzQaFgV0So0nT2Zp16AC01 WphiKaprA30ckw/H1MsA59z8I6HvhERJQ3UM00Agm2UHvMEYP5ku7PZNXhAJo9eV 7hL2QtrQm27GTvwjJm34AIlRMYJ6avCWpgv5ws7xAyoZyoq9OcBeO/MrgjpbPuL0 cLwtE+utCHh5gPbUFiZ60oYv2Pdcn1dEb6PEicfg6PpCS7ZUReWUdUaBpU5LqhI+ YXhW04SfL1wP1kWMreNH28aRqAP/ZiYM3xAO68e0KgMQI35n+RLhO6wsesNasTxv WMZXo7mOTgFwCw5HNEQ8kCfOpLA9Y5fxx3UcjSj9waWq/DNAZ6v985Xfp56V51nL uxUxJKaMZ0o7YX74YM5vw/od42XQlLmZSp2HCZqBxM7AxHF0zAo= =5XfA -----END PGP SIGNATURE-----
