/[secure-testing]/data/DSA/list
ViewVC logotype

Contents of /data/DSA/list

Parent Directory Parent Directory | Revision Log Revision Log


Revision 934 - (hide annotations) (download)
Thu Apr 28 14:43:34 2005 UTC (8 years ago) by joeyh
Original Path: sarge-checks/DSA/list
File size: 68873 byte(s)
new DSAs
1 joeyh 934 [28 Apr 2005] DSA-719-1 prozilla - format string problems
2     {CAN-2005-0523}
3     - prozilla 1:1.3.7.4-1
4     NOTE: fixed in testing in time of DSA
5     [28 Apr 2005] DSA-718-1 ethereal - buffer overflow
6     {CAN-2005-0739}
7     - ethereal 0.10.10-1
8     NOTE: fixed in testing in time of DSA
9 dom-guest 930 [27 Apr 2005] DSA-717-1 lsh-utils - buffer overflow, typo
10     {CAN-2003-0826 CAN-2005-0814}
11     - lsh-utils 2.0.1-2
12     NOTE: fixed in testing in time of DSA
13 jmm-guest 929 [27 Apr 2005] DSA-716-1 gaim - denial of service
14     {CAN-2005-0472}
15     - gaim 1.1.3-1
16     NOTE: fixed in testing in time of DSA
17 jmm-guest 924 [27 Apr 2005] DSA-715-1 cvs - several
18     {CAN-2004-1342 CAN-2004-1343}
19 dom-guest 931 - cvs 1.12.9-12
20     NOTE: not fixed in testing in time of DSA
21 dom-guest 920 [26 Apr 2005] DSA-714-1 kdelibs - several
22     {CAN-2005-1046}
23     - kdelibs 4:3.3.2-5
24     NOTE: not fixed in testing at time of DSA
25 joeyh 886 [21 Apr 2005] DSA-701-2 samba - integer overflows
26     NOTE: only a bug in the backported fix to stable, testing is ok
27 dom-guest 881 [21 Apr 2005] DSA-713-1 junkbuster - several
28     {CAN-2005-1108 CAN-2005-1109}
29     NOTE: package not in testing/unstable
30 dom-guest 862 [19 Apr 2005] DSA-712-1 geneweb - insecure file operations
31     {CAN-2005-0391}
32     - geneweb 4.10-7
33 joeyh 865 NOTE: fixed in testing at time of DSA
34 dom-guest 857 [19 Apr 2005] DSA-711-1 info2www - missing input sanitising
35     {CAN-2004-1341}
36     - info2www 1.2.2.9-23
37 jmm-guest 858 NOTE: fixed in testing in time of DSA
38 joeyh 848 [18 Apr 2005] DSA-710-1 gtkhtml - null pointer dereference
39     {CAN-2003-0541}
40     - gtkhtml 1.0.4-6.2
41     NOTE: fixed in testing at time of DSA
42 jmm-guest 834 [15 Apr 2005] DSA-709-1 libexif - buffer overflow
43     {CAN-2005-0664}
44     - libexif 0.6.9-5
45 dom-guest 828 [15 Apr 2005] DSA-708-1 php3 - missing input sanitising
46 dom-guest 829 {CAN-2005-0525}
47     - php3 3.0.18-31
48 dom-guest 797 [13 Apr 2005] DSA-707-1 mysql - several
49     {CAN-2004-0957 CAN-2005-0709 CAN-2005-0710 CAN-2005-0711}
50     - mysql-dfsg 4.0.24-5
51     - mysql-dfsg-4.1 4.1.10a-6
52     NOTE: not fixed in testing at time of DSA
53 dom-guest 796 [13 Apr 2005] DSA-706-1 axel - buffer overflow
54     {CAN-2005-0390}
55     - axel 1.0b-1
56 jmm-guest 858 NOTE: fixed in testing in time of DSA
57 dom-guest 742 [04 Apr 2005] DSA-705-1 wu-ftpd - missing input sanitising
58     {CAN-2005-0256 CAN-2003-0854}
59     - wu-ftpd 2.6.2-19
60 dom-guest 741 [04 Apr 2005] DSA-704-1 remstats - tempfile, missing input sanitising
61     {CAN-2005-0387 CAN-2005-0388}
62     - remstats 1.0.13a-5
63     NOTE: not fixed in testing at time of DSA
64 dom-guest 718 [01 Apr 2005] DSA-703-1 krb5 - buffer overflows
65     {CAN-2005-0468 CAN-2005-0469}
66     - krb5 1.3.6-1
67 dom-guest 715 [01 Apr 2005] DSA-702-1 imagemagick - several
68     {CAN-2005-0397 CAN-2005-0759 CAN-2005-0760 CAN-2005-0762}
69     - imagemagick 6.0.6.2-2.2
70 dom-guest 702 [31 Mar 2005] DSA-701-1 samba - integer overflows
71     {CAN-2004-1154}
72     - samba 3.0.10-1
73 dom-guest 686 [30 Mar 2005] DSA-700-1 mailreader - missing input sanitising
74     {CAN-2005-0386}
75     - mailreader 2.3.29-11
76     NOTE: not fixed in testing at time of DSA
77 joeyh 683 [29 Mar 2005] DSA-699-1 netkit-telnet-ssl - buffer overflow
78 dom-guest 679 {CAN-2005-0469}
79 joeyh 708 - netkit-telnet-ssl 0.17.24+0.1-7.1
80 joeyh 680 NOTE: not fixed in testing at time of DSA
81 dom-guest 678 [29 Mar 2005] DSA-698-1 mc - buffer overflow
82     {CAN-2005-0763}
83 joeyh 680 NOTE: Not clear which unstable/testing version fixed this,
84     NOTE: but advisory says it's fixed.
85 dom-guest 678 [29 Mar 2005] DSA-697-1 netkit-telnet - buffer overflow
86     {CAN-2005-0469}
87     - netkit-telnet 0.17-28
88 joeyh 680 NOTE: not fixed in testing at time of DSA
89 dom-guest 614 [22 Mar 2005] DSA-696-1 perl - design flaw
90     {CAN-2005-0448}
91     - perl 5.8.4-8
92 joeyh 680 NOTE: fixed in testing at time of DSA
93 joeyh 599 [21 Mar 2005] DSA-695-1 xli - buffer overflow, input sanitising, integer overflow
94     {CAN-2001-0775 CAN-2005-0638 CAN-2005-0639}
95     - xli 1.17.0-18
96     NOTE: not fixed in testing at time of DSA
97     [21 Mar 2005] DSA-694-1 xloadimage - missing input sanitising, integer overflow
98     {CAN-2005-0638 CAN-2005-0639}
99     - xloadimage 4.1-14.2
100     NOTE: not fixed in testing at time of DSA
101 joeyh 554 [14 Mar 2005] DSA-693-1 luxman - buffer overflow
102     {CAN-2005-0385}
103 joeyh 599 NOTE: not fixed in testing at time of DSA
104 joeyh 586 NOTE: not in unstable at time of DSA though DSA claimed it was
105 jmm-guest 583 - luxman 0.41-20
106 joeyh 554 [14 Mar 2005] DSA-662-2 squirrelmail - several
107     NOTE: only an update to a prior DSA, did not affct sid/sarge.
108 joeyh 531 [08 Mar 2005] DSA-692-1 kppp - design flaw
109     {CAN-2005-0205}
110     - kppp 4:3.1.6
111     NOTE: fixed in testing at time of DSA
112 joeyh 529 [07 Mar 2005] DSA-691-1 abuse - several
113     {CAN-2005-0098 CAN-2005-0099}
114     NOTE: not in unstable/testing
115 joeyh 490 [25 Feb 2005] DSA-690-1 bsmtpd - missing input sanitising
116     {CAN-2005-0107}
117     - bsmtpd 2.3pl8b-16
118     NOTE: not fixed in testing at time of DSA
119     [23 Feb 2005] DSA-689-1 libapache-mod-python - missing input sanitising
120 joeyh 472 {CAN-2005-0088}
121     - libapache-mod-python 2.7.10-4
122     NOTE: fixed in testing at time of DSA
123     - libapache2-mod-python 3.1.3-3
124     NOTE: fixed in testing at time of DSA
125     [23 Feb 2005] DSA-688-1 squid - mising input sanitising
126     {CAN-2005-0446}
127     - squid 2.5.8-3
128     NOTE: fixed in testing at time of DSA
129 joeyh 460 [21 Feb 2005] DSA-674-3 mailman - cross-site scripting, directory traversal
130     NOTE: only fixed bug in DSA
131 joeyh 444 [18 Feb 2005] DSA-687-1 bidwatcher - format string
132     {CAN-2005-0158}
133 joeyh 452 - bidwatcher 1.3.17-1
134 joeyh 444 NOTE: not fixed in testing at time of DSA
135 joeyh 425 [17 Feb 2005] DSA-686-1 gftp - missing input sanitising
136     {CAN-2005-0372}
137     - gftp 2.0.18-1
138     NOTE: not fixed in testing at time of DSA
139     [17 Feb 2005] DSA-685-1 emacs21 - format string
140     {CAN-2005-0100}
141     - emacs21 21.3+1-9
142     NOTE: not fixed in testing at time of DSA
143 joeyh 416 [16 Feb 2005] DSA-684-1 typespeed - format string
144     {CAN-2005-0105}
145 joeyh 420 - typespeed 0.4.4-8
146 joeyh 416 NOTE: not fixed in testing at time of DSA
147 joeyh 411 [15 Feb 2005] DSA-683-1 postgresql - buffer overflows
148     {CAN-2005-0245 CAN-2005-0247}
149     - postgresql 7.4.7-2
150     NOTE: fixed in testing at time of DSA
151     [15 Feb 2005] DSA-682-1 awstats - missing input sanitising
152     {CAN-2005-0363}
153     - awstats 6.2-1.2
154     NOTE: not fixed in testing at time of DSA
155 joeyh 406 [14 Feb 2005] DSA-681-1 synaesthesia - privilege escalation
156     {CAN-2005-0070}
157     NOTE: does not apply for sarge, program is not setuid anymore
158 joeyh 404 [14 Feb 2005] DSA-680-1 htdig - unsanitised input
159     {CAN-2005-0085}
160     - htdig 3.1.6-11
161     NOTE: fixed in testing at time of DSA
162     [14 Feb 2005] DSA-679-1 toolchain-source - insecure temporary files
163     {CAN-2005-0159}
164     - toolchain-source 3.4-5
165     NOTE: not fixed in testing at time of DSA
166 joeyh 394 [11 Feb 2005] DSA-678-1 netkit-rwho - missing input validation
167     {CAN-2004-1180}
168     - netkit-rwho 0.17-8
169     NOTE: not fixed in testing at time of DSA
170     [11 Feb 2005] DSA-677-1 sympa - buffer overflow
171     {CAN-2005-0073}
172 joeyh 402 - sympa 4.1.2-2.1
173 joeyh 394 NOTE: not fixed in testing at time of DSA
174     [11 Feb 2005] DSA-676-1 xpcd - buffer overflow
175     {CAN-2005-0074}
176 joeyh 402 - xpcd 2.08-11.1
177 joeyh 394 NOTE: not fixed in testing at time of DSA
178     [11 Feb 2005] DSA-674-2 mailman - cross-site scripting, directory traversal
179     NOTE: only fixed bug in DSA
180 joeyh 389 [10 Feb 2005] DSA-675-1 hztty - privilege escalation
181     {CAN-2005-0019}
182     - hztty 2.0-6.1
183     NOTE: not fixed in testing at time of DSA
184 joeyh 388 [10 Feb 2005] DSA-674-1 mailman - cross-site scripting, directory traversal
185     {CAN-2004-1177}
186     - mailman 2.1.5-5
187     NOTE: fixed in testing at time of DSA
188     {CAN-2005-0202}
189     - mailman 2.1.5-6
190     NOTE: not fixed in testing at time of DSA
191     [10 Feb 2005] DSA-673-1 evolution - integer overflow
192     {CAN-2005-0102}
193     - evolution 2.0.3-1.2
194     NOTE: fixed in testing at time of DSA
195 joeyh 379 [09 Feb 2005] DSA-672-1 xview - buffer overflows
196     {CAN-2005-0076}
197     - xview 3.2p1.4-19
198 joeyh 388 NOTE: not fixed in testing at time of DSA
199 joeyh 369 [08 Feb 2005] DSA-671-1 xemacs21 - format string
200     {CAN-2005-0100}
201     NOTE: not fixed in testing at time of DSA
202     - xemacs21 21.4.16-2
203     [08 Feb 2005] DSA-670-1 emacs20 - format string
204     {CAN-2005-0100}
205     NOTE: also affects emacs21 in unstable, fixed
206 joeyh 361 [04 Feb 2005] DSA-689-1 php3 - several
207     {CAN-2004-0594 CAN-2004-0595}
208     - php3 3.0.18-27
209     NOTE: fixed in testing at time of DSA
210 joeyh 356 [04 Feb 2005] DSA-668-1 postgresql - privilege escalation
211     {CAN-2005-0227}
212 joeyh 340 - postgresql 7.4.7-1
213     NOTE: not fixed in testing at time of DSA
214     [04 Feb 2005] DSA-667-1 squid - several
215     {CAN-2005-0173 CAN-2005-0175 CAN-2005-0194 CAN-2005-0211}
216     - squid 2.5.7-7
217     NOTE: not fixed in testing at time of DSA
218     [04 Feb 2005] DSA-666-1 python2.2 - design flaw
219     {CAN-2005-0089}
220     - python2.2 2.2.3-14
221     - python2.3 2.3.4-20
222     - python2.4 2.4-5
223     NOTE: not fixed in testing at time of DSA
224     [04 Feb 2005] DSA-665-1 ncpfs - missing privilege release
225     {CAN-2005-0013}
226 joeyh 385 - ncpfs 2.2.6-1
227 joeyh 340 NOTE: not fixed in testing at time of DSA
228 joeyh 338 [02 Feb 2005] DSA-664-1 cpio - broken file permissions
229 joeyh 334 {CAN-1999-1572}
230 joeyh 345 - cpio 2.5-1.2
231 joeyh 334 NOTE: not fixed in testing at time of DSA
232 joeyh 332 [02 Feb 2005] DSA-663-1 prozilla - buffer overflows
233     {CAN-2004-1120}
234     - prozilla 1.3.7.3-1
235     NOTE: fixed in testing at time of DSA
236     [01 Feb 2005] DSA-662-1 squirrelmail - several
237     {CAN-2005-0104 CAN-2005-0152}
238     NOTE: CAN-2005-0152 only exists in 1.2.6 version
239 joeyh 338 - squirrelmail 1.4.4
240     NOTE: fixed in testing at time of DSA
241 jmm-guest 872 [20 Apr 2005] DSA-661-2 f2c - insecure temporary files
242 joeyh 323 {CAN-2005-0017 CAN-2005-0018}
243 jmm-guest 913 - f2c 20020621-3.3
244 joeyh 323 NOTE: not fixed in testing at time of DSA
245     [26 Jan 2005] DSA-660-1 kdebase - missing return value check
246 joeyh 319 {CAN-2005-0078}
247     - kdebase 4:3.0.5
248     NOTE: fixed in testing at time of DSA
249     [26 Jan 2005] DSA-659-1 libpam-radius-auth - information leak, integer underflow
250     {CAN-2004-1340 CAN-2005-0108}
251     - libpam-radius-auth 1.3.16-3
252     NOTE: 1/2 fixed in testing at time of DSA
253 joeyh 316 [25 Jan 2005] DSA-658-1 libdbi-perl - insecure temporary file
254     {CAN-2005-0077}
255     - libdbi-perl 1.46-6
256     NOTE: not fixed in testing at time of DSA
257     [25 Jan 2005] DSA-657-1 xine-lib - buffer overflow
258     {CAN-2004-1379}
259     - xine-lib 1-rc6a-1
260     NOTE: fixed in testing at time of DSA
261     [25 Jan 2005] DSA-656-1 vdr - insecure file access
262     {CAN-2005-0071}
263     - vdr 1.2.6-6
264     NOTE: not fixed in testing at time of DSA
265     [25 Jan 2005] DSA-655-1 zhcon - missing privilege release
266     {CAN-2005-0072}
267 joeyh 321 - zhcon 1:0.2.3-8.1
268 joeyh 316 NOTE: not fixed in testing at time of DSA
269 joeyh 304 [21 Jan 2005] DSA-654-1 enscript - several
270     {CAN-2004-1184 CAN-2004-1185 CAN-2004-1186}
271     - enscript 1.6.4-6
272     NOTE: not fixed in testing at time of DSA
273     [21 Jan 2005] DSA-653-1 ethereal - buffer overflow
274     {CAN-2005-0084}
275     - ethereal 0.10.9-1
276     NOTE: not fixed in testing at time of DSA
277     [21 Jan 2005] DSA-652-1 unarj
278     {CAN-2004-0947 CAN-2004-1027}
279     NOTE: not-for-us (unarj)
280 joeyh 299 [20 Jan 2005] DSA-651-1 squid - buffer overflow, integer overflow
281     {CAN-2005-0094 CAN-2005-0095}
282     - squid 2.5.7-4
283     NOTE: not fixed in testing at time of DSA
284     [20 Jan 2005] DSA-650-1 sword - missing input sanitising
285     {CAN-2005-0015}
286 joeyh 303 - sword 1.5.7-7
287 joeyh 299 NOTE: not fixed in testing at time of DSA
288     [20 Jan 2005] DSA-649-1 xtrlock - buffer overflow
289     {CAN-2005-0079}
290     - xtrlock 2.0-9
291     NOTE: fixed in testing at time of DSA
292 joeyh 291 [19 Jan 2005] DSA-648-1 xpdf - buffer overflow
293     {CAN-2005-0064}
294     - xpdf 3.00-12
295     NOTE: not fixed in testing at time of DSA
296     [19 Jan 2005] DSA-647-1 mysql - insecure temporary files
297     {CAN-2005-0004}
298     - mysql-dfsg 4.0.23-3
299     - mysql-dfsg-4.1 4.1.8a-6
300     NOTE: not fixed in testing at time of DSA
301     [19 Jan 2005] DSA-646-1 imagemagick - buffer overflow
302     {CAN-2005-0005}
303     - imagemagick 6.0.6.2-2
304     NOTE: not fixed in testing at time of DSA
305     [19 Jan 2005] DSA-645-1 cupsys - buffer overflow
306     {CAN-2005-0064}
307     NOTE: cupsys not affected in sarge, though other programs are vulnerable
308     NOTE: see CAN/list
309     NOTE: not fixed in testing at time of DSA
310 joeyh 283 [18 Jan 2005] DSA-644-1 chbg - buffer overflow
311     {CAN-2004-1264}
312     - chbg 1.5-4
313     NOTE: fixed in testing at time of DSA
314     [18 Jan 2005] DSA-643-1 queue - buffer overflows
315     {CAN-2004-0555}
316     - queue 1.30.1-5
317     NOTE: not fixed in testing at time of DSA
318     [17 Jan 2005] DSA-642-1 gallery - several
319 joeyh 279 {CAN-2004-1106}
320     - gallery 1.4.4-pl4-1
321     NOTE: fixed in testing at time of DSA
322     [17 Jan 2005] DSA-641-1 playmidi - buffer overflow
323     {CAN-2005-0020}
324     - playmidi 2.4debian-3
325     NOTE: not fixed in testing at time of DSA
326     [17 Jan 2005] DSA-640-1 gatos - buffer overflow
327     {CAN-2005-0016}
328     - gatos 0.0.5-15
329     NOTE: not fixed in testing at time of DSA
330     [14 Jan 2005] DSA-639-1 mc - several
331 joeyh 275 {CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176}
332 joeyh 406 NOTE: unstable not vulnerable according to DSA
333     NOTE: DSA was wrong..
334 joeyh 504 - mc 1:4.6.0-4.6.1-pre3-1
335 joeyh 406 NOTE: not fixed in testing at time of DSA
336 joeyh 274 [13 Jan 2005] DSA-638-1 gopher - several
337     {CAN-2004-0560 CAN-2004-0561}
338     NOTE: not in sarge
339 joeyh 271 [13 Jan 2005] DSA-637-1 exim-tls - buffer overflow
340     {CAN-2005-0021}
341     NOTE: not in sarge
342 joeyh 267 [12 Jan 2005] DSA-636-1 glibc - insecure temporary files
343     {CAN-2004-0968}
344     - glibc 2.3.2.ds1-20
345     NOTE: fixed in testing at time of DSA
346     [12 Jan 2005] DSA-635-1 exim - buffer overflow
347     {CAN-2005-0021}
348     - exim4 4.34-10
349     NOTE: fixed in testing at time of DSA
350     - exim 3.36-13
351     NOTE: not fixed in testing at time of DSA
352 joeyh 262 [11 Jan 2005] DSA-634-1 hylafax - weak hostname and username validation
353     {CAN-2004-1182}
354     - hylafax 4.2.1-1
355     NOTE: fixed in testing at time of DSA
356     [11 Jan 2005] DSA-633-1 bmv - insecure temporary file
357     {CAN-2003-0014}
358     - bmv 1.2-17
359     NOTE: fixed in testing at time of DSA
360     [10 Jan 2005] DSA-632-1 linpopup - buffer overflow
361 joeyh 260 {CAN-2004-1282}
362     - linpopup 1.2.0-7
363     NOTE: fixed in testing at time of DSA
364 joeyh 262 [10 Jan 2005] DSA-631-1 kdelibs - unsanitised input
365 joeyh 260 {CAN-2004-1165}
366 joeyh 278 - kdelibs 4:3.3.2-1
367 joeyh 260 NOTE: not fixed in testing at time of DSA
368 joeyh 262 [10 Jan 2005] DSA-630-1 lintian - insecure temporary directory
369 joeyh 260 {CAN-2004-1000}
370     - lintian 1.23.6
371     NOTE: not fixed in testing at time of DSA
372 joeyh 262 [07 Jan 2005] DSA-629-1 krb5 - buffer overflow
373 joeyh 252 {CAN-2004-1189}
374     - krb5 1.3.6-1
375     NOTE: not fixed in testing at time of DSA
376 joeyh 262 [06 Jan 2005] DSA-628-1 imlib2 - integer overflows
377 joeyh 248 {CAN-2004-1026}
378     - imlib2 1.1.2-2.1
379     NOTE: not fixed in testing at time of DSA
380 joeyh 262 [06 Jan 2005] DSA-627-1 namazu2 - unsanitised input
381 joeyh 248 {CAN-2004-1318}
382     - namazu2 2.0.14-1
383     NOTE: not fixed in testing at time of DSA
384 joeyh 262 [06 Jan 2005] DSA-626-1 tiff - unsanitised input
385 joeyh 248 {CAN-2004-1183}
386     - libtiff4 3.6.1-5
387     NOTE: not fixed in testing at time of DSA
388 joeyh 262 [05 Jan 2005] DSA-625-1 pcal - buffer overflows
389 joeyh 248 {CAN-2004-1289}
390     - pcal 4.8.0-1
391     NOTE: not fixed in testing at time of DSA
392 joeyh 262 [05 Jan 2005] DSA-624-1 zip - buffer overflow
393 joeyh 236 {CAN-2004-1010}
394     - zip 2.30-8
395 joeyh 248 NOTE: fixed in testing at time of DSA
396 joeyh 262 [04 Jan 2005] DSA-623-1 nasm - buffer overflow
397 joeyh 229 {CAN-2004-1287}
398     - nasm 0.98.38-1.1
399 joeyh 262 [03 Jan 2005] DSA-622-1 htmlheadline - insecure temporary files
400 joeyh 229 {CAN-2004-1181}
401     NOTE: not in unstable
402 joeyh 221 [31 Dec 2004] DSA-621-1 cupsys - buffer overflow
403     {CAN-2004-1125}
404     - cupsys 1.1.22-2
405 joeyh 217 [30 Dec 2004] DSA-620-1 perl - insecure temporary files / directories
406     {CAN-2004-0452 CAN-2004-0976}
407     - perl 5.8.4-5
408     [30 Dev 2004] DSA-619-1 xpdf - buffer overflow
409     {CAN-2004-1125}
410     - xpdf 3.00-11
411     [24 Dec 2004] DSA-618-1 imlib - buffer overflows, integer overflows
412     {CAN-2004-1025 CAN-2004-1026}
413     - imlib 1.9.14-17.1
414     - imlib-png2 1.9.14-16.1
415     [24 Dec 2004] DSA-617-1 libtiff - insufficient input validation
416 joeyh 214 {CAN-2004-1308}
417     - libtiff4 3.6.1-4
418 joeyh 212 [23 Dec 2004] DSA-616-1 telnetd-ssl - format string
419     {CAN-2004-0998}
420     - telnetd-ssl 0.17.24+0.1-6
421 joeyh 206 [22 Dec 2004] DSA-615-1 debmake - insecure temporary file
422     {CAN-2004-1179}
423     - debmake 3.7.7
424     [21 Dec 2004] DSA-614-1 xzgv - integer overflows
425     {CAN-2004-0994}
426     - xzgv 0.8-3
427     [21 Dec 2004] DSA-613-1 ethereal - inifinite loop
428     {CAN-2004-114}
429     - ethereal 0.10.8-1
430     [21 Dec 2004] DSA-614-1 xzgv - integer overflows
431     {CAN-2004-0994}
432 joeyh 220 - xzgv 0.8-3
433 joeyh 203 [20 Dec 2004] DSA-612-1 a2ps - unsanitised input
434     {CAN-2004-1170}
435     - a2ps 4.13b-4.2
436     [20 Dec 2004] DSA-611-1 htget - buffer overflow
437     {CAN-2004-0852}
438     NOTE: htget not in sarge or unstable
439     [17 Dec 2004] DSA-610-1 cscope - insecure temporary file
440 joeyh 201 {CAN-2004-0996}
441     - cscope 15.5-1
442     [14 Dec 2004] DSA-609-1 atari800 - buffer overflows
443 joeyh 197 {CAN-2004-1076}
444     - atari800 1.3.2-1
445     [14 Dec 2004] DSA-608-1 zgv - integer overflows, unsanitised input
446     {CAN-2004-1095 CAN-2004-0999}
447 joeyh 237 - zgv 5.7-1.3
448     NOTE: changelog says he only patched 1095, but diff comparison
449     NOTE: shows 0999 was also fixed.
450 joeyh 193 [10 Dec 2004] DSA-607-1 xfree86 - several
451     {CAN-2004-0914}
452     - xfree86 4.3.0.dfsg.1-9
453 joeyh 183 [08 Dec 2004] DSA-606-1 nfs-utils - wrong signal handler
454     {CAN-2004-1014}
455 joeyh 245 - nfs-utils 1:1.0.6-3.1
456 joeyh 180 [06 Dec 2004] DSA-605-1 viewcvs - settings not honored
457     {CAN-2004-0915}
458     - viewcvs 0.9.2+cvs.1.0.dev.2004.07.28-1.2
459 joeyh 158 [03 Dec 2004] DSA-604-1 hpsockd - missing input sanitising
460     {CAN-2004-0993}
461     - hpsockd 0.14
462 joeyh 156 [01 Dec 2004] DSA-603-1 openssl - insecure temporary file
463     {CAN-2004-0975}
464 joeyh 716 - openssl 0.9.7e-3
465 joeyh 156 [29 Nov 2004] DSA-602-1 libgd2 - integer overlow
466 joeyh 153 {CAN-2004-0941 CAN-2004-0990}
467     NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
468 joeyh 172 - libgd2 2.0.33-1.1
469 joeyh 156 [29 Nov 2004] DSA-601-1 libgd1 - integer overflow
470 joeyh 153 {CAN-2004-0941 CAN-2004-0990}
471     NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
472 joeyh 172 - libgd 1.8.4-36.1
473 joeyh 151 [25 Nov 2004] DSA-599-1 tetex-bin - integer overflows
474     {CAN-2004-0888}
475     - tetex-bin 2.0.2-23
476     [25 Nov 2004] DSA-598-1 yardradius - buffer overflow
477     {CAN-2004-0987}
478     - yardradius 1.0.20-15
479     [25 Nov 2004] DSA-597-1 cyrus-imapd - buffer overflow
480     {CAN-2004-1012 CAN-2004-1013}
481 joeyh 180 - cyrus21-imapd 2.1.17-1
482 joeyh 151 [24 Nov 2004] DSA-596-2 sudo - missing input sanitising
483     {CAN-2004-1051}
484     - sudo 1.6.8p3-1
485     [24 Nov 2004] DSA-596-1 sudo - missing input sanitising
486     {CAN-2004-1051}
487     - sudo 1.6.8p3-1
488     [24 Nov 2004] DSA-595-1 bnc - buffer overflow
489     {CAN-2004-1052}
490     NOTE: package not in sarge or sid
491 joeyh 127 [17 Nov 2004] DSA-594-1 apache - buffer overflows
492     {CAN-2004-0940}
493     - apache 1.3.33-2
494 joeyh 121 [16 Nov 2004] DSA-593-1 imagemagick - buffer overflow
495     {CAN-2004-0981}
496     - imagemagick 6:6.0.6.2-1.5
497 joeyh 113 [12 Nov 2004] DSA-592-1 ez-ipupdate - format string
498     {CAN-2004-0980}
499 joeyh 116 - ez-ipupdate 3.0.11b8-8
500 joeyh 103 [09 Nov 2004] DSA-591-1 libgd2 - integer overflows
501     {CAN-2004-0990}
502     - libgd2 2.0.30-1
503     [09 Nov 2004] DSA-590-1 gnats - format string vulnerability
504     {CAN-2004-0623}
505     NOTE: DSA got version of fix for unstable wrong
506     - gnats 4.0-6.1
507     [09 Nov 2004] DSA-589-1 libgd - integer overflows
508     {CAN-2004-0990}
509 joeyh 245 - libgd1 1.8.4-36.1
510 joeyh 99 [08 Nov 2004] DSA-588-1 gzip - insecure temporary files
511     {CAN-2004-0970}
512     NOTE: dsa says sid not affected
513     [08 Nov 2004] DSA-587-1 freeamp - buffer overflow
514     {CAN-2004-0964}
515     NOTE: DSA says zinf not vulnerable in sarge
516     [08 Nov 2004] DSA-586-1 ruby - infinite loop
517     {CAN-2004-0983}
518     - ruby1.6 1.6.8-12
519     - ruby1.8 1.8.1+1.8.2pre2-4
520 joeyh 83 [05 Nov 2004] DSA-585-1 shadow - programming error
521     {CAN-2004-1001}
522     - shadow 1:4.0.3-30.3
523 joeyh 73 [04 Nov 2004] DSA-584-1 dhcp - format string vulnerability
524     {CAN-2004-1006}
525     - dhcp 2.0pl5-19.1
526 joeyh 68 [03 Nov 2004] DSA-583-1 lvm10 - insecure temporary directory
527     {CAN-2004-0972}
528 joeyh 61 [02 Nov 2004] DSA-582-1 libxml - buffer overflow
529     {CAN-2004-0989}
530     - libxml 1.8.17-9
531     - libxml2 2.6.11-5
532     [01 Nov 2004] DSA-581-1 xpdf - integer overflows
533     {CAN-2004-0888}
534     - xpdf 3.00-9
535 joeyh 54 [01 Nov 2004] DSA-580-1 iptables - missing initialisation
536     {CAN-2004-0986}
537     - iptables 1.2.11-4
538     [01 Nov 2004] DSA-579-1 abiword - buffer overflow
539     {CAN-2004-0645}
540     NOTE: according to DSA, sid's abiword is not affected. sarge is same
541     [01 Nov 2004] DSA-578-1 mpg123 - buffer overflow
542     {CAN-2004-0982}
543     - mpg123 0.59r-17
544 joeyh 36 [29 Oct 2004] DSA-577-1 postgresql - symlink vulnerability
545     {CAN-2004-0977}
546     - postgresql 7.4.6-1
547     [29 Oct 2004] DSA-576-1 squid - multiple
548     {CVE-1999-0710 CAN-2004-0918}
549     - squid 2.5.7-1
550 joeyh 17 [28 Oct 2004] DSA-575-1 catdoc - insecure temporary file
551     {CAN-2003-0193}
552     - catdoc 0.91.5-2
553     [28 Oct 2004] DSA-574-1 cabextract - missing directory sanitising
554     {CAN-2004-0916}
555     - cabextract 1.1-1
556 joeyh 2 [21 Oct 2004] DSA-573-1 cupsys - integer overflows
557     {CAN-2004-0888}
558     - cupsys 1.1.20final+rc1-10
559     {CAN-2004-0889}
560 joeyh 96 - xpdf 3.00-10
561 micah 426 NOTE: kpdf and kfax are fixed in sarge, bug #278173 and #280373 for reference
562 joeyh 123 - kpdf 4:3.3.1-1
563 joeyh 2 - gpdf 2.8.0-1
564 joeyh 123 - kfax 4:3.3.1-1
565 joeyh 2 [21 Oct 2004] DSA-572-1 ecartis - multiple
566     {CAN-2004-0913}
567     - ecartis 1.0.0+cvs.20030911-8
568     [20 Oct 2004] DSA-571-1 libpng3 - buffer overflows, integer overflow
569     {CAN-2004-0955}
570     - libpng3 1.2.5.0-9
571     [20 Oct 2004] DSA-570-1 libpng - integer overflow
572     {CAN-2004-0955}
573     - libpng 1.0.15-8
574     [18 Oct 2004] DSA-569-1 netkit-telnet-ssl - invalid free(3)
575     {CAN-2004-0911}
576     - netkit-telnet-ssl 0.17.24+0.1-4
577     [16 Oct 2004] DSA-568-1 cyrus-sasl-mit - unsanitised input
578     {CAN-2004-0884}
579     NOTE removed from testing
580     NOTE maintainer reports hole not in cyrus-sasl2-mit
581     [15 Oct 2004] DSA-567-1 tiff - heap overflows
582     {CAN-2004-0803 CAN-2004-0804 CAN-2004-0886}
583     - tiff 3.6.1-2
584     - tiff3g 3.6.1-2
585     [14 Oct 2004] DSA-566-1 cupsys - unsanitised input
586     {CAN-2004-0923}
587     - cupsys 1.1.20final+rc1-9
588     [13 Oct 2004] DSA-565-1 sox - buffer overflows
589     {CAN-2004-0557}
590     - sox 12.17.4-9
591     [13 Oct 2004] DSA-564-1 mpg123 - missing user input sanitising
592     {CAN-2004-0805}
593     - mpg123 0.59r-16
594     [12 Oct 2004] DSA-563-1 cyrus-sasl - unsanitised input
595     {CAN-2004-0884}
596     - cyrus-sasl 1.5.28-6.2
597     - cyrus-sasl2 2.1.19-1.3
598     [11 Oct 2004] DSA-562-2 mysql - several vulnerabilities
599     {CAN-2004-0835 CAN-2004-0836 CAN-2004-0837}
600     - mysql 4.0.21-1
601     [11 Oct 2004] DSA-561-1 xfree86 - integer and stack overflows
602     {CAN-2004-0687 CAN-2004-0688}
603     - xfree86 4.3.0.dfsg.1-8
604     [07 Oct 2004] DSA-600-1 samba - arbitrary file access
605     {CAN-2004-0815}
606     NOTE: not affected according to DSA
607     [07 Oct 2004] DSA-560-1 lesstif1-1 - integer and stack overflows
608     {CAN-2004-0687 CAN-2004-0688}
609     - lesstif1-1 0.93.94-10
610     [06 Oct 2004] DSA-559-1 net-acct - insecure temporary file
611     {CAN-2004-0851}
612     - net-acct 0.71-7
613     [06 Oct 2004] DSA-558-1 libapache-mod-dav - null pointer dereference
614     {CAN-2004-0809}
615     - libapache-mod-dav 1.0.3-10
616     - apache2 2.0.51-1
617     [04 Oct 2004] DSA-557-1 pppoe - missing privilegue dropping
618     {CAN-2004-0564}
619     - pppoe 3.5-4
620     [03 Oct 2004] DSA-556-1 netkit-telnet - invalid free(3)
621     {CAN-2004-0911}
622     - netkit-telnet 0.17-26
623     [30 Sep 2004] DSA-555-1 freenet6 - file permissions
624     {CAN-2004-0563}
625     - freenet6 1.0-2.2
626     [27 Sep 2004] DSA-554-1 sendmail - pre-set password
627     {CAN-2004-0833}
628     - sendmail 8.13.1-13
629     [27 Sep 2004] DSA-553-1 getmail - symlink vulnerability
630     {CAN-2004-0880 CAN-2004-0881}
631     - getmail 3.2.5-1
632     [22 Sep 2004] DSA-552-1 imlib2 - unsanitised input
633     {CAN-2004-0802}
634     - imlib2 1.1.0-12.4
635     [21 Sep 2004] DSA-551-1 lukemftpd - incorrect internal variable handling
636     {CAN-2004-0794}
637     - lukemftpd 1.1-2.2
638     [20 Sep 2004] DSA-550-1 wv - buffer overflow
639     {CAN-2004-0645}
640     - wv 1.0.2-0.1
641     [17 Sep 2004] DSA-549-1 gtk+2.0 - multiple holes
642     {CAN-2004-0782 CAN-2004-0783 CAN-2004-0788}
643     - gtk+2.0 2.4.9-2
644     [16 Sep 2004] DSA-548-1 imlib - unsanitised input
645     {CAN-2004-0817}
646     - imlib 1.9.14-17
647 joeyh 255 - imlib+png2 1.9.14-16.2
648 joeyh 2 [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows
649     {CAN-2004-0827}
650     - imagemagic 6.0.6.2-1
651     [16 Sep 2004] DSA-546-1 gdk-pixbuf - multiple holes
652     {CAN-2004-0753 CAN-2004-0782 CAN-2004-0788}
653     - gdk-pixbuf 0.22.0-7
654     [15 Sep 2004] DSA-545-1 cupsys - denial of service
655     {CAN-2004-0558}
656     - cupsys 1.1.20final+rc1-6
657     [14 Sep 2004] DSA-544-1 webmin - insecure temporary directory
658     {CAN-2004-0559}
659     - webmin 1.160-1
660     - usermin 1.090-1
661     [31 Aug 2004] DSA-543-1 krb5 -- several vulnerabilities
662     {CAN-2004-0642 CAN-2004-0643 CAN-2004-0644 CAN-2004-0772}
663     - krb5 1.3.4-3
664     [31 Aug 2004] DSA-458-2 python2.2 - buffer overflow
665     {CAN-2004-0150}
666     NOTE: not affected according to DSA
667     [30 Aug 2004] DSA-542-1 qt - unsanitised input
668     {CAN-2004-0691 CAN-2004-0692 CAN-2004-0693}
669     - qt-x11-free 3.3.3-4
670     [25 Aug 2004] DSA-541 icecast-server - cross site scripting
671     {CAN-2004-0781}
672     - icecast-server 1.3.12-8
673     [18 Aug 2004] DSA-540 mysql-dfsg - insecure file creation
674     {CAN-2004-0457}
675     - mysql-dfsg 4.0.20-11
676     [18 Aug 2004] DSA-539 kdelibs - denial of service
677     {CAN-2004-0689}
678     - kdelibs 4:3.2.3-3.sarge.1
679     [17 Aug 2004] DSA-538 rsync - unauthorised directory traversal and file access
680     - rsync 2.6.2-3
681 joeyh 172 [16 Aug 2004] DSA-537 ruby - insecure file permissions
682 joeyh 2 {CAN-2004-0755}
683     - ruby1.8 1.8.1+1.8.2pre1-4
684     HELP: is ruby1.6 vulnerable?
685     [04 Aug 2004] DSA-536 libpng - several vulnerabilities
686     {CAN-2004-0597 CAN-2004-0598 CAN-2004-0599 CAN-2004-0768}
687     - libpng 1.0.15-6
688     - libpng3 1.2.5.0-7
689     [02 Aug 2004] DSA-535 squirrelmail - several vulnerabilities
690     {CAN-2004-0519 CAN-2004-0520 CAN-2004-0521 CAN-2004-0639}
691     - squirrelmail 2:1.4.3a-0.1
692     [22 Jul 2004] DSA-534 mailreader - directory traversal
693     {CAN-2002-1581}
694     - mailreader 2.3.29-9
695     [22 Jul 2004] DSA-533 courier - cross-site scripting
696     {CAN-2004-0591}
697     - courier 0.45.4-4
698     [22 Jul 2004] DSA-532 libapache-mod-ssl - several vulnerabilities
699     {CAN-2004-0488 CAN-2004-0700}
700     - libapache-mod-ssl 2.8.19-1
701     [20 Jul 2004] DSA-531 php4 - several vulnerabilities
702     {CAN-2004-0594 CAN-2004-0595}
703     ! php4 4:4.3.8-1
704     [17 Jul 2004] DSA-530 l2tpd - buffer overflow
705     {CAN-2004-0649}
706     - l2tpd 0.70-pre20031121-2
707     [17 Jul 2004] DSA-529 netkit-telnet-ssl - format string
708     {CAN-2004-0640}
709     ! netkit-telnet-ssl 0.17.24+0.1-2
710     [17 Jul 2004] DSA-528 ethereal - denial of service
711     {CAN-2004-0635}
712     - ethereal 0.10.5-1
713     [03 Jul 2004] DSA-527 pavuk - buffer overflow
714     {CAN-2004-0456}
715     NOTE: DSA is incorrect; pavuk is in sarge and unstable.
716     ! pavuk 0.9pl28-3
717     [03 Jul 2004] DSA-526 webmin - several vulnerabilities
718     {CAN-2004-0582 CAN-2004-0583}
719     - webmin 1.150-1
720     [24 Jun 2004] DSA-525 apache - buffer overflow
721     {CAN-2004-0492}
722     - apache 1.3.31-2
723     [19 Jun 2004] DSA-524 rlpr - several vulnerabilities
724     {CAN-2004-0393 CAN-2004-0454}
725     - rlpr 2.02-7.1
726     [19 Jun 2004] DSA-523 www-sql - buffer overflow
727     {CAN-2004-0455}
728     - www-sql 0.5.7-18
729     [19 Jun 2004] DSA-522 super - format string vulnerability
730     {CAN-2004-0579}
731     - super 3.23.0-1
732     [18 Jun 2004] DSA-521 sup - format string vulnerability
733     {CAN-2004-0451}
734     - sup 1.8-11
735     [16 Jun 2004] DSA-520 krb5 - buffer overflows
736     {CAN-2004-0523}
737     - krb5 1.3.3-2
738     [15 Jun 2004] DSA-519 cvs - several vulnerabilities
739     {CAN-2004-0416 CAN-2004-0417 CAN-2004-0418}
740     - cvs 1:1.12.9-1
741     [14 Jun 2004] DSA-518 kdelibs - unsanitised input
742     {CAN-2004-0411}
743     - kdelibs 3.2.3
744     [10 Jun 2004] DSA-517 cvs - buffer overflow
745     {CAN-2004-0414]
746     - cvs 1.12.9-1
747     [07 Jun 2004] DSA-516 postgresql - buffer overflow
748     {CAN-2004-0547}
749     - postgresql 07.03.0200-3.
750     [05 Jun 2004] DSA-515 lha - several vulnerabilities
751     {CAN-2004-0234 CAN-2004-0235}
752     ! lha 1.14i-8
753     NOTE: If 1.14i-8 cannot get into testing, the fix for 1.14i-2.0.1
754     from the DSA could to updated via t-p-u.
755     [04 Jun 2004] DSA-514 kernel-image-sparc-2.2 - failing function and TLB flush
756     {CAN-2004-0077}
757     - kernel-image-sparc-2.2 9.1
758     NOTE: did not check other versions of the kernel
759     [03 Jun 2004] DSA-513 log2mail - format string
760     {CAN-2004-0450}
761     ! log2mail 0.2.8-3
762     [02 Jun 2004] DSA-512 gallery - unauthenticated access
763     {CAN-2004-0522}
764     - gallery 1.4.3-pl2-1
765     [30 May 2004] DSA-511 ethereal - buffer overflows
766 micah 622 {CAN-2004-0176}
767 joeyh 2 - ethereal 0.10.3-1
768     [29 May 2004] DSA-510 jftpgw - format string
769     {CAN-2004-0448}
770     - jftpgw 0.13.4-1
771     [29 May 2004] DSA-509 gatos - privilege escalation
772     {CAN-2004-0395}
773     - gatos 0.0.5-12
774     [22 May 2004] DSA-508 xpcd - buffer overflow
775     {CAN-2004-0402}
776     - xpcd 2.08-10
777     [19 May 2004] DSA-507 cadaver - buffer overflow
778     {CAN-2004-0398}
779     - cadaver 0.22.1-3
780     [19 May 2004] DSA-506 neon - buffer overflow
781     {CAN-2004-0398}
782     - neon 0.24.6.dfsg-1
783     [19 May 2004] DSA-505 cvs - heap overflow
784     {CAN-2004-0396}
785     - cvs 1.12.5-6
786     [18 May 2004] DSA-504 heimdal - missing input sanitising
787     {CAN-2004-0434}
788     - heimdal 0.6.2-1
789     [13 May 2004] DSA-503 mah-jong - missing argument check
790     {CAN-2004-0458}
791     - mah-jong 1.6.2-1
792     [11 May 2004] DSA-502 exim-tls - buffer overflow
793     {CAN-2004-0399 CAN-2004-0400}
794     NOTE: exim-tls not in sarge
795     [07 May 2004] DSA-501 exim - buffer overflow
796     {CAN-2004-0399 CAN-2004-0400}
797     - exim 3.36-11
798     - exim4 4.33-1
799     [01 May 2004] DSA-500 flim - insecure temporary file
800     {CAN-2004-0422}
801     - flim 1:1.14.6+0.20040415-1
802     [01 May 2004] DSA-499 rsync - directory traversal
803     {CAN-2004-0426}
804     - rsync 2.6.1-1
805     [30 Apr 2004] DSA-498 libpng - out of bound access
806     {CAN-2004-0421}
807     - libpng 1.0.15-5
808     - libpng3 1.2.5.0-6
809     [29 Apr 2004] DSA-497 mc - several vulnerabilities
810     {CAN-2004-0226 CAN-2004-0231 CAN-2004-0232}
811     - mc 1:4.6.0-4.6.1-pre1-2
812     [29 Apr 2004] DSA-496 eterm - missing input sanitising
813     {CAN-2003-0068}
814     - eterm 0.9.2-6
815     [26 Apr 2004] DSA-495 linux-kernel-2.4.16-arm - several vulnerabilities
816     {CAN-2003-0127 CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
817     NOTE: 2.4.16 not present. Did not check newer kernels.
818     [21 Apr 2004] DSA-494 ident2 - buffer overflow
819     {CAN-2004-0408}
820     - ident2 1.04-2
821     [21 Apr 2004] DSA-493 xchat - buffer overflow
822     {CAN-2004-0409}
823     - xchat 2.0.8-1
824     [18 Apr 2004] DSA-492 iproute - denial of service
825     {CAN-2003-0856}
826     - iproute 20010824-13.1
827     [17 Apr 2004] DSA-491 linux-kernel-2.4.19-mips - several vulnerabilities
828     {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
829     NOTE: 2.4.19 not present. Did not check newer kernels.
830     [17 Apr 2004] DSA-490 zope - arbitrary code execution
831     {CVE-2002-0688}
832     - zope 2.6.0-0.1
833     [17 Apr 2004] DSA-489 linux-kernel-2.4.17-mips+mipsel - several vulnerabilities
834     {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
835     NOTE: 2.4.17 not present. Did not check newer kernels.
836     [16 Apr 2004] DSA-488 logcheck - insecure temporary directory
837     {CAN-2004-0404}
838     - logcheck 1.1.1-13.2
839     [16 Apr 2004] DSA-487 neon - format string
840     {CAN-2004-0179}
841     - newo 0.24.5-1
842     [16 Apr 2004] DSA-486 cvs - several vulnerabilities
843     {CAN-2004-0180 CAN-2004-0405}
844     - cvs 1:1.12.5-4
845     [14 Apr 2004] DSA-485 ssmtp - format string
846     {CAN-2004-0156}
847     - ssmtp 2.60.7
848     [14 Apr 2004] DSA-484 xonix - failure to drop privileges
849     {CAN-2004-0157}
850     - xonix 1.4-21
851     [14 Apr 2004] DSA-483 mysql - insecure temporary file creation
852     {CAN-2004-0381}
853     - mysql-dfsg 4.0.18-4
854     {CAN-2004-0388}
855     ! mysql-dfsg 4.0.18-6
856     [14 Apr 2004] DSA-482 linux-kernel-2.4.17-apus+s390 - several vulnerabilities
857     {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
858     NOTE: 2.4.17 not present. Did not check newer kernels.
859     [14 Apr 2004] DSA-481 linux-kernel-2.4.17-ia64 - several vulnerabilities
860     {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
861     NOTE: 2.4.17 not present. Did not check newer kernels.
862     [14 Apr 2004] DSA-480 linux-kernel-2.4.17+2.4.18-hppa - several vulnerabilities
863     {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
864     NOTE: 2.4.17/18 not present. Did not check newer kernels.
865     [14 Apr 2004] DSA-479 linux-kernel-2.4.18-alpha+i386+powerpc - several vulnerabilities
866     {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
867     NOTE: 2.4.18 not present. Did not check newer kernels.
868     [06 Apr 2004] DSA-478 tcpdump - denial of service
869     {CAN-2004-0183 CAN-2004-0184}
870     - tcpdump 3.7.2-4
871     [06 Apr 2004] DSA-477 xine-ui - insecure temporary file creation
872     {CAN-2004-0372}
873     - xine-ui 0.99.1-1
874     [06 Apr 2004] DSA-476 heimdal - cross-realm
875     {CAN-2004-0371}
876     - heimdal 0.6.1-1
877     [05 Apr 2004] DSA-475 linux-kernel-2.4.18-hppa - several vulnerabilities
878     {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
879     NOTE: 2.4.18 not present. Did not check newer kernels.
880     [03 Apr 2004] DSA-474 squid - ACL bypass
881     {CAN-2004-0189}
882     - squid 2.5.5-1
883     [03 Apr 2004] DSA-473 oftpd - denial of service
884     {CAN-2004-0376}
885     - oftpd 20040304-1
886     [03 Apr 2004] DSA-472 fte - several vulnerabilities
887     {CAN-2003-0648}
888     - fte 0.50.0-1.1
889     [02 Apr 2004] DSA-471 interchange - missing input sanitising
890     {CAN-2004-0374}
891     - interchange 5.0.1-1
892     [01 Apr 2004] DSA-470 linux-kernel-2.4.17-hppa - several vulnerabilities
893     {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
894     NOTE: 2.4.17 not present. Did not check newer kernels.
895     [29 Mar 2004] DSA-469 pam-pgsql - missing input sanitising
896     {CAN-2004-0366}
897     - pam-pgsql 0.5.2-7.1
898     [24 Mar 2004] DSA-468 emil - several vulnerabilities
899     {CAN-2004-0152 CAN-2004-0153}
900     - emil 2.1.0-beta9-14
901     [23 Mar 2004] DSA-467 ecartis - several vulnerabilities
902     {CAN-2003-0781 CAN-2003-0782}
903     - ecartis 1.0.0+cvs.20030911
904     [18 Mar 2004] DSA-466 linux-kernel-2.2.10-powerpc-apus - failing function and TLB flush
905     {CAN-2004-0077}
906     NOTE: 2.2.10 not present. Did not check newer kernels.
907     [17 Mar 2004] DSA-465 openssl - several vulnerabilities
908     {CAN-2004-0079 CAN-2004-0081}
909     - openssl 0.9.7d-1
910     NOTE: CAN-2004-0081 only affects 0.9.6.
911     NOTE: 0.9.7d also fixes CAN-2004-0112
912     - openssl 0.9.6l
913 joeyh 136 - openssl096 0.9.6m-1
914 joeyh 2 [16 Mar 2004] DSA-464 gdk-pixbuf - broken image handling
915     {CAN-2004-0111}
916     - gdk-pixbuf 0.22.0-3
917     [12 Mar 2004] DSA-463 samba - privilege escalation
918     {CAN-2004-0186}
919     - samba 3.0.2-2
920     [12 Mar 2004] DSA-462 xitalk - missing privilege release
921     {CAN-2004-0151}
922     - xitalk 1.1.11-11
923     [11 Mar 2004] DSA-461 calife - buffer overflow
924     {CAN-2004-0188}
925     - calife 2.8.6-1
926     [10 Mar 2004] DSA-460 sysstat - insecure temporary file
927     {CAN-2004-0108}
928     - sysstat 5.0.2-1
929     [10 Mar 2004] DSA-459 kdelibs - cookie path traversal
930     {CAN-2003-0592}
931     - kdelibs 4:3.1.3-1
932     [09 Mar 2004] DSA-458 python2.2 - buffer overflow
933     {CAN-2004-0150}
934     NOTE: not affected according to DSA
935     [08 Mar 2004] DSA-457 wu-ftpd - several vulnerabilities
936 joeyh 164 {CAN-2004-0148 CAN-2004-0185}
937 joeyh 2 - wu-ftpd 2.6.2-17.1
938     [06 Mar 2004] DSA-456 linux-kernel-2.2.19-arm - failing function and TLB flush
939     {CAN-2004-0077}
940     NOTE: 2.2.19 not present. Did not check newer kernels.
941     [03 Mar 2004] DSA-455 libxml - buffer overflows
942     {CAN-2004-0110}
943     - libxml 1.8.17-5
944     - libxml2 2.6.6-1
945     [02 Mar 2004] DSA-454 linux-kernel-2.2.22-alpha - failing function and TLB flush
946     {CAN-2004-0077}
947     NOTE: 2.2.22 not present. Did not check newer kernels.
948     [02 Mar 2004] DSA-453 linux-kernel-2.2.20-i386+m68k+powerpc - failing function and TLB flush
949     {CAN-2004-0077}
950     NOTE: 2.2.20 not present. Did not check newer kernels.
951     [29 Feb 2004] DSA-452 libapache-mod-python - denial of service
952     {CAN-2003-0973}
953     - libapache-mod-python 2:2.7.10-1
954     [27 Feb 2004] DSA-451 xboing - buffer overflows
955     {CAN-2004-0149}
956     - xboing 2.4-26.1
957     [27 Feb 2004] DSA-450 linux-kernel-2.4.19-mips - several vulnerabilities
958     {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
959     NOTE: 2.4.19 not present. Did not check newer kernels.
960     [24 Feb 2004] DSA-449 metamail - buffer overflow, format string bugs
961     {CAN-2004-0104 CAN-2004-0105}
962     - metamail 2.7-45.2
963     [22 Feb 2004] DSA-448 pwlib - several vulnerabilities
964     {CAN-2004-0097}
965     - pwlib 1.5.2-4
966     [22 Feb 2004] DSA-447 hsftp - format string
967     {CAN-2004-0159}
968     ! hsftp 1.15-1
969     [21 Feb 2004] DSA-446 synaesthesia - insecure file creation
970     {CAN-2004-0160}
971     DSA notes not setuid anymore so ok
972     [21 Feb 2004] DSA-445 lbreakout2 - buffer overflow
973     {CAN-2004-0158}
974     - lbreakout2 2.4
975     [20 Feb 2004] DSA-444 linux-kernel-2.4.17-ia64 - missing function return value check
976     {CAN-2004-0077}
977     NOTE: 2.4.17 not present. Did not check newer kernels.
978     [19 Feb 2004] DSA-443 xfree86 - several vulnerabilities
979     {CAN-2003-0690}
980     - xfree86 4.3.0-0pre1v2
981     {CAN-2004-0083 CAN-2004-0084 CAN-2004-0106}
982     - xfree86 4.3.0-1
983     {CAN-2004-0093 CAN-2004-0094}
984     - xfree86 4.2.1-6
985     [19 Feb 2004] DSA-442 linux-kernel-2.4.17-s390 - several vulnerabilities
986     {CAN-2003-0001 CAN-2003-0244 CAN-2003-0246 CAN-2003-0247 CAN-2003-0248 CAN-2003-0364 CAN-2003-0961 CAN-2003-0985 CAN-2004-0077 CVE-2002-0429}
987     NOTE: 2.4.17 not present. Did not check newer kernels.
988     [18 Feb 2004] DSA-441 linux-kernel-2.4.17-mips+mipsel - missing function return value check
989     {CAN-2004-0077}
990     NOTE: 2.4.17 not present. Did not check newer kernels.
991     [18 Feb 2004] DSA-440 linux-kernel-2.4.17-powerpc-apus - several vulnerabilities
992     {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
993     NOTE: 2.4.17 not present. Did not check newer kernels.
994     [18 Feb 2004] DSA-439 linux-kernel-2.4.16-arm - several vulnerabilities
995     {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
996     NOTE: 2.4.16 not present. Did not check newer kernels.
997     [18 Feb 2004] DSA-438 linux-kernel-2.4.18-alpha+i386+powerpc - missing function return value check
998     {CAN-2004-0077}
999     NOTE: 2.4.17 not present. Did not check newer kernels.
1000     [11 Feb 2004] DSA-437 cgiemail - open mail relay
1001     {CAN-2002-1575}
1002     - cgiemail 1.6-20
1003     [08 Feb 2004] DSA-436 mailman - several vulnerabilities
1004     {CAN-2003-0991}
1005 joeyh 68 NOTE: apparently specific to mailman 2.0, not 2.1
1006 joeyh 2 {CAN-2003-0965}
1007     - mailman 2.1.4-1
1008     {CAN-2003-0038}
1009     - mailman 2.1.1-1
1010     [06 Feb 2004] DSA-435 mpg123 - heap overflow
1011     {CAN-2003-0865}
1012     - mpg123 0.59r-15
1013     [05 Feb 2004] DSA-434 gaim - several vulnerabilities
1014     {CAN-2004-0005 CAN-2004-0006 CAN-2004-0007 CAN-2004-0008}
1015     - gaim 1:0.75-2
1016     [04 Feb 2004] DSA-433 kernel-patch-2.4.17-mips - integer overflow
1017     {CAN-2003-0961}
1018     NOTE: 2.4.17 not present. Did not check newer kernels.
1019     [03 Feb 2004] DSA-432 crawl - buffer overflow
1020     {CAN-2004-0103}
1021     - crawl 4.0.0beta26-4
1022     [01 Feb 2004] DSA-431 perl - information leak
1023     {CAN-2003-0618}
1024     - perl 5.8.3-3
1025     [28 Jan 2004] DSA-430 trr19 - missing privilege release
1026     {CAN-2004-0047}
1027     - trr19 1.0beta5-17.1
1028     [26 Jan 2004] DSA-429 gnupg - cryptographic weakness
1029     {CAN-2003-0971}
1030     - gnupg 1.2.4-1
1031     [20 Jan 2004] DSA-428 slocate - buffer overflow
1032     {CAN-2003-0848}
1033     - slocate 2.7-3
1034     [19 Jan 2004] DSA-427 linux-kernel-2.4.17-mips+mipsel - missing boundary check
1035     {CAN-2003-0985}
1036     NOTE: 2.4.17 not present. Did not check newer kernels.
1037     [18 Jan 2004] DSA-426 netpbm-free - insecure temporary files
1038     {CAN-2003-0924}
1039     - netpbm-free 2:9.25-9
1040     [16 Jan 2004] DSA-425 tcpdump - multiple vulnerabilities
1041     {CAN-2003-1029 CAN-2003-0989 CAN-2004-0055 CAN-2004-0057}
1042     HELP: No idea if this is fixed, we have a new upstream version
1043     HELP: that came out after these advisories, but neither the debian nor
1044     HELP: the upstream changelog seem to mention them.
1045 joeyh 172 NOTE: Mailed maintainer.
1046 joeyh 2 [16 Jan 2004] DSA-424 mc - buffer overflow
1047     {CAN-2003-1023}
1048     - mc 1:4.6.0-4.6.1-pre1-1
1049     [15 Jan 2004] DSA-423 linux-kernel-2.4.17-ia64 - several vulnerabilities
1050     {CAN-2003-0001 CAN-2003-0018 CAN-2003-0127 CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0961 CAN-2003-0985}
1051     NOTE: 2.4.17 not present. Did not check newer kernels.
1052     [13 Jan 2004] DSA-422 cvs - remote vulnerability
1053     - cvs 1.11.11
1054     [12 Jan 2004] DSA-421 mod-auth-shadow - password expiration
1055     {CAN-2004-0041}
1056     - mod-auth-shadow 1.4-1
1057     [12 Jan 2004] DSA-420 jitterbug - improperly sanitised input
1058     {CAN-2004-0028}
1059     - jitterbug 1.6.2-4.5
1060     [09 Jan 2004] DSA-419 phpgroupware - missing filename sanitising, SQL injection
1061     {CAN-2004-0016 CAN-2004-0017}
1062     - phpgroupware 0.9.14.007-4
1063     [07 Jan 2004] DSA-418 vbox3 - privilege leak
1064     {CAN-2004-0015}
1065     - vbox3 0.1.8
1066     [07 Jan 2004] DSA-417 linux-kernel-2.4.18-powerpc+alpha - missing boundary check
1067     {CAN-2003-0961 CAN-2003-0985}
1068     NOTE: 2.4.18 not present. Did not check newer kernels.
1069     [06 Jan 2004] DSA-416 fsp - buffer overflow, directory traversal
1070 joeyh 164 {CAN-2003-1022 CAN-2004-0011}
1071 joeyh 2 - fsp 2.81.b18-1
1072     [06 Jan 2004] DSA-415 zebra - denial of service
1073     {CAN-2003-0795 CAN-2003-0858}
1074     - quagga 0.96.4x-4
1075     [06 Jan 2004] DSA-414 jabber - denial of service
1076     {CAN-2004-0013}
1077     - jabber 1.4.3-1
1078     [06 Jan 2004] DSA-413 linux-kernel-2.4.18 - missing boundary check
1079     {CAN-2003-0985}
1080     NOTE: 2.4.18 not present. Did not check newer kernels.
1081     [05 Jan 2004] DSA-412 nd - buffer overflows
1082     {CAN-2004-0014}
1083     - nd 0.8.2-1
1084     [05 Jan 2004] DSA-411 mpg321 - format string vulnerability
1085     {CAN-2003-0969}
1086     - mpg321 0.2.10.3
1087     [05 Jan 2004] DSA-410 libnids - buffer overflow
1088     {CAN-2003-0850}
1089     - libnids 1.18-1
1090     [05 Jan 2004] DSA-409 bind - denial of service
1091     {CAN-2003-0914}
1092     - bind 1:8.4.3-1
1093     [05 Jan 2004] DSA-408 screen - integer overflow
1094     {CAN-2003-0972}
1095     - screen 4.0.2-0.1
1096     [05 Jan 2004] DSA-407 ethereal - buffer overflows
1097     {CAN-2003-0925 CAN-2003-0926 CAN-2003-0927 CAN-2003-1012 CAN-2003-1013
1098     - ethereal 0.10.0-1
1099     [05 Jan 2004] DSA-406 lftp - buffer overflow
1100     - lftp 2.6.10-1
1101     [30 Dec 2003] DSA-405 xsok - missing privilege release
1102     {CAN-2003-0949}
1103     - xsok 1.02-11
1104     [04 Dec 2003] DSA-404 rsync - heap overflow
1105     {CAN-2003-0962}
1106     - rsync 2.5.6-1.1
1107     [01 Dec 2003] DSA-403 kernel-image-2.4.18-1-alpha, kernel-image-2.4.18-1-i386, kernel-source-2.4.18 - local root exploit
1108     {CAN-2003-0961}
1109     NOTE: 2.4.18 not present in sarge, did not check newer kernels.
1110     [17 Nov 2003] DSA-402 minimalist - unsanitised input
1111     {CAN-2003-0902}
1112     - minimalist 2.4-1
1113     [17 Nov 2003] DSA-401 hylafax - format strings
1114     {CAN-2003-0886}
1115     - hylafax 1:4.1.8-1
1116     [11 Nov 2003] DSA-400 omega-rpg - buffer overflow
1117     {CAN-2003-0932}
1118     - omega-rpg 0.90-pa9-11
1119     [10 Nov 2003] DSA-399 epic4 - buffer overflow
1120     {CAN-2003-0328}
1121     - epic4 1:1.1.11.20030409-2
1122     [10 Nov 2003] DSA-398 conquest - buffer overflow
1123     {CAN-2003-0933}
1124     - conquest 7.2-5
1125     [07 Nov 2003] DSA-397 postgresql - buffer overflow
1126     {CAN-2003-0901}
1127     - postgresql 7.3.4
1128     [29 Oct 2003] DSA-396 thttpd - missing input sanitizing, wrong calculation
1129     {CAN-2002-1562 CAN-2003-0899}
1130     - thttpd 2.23beta1-2.3
1131     [15 Oct 2003] DSA-395 tomcat4 - incorrect input handling
1132     {CAN-2003-0866}
1133     ! tomcat4 4.1.24-2
1134     NOTE another RC (unreproducible?) bug and missing deps (#263201)
1135     NOTE are keeping the fix out of testing
1136     [11 Oct 2003] DSA-394 openssl095 - ASN.1 parsing vulnerability
1137     {CAN-2003-0543 CAN-2003-0544 CAN-2003-0545}
1138     - openssl 0.9.7c
1139     - openssl096 0.9.6k
1140     [01 Oct 2003] DSA-393 openssl - denial of service
1141     {CAN-2003-0543 CAN-2003-0544 CAN-2003-0545}
1142     - openssl 0.9.7c
1143     - openssl096 0.9.6k
1144     [29 Sep 2003] DSA-392 webfs - buffer overflows, file and directory exposure
1145     {CAN-2003-0832 CAN-2003-0833}
1146     - webfs 1.20
1147     [28 Sep 2003] DSA-391 freesweep - buffer overflow
1148     {CAN-2003-0828}
1149     - freesweep 0.88-4.1
1150     [26 Sep 2003] DSA-390 marbles - buffer overflow
1151     {CAN-2003-0830}
1152     NOTE not present in sid, sarge
1153     [20 Sep 2003] DSA-389 ipmasq - insecure packet filtering rules
1154     {CAN-2003-0785}
1155     - ipmasq 3.5.12
1156     [19 Sep 2003] DSA-388 kdebase - several vulnerabilities
1157     {CAN-2003-0690 CAN-2003-0692}
1158     - kdebase 4:3.2
1159     [18 Sep 2003] DSA-387 gopher - buffer overflows
1160     {CAN-2003-0805}
1161     - gopher 3.0.6
1162     [18 Sep 2003] DSA-386 libmailtools-perl - input validation bug
1163     {CAN-2002-1271}
1164     - libmailtools-perl 1.51
1165     [18 Sep 2003] DSA-385 hztty - buffer overflows
1166     {CAN-2003-0783}
1167     - hztty 2.0-6
1168     [17 Sep 2003] DSA-384 sendmail - buffer overflows
1169     {CAN-2003-0681 CAN-2003-0694}
1170     - sendmail 8.12.10-1
1171     [17 Sep 2003] DSA-383 ssh-krb5 - possible remote vulnerability
1172     {CAN-2003-0693}
1173     {CAN-2003-0695}
1174     {CAN-2003-0682}
1175     HELP: Screwy changelog does not make sense. Filed bug.
1176     [16 Sep 2003] DSA-382 ssh - possible remote vulnerability
1177     {CAN-2003-0693}
1178     - openssh 1:3.6.1p2-6.0
1179     {CAN-2003-0695}
1180     - openssh 1:3.7.1
1181     {CAN-2003-0682}
1182     - openssh 1:3.6.1p2-9
1183     [13 Sep 2003] DSA-381 mysql - buffer overflow
1184     {CAN-2003-0780}
1185     - mysql-dfsg 4.0.15-1
1186     [12 Sep 2003] DSA-380 xfree86 - buffer overflows, denial of service
1187     {CAN-2003-0063}
1188     - xfree86 4.2.1-11
1189     {CAN-2003-0071}
1190     - xfree86 4.2.1-11
1191     {CAN-2002-0164}
1192     - xfree86 4.2.1-11
1193     {CAN-2003-0730}
1194     - xfree86 4.2.1-12
1195     [11 Sep 2003] DSA-379 sane-backends - several vulnerabilities
1196     {CAN-2003-0773 CAN-2003-0774 CAN-2003-0775 CAN-2003-0776 CAN-2003-0777 CAN-2003-0778}
1197     - sane-backends 1.0.11-1
1198     [07 Sep 2003] DSA-378 mah-jong - buffer overflows, denial of service
1199     {CAN-2003-0705 CAN-2003-0706}
1200     - mah-jong 1.5.6-2
1201     [04 Sep 2003] DSA-377 wu-ftpd - insecure program execution
1202     {CVE-1999-0997}
1203     - wu-ftpd 2.6.2-15
1204     [04 Sep 2003] DSA-376 exim - buffer overflow
1205     {CAN-2003-0743}
1206     - exim 3.36-8
1207     [29 Aug 2003] DSA-375 node - buffer overflow, format string
1208     {CAN-2003-0707 CAN-2003-0708}
1209     - node 0.3.2-1
1210     [26 Aug 2003] DSA-374 libpam-smb - buffer overflow
1211     {CAN-2003-0686}
1212     NOTE: not in sid/sarge
1213     [16 Aug 2003] DSA-373 autorespond - buffer overflow
1214     {CAN-2003-0654}
1215     - autorespond 2.0.4-1
1216     [16 Aug 2003] DSA-372 netris - buffer overflow
1217     {CAN-2003-0685}
1218     - netris 0.52-1
1219     [11 Aug 2003] DSA-371 perl - cross-site scripting
1220     {CAN-2003-0615}
1221     - perl 5.8.0-19
1222     [08 Aug 2003] DSA-370 pam-pgsql - format string
1223     {CAN-2003-0672}
1224     - pam-pgsql 0.5.2-7
1225     [08 Aug 2003] DSA-369 zblast - buffer overflow
1226     {CAN-2003-0613}
1227     - zblast 1.2.1-7
1228     [08 Aug 2003] DSA-368 xpcd - buffer overflow
1229     {CAN-2003-0649}
1230     - xpcd 2.08-9
1231     [08 Aug 2003] DSA-367 xtokkaetama - buffer overflow
1232     {CAN-2003-0652}
1233     - xtokkaetama 1.0b-9
1234     [05 Aug 2003] DSA-366 eroaster - insecure temporary file
1235     {CAN-2003-0656}
1236     - eroaster 2.2.0-0.5-1
1237     [05 Aug 2003] DSA-365 phpgroupware - several vulnerabilities
1238     {CAN-2003-0504 CAN-2003-0599 CAN-2003-0657}
1239     - phpgroupware 0.9.14.007-1)
1240     [04 Aug 2003] DSA-364 man-db - buffer overflows, arbitrary command execution
1241     {CAN-2003-0620 CAN-2003-0645}
1242     - man-db 2.4.1-13
1243     [03 Aug 2003] DSA-363 postfix - denial of service, bounce-scanning
1244     {CAN-2003-0468 CAN-2003-0540}
1245     - postfix 1.1.12
1246     [02 Aug 2003] DSA-362 mindi - insecure temporary file
1247     {CAN-2003-0617}
1248     - mindi 0.86-1
1249     [01 Aug 2003] DSA-361 kdelibs, kdelibs-crypto - several vulnerabilities
1250     {CAN-2003-0459 CAN-2003-0370}
1251     - kdelibs 4:3.1.3-1
1252     [01 Aug 2003] DSA-360 xfstt - several vulnerabilities
1253     {CAN-2003-0581}
1254     - xfstt 1.5-1
1255     {CAN-2003-0625}
1256     - xfstt 1.5.1-1
1257     [31 Jul 2003] DSA-359 atari800 - buffer overflows
1258     {CAN-2003-0630}
1259     - atari800 1.3.1-2
1260     [31 Jul 2003] DSA-358 linux-kernel-2.4.18 - several vulnerabilities
1261     {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}
1262     NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.
1263     [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit
1264 joeyh 191 {CAN-2003-0466}
1265 joeyh 2 - wu-ftpd 2.6.2-12
1266     [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows
1267     {CAN-2003-0611}
1268     - xtokkaetama 1.0b-8
1269     [30 Jul 2003] DSA-355 gallery - cross-site scripting
1270     {CAN-2003-0614}
1271     - gallery 1.3.4-3
1272     [29 Jul 2003] DSA-354 xconq - buffer overflows
1273     {CAN-2003-0607}
1274     - xconq 7.4.1-2.1
1275     [29 Jul 2003] DSA-353 sup - insecure temporary file
1276     {CAN-2003-0606}
1277     - sup 1.8-9
1278     [22 Jul 2003] DSA-352 fdclone - insecure temporary directory
1279     {CAN-2003-0596}
1280     - fdclone 2.04-1
1281     [16 Jul 2003] DSA-351 php4 - cross-site scripting
1282     {CAN-2003-0442}
1283     - php4 4:4.3.2+rc3-1
1284     [15 Jul 2003] DSA-350 falconseye - buffer overflow
1285     {CAN-2003-0358}
1286     NOTE: not in testing, fixed in unstable
1287     - falconseye 1.9.3-9
1288     [14 Jul 2003] DSA-349 nfs-utils - buffer overflow
1289     {CAN-2003-0252}
1290     - nfs-utils 1:1.0.3-2
1291     [11 Jul 2003] DSA-348 traceroute-nanog - integer overflow, buffer overflow
1292     {CAN-2003-0453}
1293     - traceroute-nanog 6.1.1-1.3
1294     [08 Jul 2003] DSA-347 teapop - SQL injection
1295     {CAN-2003-0515}
1296     - teapop 0.3.5-2
1297     [08 Jul 2003] DSA-346 phpsysinfo - directory traversal
1298     {CAN-2003-0536}
1299     - phpsysinfo 2.1-1
1300     [08 Jul 2003] DSA-345 xbl - buffer overflow
1301     {CAN-2003-0535}
1302     - xbl 1.0k-6
1303     [08 Jul 2003] DSA-344 unzip - directory traversal
1304 joeyh 84 {CAN-2003-0282}
1305 joeyh 2 - unzip 5.50-3
1306     [08 Jul 2003] DSA-343 skk, ddskk - insecure temporary file
1307     {CAN-2003-0539}
1308     - skk 10.62a-6
1309     - ddskk 12.1.cvs.20030622-1
1310     [07 Jul 2003] DSA-342 mozart - unsafe mailcap configuration
1311     {CAN-2003-0538}
1312     NOTE: mozart is not in sarge
1313     - mozart 1.2.5.20030212-2
1314     [07 Jul 2003] DSA-341 liece - insecure temporary file
1315     {CAN-2003-0537}
1316     - liece 2.0+0.20030527cvs-1
1317     [06 Jul 2003] DSA-340 x-face-el - insecure temporary file
1318     - x-face-el 1.3.6.23-1
1319     [06 Jul 2003] DSA-339 semi - insecure temporary file
1320     {CAN-2003-0440}
1321     - semi 1.14.5+20030609-1
1322     [29 Jun 2003] DSA-338 proftpd - SQL injection
1323     {CAN-2003-0500}
1324     - proftpd 1.2.8-8
1325     [29 Jun 2003] DSA-337 gtksee - buffer overflow
1326     {CAN-2003-0444}
1327     ! gtksee 0.5.6-1
1328     [29 Jun 2003] DSA-336 linux-kernel-2.2.20 - several vulnerabilities
1329     {CAN-2002-1380 CVE-2002-0429 CAN-2003-0001 CAN-2003-0127 CAN-2003-0364 CAN-2003-0246 CAN-2003-0244 CAN-2003-0247 CAN-2003-0248}
1330     - kernel-source-2.2.25 2.2.25-3
1331     NOTE: did not check newer kernels
1332     [28 Jun 2003] DSA-335 mantis - incorrect permissions
1333     {CAN-2003-0499}
1334     - mantis 0.17.5-6
1335     [28 Jun 2003] DSA-334 xgalaga - buffer overflows
1336     {CAN-2003-0454}
1337     - xgalaga 2.0.34-22
1338     [27 Jun 2003] DSA-333 acm - integer overflow
1339     {CVE-2002-0391}
1340     - acm 5.0-10
1341     [27 Jun 2003] DSA-332 linux-kernel-2.4.17 - several vulnerabilities
1342     {CVE-2002-0429 CAN-2003-0001 CAN-2003-0127 CAN-2003-0244 CAN-2003-0246 CAN-2003-0247 CAN-2003-0248 CAN-2003-0364}
1343     NOTE: note in the archive, and did not check newer kernels
1344     [27 Jun 2003] DSA-331 imagemagick - insecure temporary file
1345     {CAN-2003-0455}
1346     - imagemagick 4:5.5.7-1
1347     [23 Jun 2003] DSA-330 tcptraceroute - failure to drop root privileges
1348     {CAN-2003-0489}
1349     - tcptraceroute 1.4-4
1350     [20 Jun 2003] DSA-329 osh - buffer overflows
1351     {CAN-2003-0452}
1352     - osh 1.7-12
1353     [19 Jun 2003] DSA-328 webfs - buffer overflow
1354     {CAN-2003-0445}
1355     - webfs 1.20
1356     [19 Jun 2003] DSA-327 xbl - buffer overflows
1357     {CAN-2003-0451}
1358     - xbl 1.0k-5
1359     [19 Jun 2003] DSA-326 orville-write - buffer overflows
1360     {CAN-2003-0441}
1361     - orville-write 2.54-1
1362     [19 Jun 2003] DSA-325 eldav - insecure temporary file
1363     {CAN-2003-0438}
1364     - eldav 0.7.2-1
1365     [18 Jun 2003] DSA-324 ethereal - several vulnerabilities
1366     {CAN-2003-0428 CAN-2003-0429 CAN-2003-0431 CAN-2003-0432}
1367     - ethereal 0.9.13-1.
1368     [16 Jun 2003] DSA-323 noweb - insecure temporary files
1369     {CAN-2003-0381}
1370     - noweb 2.10c-2
1371     [16 Jun 2003] DSA-322 typespeed - buffer overflow
1372     {CAN-2003-0435}
1373     - typespeed 0.4.4
1374     [13 Jun 2003] DSA-321 radiusd-cistron - buffer overflow
1375     {CAN-2003-0450}
1376     - radiusd-cistron 1.6.6-2
1377     [13 Jun 2003] DSA-320 mikmod - buffer overflow
1378     {CAN-2003-0427}
1379     - mikmod 3.1.6-6
1380     [12 Jun 2003] DSA-319 webmin - session ID spoofing
1381     {CAN-2003-0101}
1382     - webmin 1.070-1
1383     [12 Jun 2003] DSA-318 lyskom-server - denial of service
1384     {CAN-2003-0366}
1385     - lyskom-server 2.0.7-2
1386     [11 Jun 2003] DSA-317 cupsys - denial of service
1387     {CAN-2003-0195}
1388     - cupsys 1.1.19final-1
1389     [11 Jun 2003] DSA-316 nethack - buffer overflow, incorrect permissions
1390     {CAN-2003-0358 CAN-2003-0359}
1391     - nethack 3.4.1-1
1392     - slashem 0.0.6E4F8-6
1393     - jnethack 1.1.5-15
1394     NOTE: DSA contains some strange non-nethack version numbers
1395     [11 Jun 2003] DSA-315 gnocatan - buffer overflows, denial of service
1396     {CAN-2003-0433}
1397     HELP: no mention of any security fixes in debian changelog,
1398     HELP: upstream changelog. Mailed maintainer.
1399     [11 Jun 2003] DSA-314 atftp - buffer overflow
1400     {CAN-2003-0380}
1401     - atftp 0.6.2
1402     [11 Jun 2003] DSA-313 ethereal - buffer overflows, integer overflows
1403     {CAN-2003-0356 CAN-2003-0357}
1404     - ethereal 0.9.12-1
1405     [09 Jun 2003] DSA-312 kernel-patch-2.4.18-powerpc - several vulnerabilities
1406     {CVE-2002-0429 CAN-2003-0001 CAN-2003-0127 CAN-2003-0244 CAN-2003-0246 CAN-2003-0247 CAN-2003-0248}
1407     NOTE: not in unstable/testing. Did not check other versions.
1408     [08 Jun 2003] DSA-311 linux-kernel-2.4.18 - several vulnerabilities
1409     {CVE-2002-0429 CAN-2003-0001 CAN-2003-0127 CAN-2003-0244 CAN-2003-0246 CAN-2003-0247 CAN-2003-0248 CAN-2003-0364}
1410     NOTE: not in unstable/testing. Did not check other versions.
1411     [08 Jun 2003] DSA-310 xaos - improper setuid-root execution
1412     {CAN-2003-0385}
1413     - xaos 3.1r-4
1414     [06 Jun 2003] DSA-309 eterm - buffer overflow
1415     {CAN-2003-0382}
1416     - eterm 0.9.2-1
1417     [06 Jun 2003] DSA-308 gzip - insecure temporary files
1418     {CVE-1999-1332 CAN-2003-0367}
1419     - gzip 1.3.5-6
1420     [27 May 2003] DSA-307 gps - multiple vulnerabilities
1421     {CAN-2003-0361 CAN-2003-0360 CAN-2003-0362}
1422     - gps 1.1.0-1
1423     [19 May 2003] DSA-306 ircii-pana - buffer overflows, integer overflow
1424     {CAN-2003-0321 CAN-2003-0322 CAN-2003-0328}
1425     - ircii-pana 1:1.0-0c19-8
1426     [15 May 2003] DSA-305 sendmail - insecure temporary files
1427     {CAN-2003-0308}
1428     - sendmail 8.12.9-2
1429     [15 May 2003] DSA-304 lv - privilege escalation
1430     {CAN-2003-0188}
1431     - lv 4.49.5-2
1432     [15 May 2003] DSA-303 mysql - privilege escalation
1433     {CAN-2003-0073}
1434     - mysql-dfsg 4.0.12-2
1435     {CAN-2003-0150}
1436     HELP: not sure if this is fixed
1437     [07 May 2003] DSA-302 fuzz - privilege escalation
1438     {CAN-2003-0261}
1439     - fuzz 0.6-7.1
1440     [07 May 2003] DSA-301 libgtop - buffer overflow
1441     {CAN-2001-0928}
1442     - libgtop 1.0.13-4
1443     [06 May 2003] DSA-300 balsa - buffer overflow
1444     {CAN-2003-0167}
1445     - balse 2.0.10
1446     [06 May 2003] DSA-299 leksbot - improper setuid-root execution
1447     {CAN-2003-0262}
1448     - lexbot 1.2-5
1449     [02 May 2003] DSA-298 epic4 - buffer overflows
1450     {CAN-2003-0323}
1451     - epic4 1:1.1.11.20030409-1
1452     [01 May 2003] DSA-297 snort - integer overflow, buffer overflow
1453     {CAN-2003-0033 CAN-2003-0209}
1454     - snort 2.0.0-1
1455     [30 Apr 2003] DSA-296 kdebase - insecure execution
1456     {CAN-2003-0204}
1457     - kdebase 4:3.1.0-1
1458     [30 Apr 2003] DSA-295 pptpd - buffer overflow
1459     {CAN-2003-0213}
1460     - pptpd 1.1.4-0.b3.2
1461     [23 Apr 2003] DSA-294 gkrellm-newsticker - missing quoting, incomplete parser
1462     {CAN-2003-0205 CAN-2003-0206}
1463     NOTE: not in unstable/testing
1464     [23 Apr 2003] DSA-293 kdelibs - insecure execution
1465     {CAN-2003-0204}
1466     - kdebase 4:3.1.0-1
1467     [22 Apr 2003] DSA-292 mime-support - insecure temporary file creation
1468     {CAN-2003-0214}
1469     - mime-support 3.23-1
1470     [22 Apr 2003] DSA-291 ircii - buffer overflows
1471     {CAN-2003-0323}
1472     - ircii 20030315-1
1473     [17 Apr 2003] DSA-290 sendmail-wide - char-to-int conversion
1474     {CAN-2003-0161}
1475     - sendmail-wide 8.12.9+3.5Wbeta-1
1476     [17 Apr 2003] DSA-289 rinetd - incorrect memory resizing
1477     {CAN-2003-0212}
1478     - rinetd 0.61-2
1479     [17 Apr 2003] DSA-288 openssl - several vulnerabilities
1480     {CAN-2003-0147 CAN-2003-0131}
1481     - openssl 0.9.7b-1
1482     - openssl096 0.9.6j-1
1483     [15 Apr 2003] DSA-287 epic - buffer overflows
1484     {CAN-2003-0324}
1485     - epic4 1:1.1.11.20030409-1
1486     [14 Apr 2003] DSA-286 gs-common - insecure temporary file
1487     {CAN-2003-0207}
1488     - gs-common 0.3.3.1
1489     [14 Apr 2003] DSA-285 lprng - insecure temporary file
1490     {CAN-2003-0136}
1491     - lprng 3.8.20-4.
1492     [12 Apr 2003] DSA-284 kdegraphics - insecure execution
1493     {CAN-2003-0204}
1494     - kdegraphics 4:3.1.0-1
1495     [11 Apr 2003] DSA-283 xfsdump - insecure file creation
1496     {CAN-2003-0173}
1497     - xfsdump 2.2.8-1
1498     [09 Apr 2003] DSA-282 glibc - integer overflow
1499     {CAN-2003-0028}
1500     - glibc 2.3.1-16
1501     [08 Apr 2003] DSA-281 moxftp - buffer overflow
1502     {CAN-2003-0203}
1503     - moxftp 2.2-18.20
1504     [07 Apr 2003] DSA-280 samba - buffer overflow
1505     {CAN-2003-0201 CAN-2003-0196}
1506     - samba 3.0
1507     [07 Apr 2003] DSA-279 metrics - insecure temporary file creation
1508     {CAN-2003-0202}
1509     NOTE: note in unstable/testing
1510     [04 Apr 2003] DSA-278 sendmail - char-to-int conversion
1511     {CAN-2003-0161}
1512     - sendmail 8.12.9-1
1513     [03 Apr 2003] DSA-277 apcupsd - buffer overflows, format string
1514     {CAN-2003-0098 CAN-2003-0099}
1515     - apcupsd 3.8.5-1.2
1516     [03 Apr 2003] DSA-276 linux-kernel-s390 - local privilege escalation
1517     {CAN-2003-0127}
1518     NOTE: this version is not in sarge, did not check others
1519     [02 Apr 2003] DSA-275 lpr-ppd - buffer overflow
1520     {CAN-2003-0144}
1521     - lpr-ppd 1:0.72-3
1522     [28 Mar 2003] DSA-274 mutt - buffer overflow
1523     {CAN-2003-0167}
1524     - mutt 1.4.0
1525     [28 Mar 2003] DSA-273 krb4 - Cryptographic weakness
1526     {CAN-2003-0138 CAN-2003-0139}
1527     - krb4 1.2.2-1
1528     [28 Mar 2003] DSA-272 dietlibc - integer overflow
1529     {CAN-2003-0028}
1530     - dietlibc 0.22-2
1531     [27 Mar 2003] DSA-271 ecartis - unauthorized password change
1532     {CAN-2003-0162}
1533     - ecartis 1.0.0+cvs.20030321-1
1534     [27 Mar 2003] DSA-270 linux-kernel-mips - local privilege escalation
1535     {CAN-2003-0127}
1536     NOTE: not in unstable/testing, did not check other versions
1537     [26 Mar 2003] DSA-269 heimdal - Cryptographic weakness
1538     {CAN-2003-0138}
1539     - heimdal 0.5.2-1
1540     [25 Mar 2003] DSA-268 mutt - buffer overflow
1541     {CAN-2003-0140}
1542     - mutt 1.5.4-1
1543     [24 Mar 2003] DSA-267 lpr - buffer overflow
1544     {CAN-2003-0144}
1545     - lpr 1:2000.05.07-4.20
1546     [24 Mar 2003] DSA-266 krb5 - several vulnerabilities
1547     {CAN-2003-0028}
1548     - krb5 1.3.3-2
1549     NOTE: changelog does not mention this one, verified patch from
1550     NOTE: Tom Yu was applied to this version.
1551     {CAN-2003-0072}
1552     - krb5 1.2.7-3
1553     NOTE: changelog does not mention this one, verified patch from
1554     NOTE: upstream was applied to this version.
1555     {CAN-2003-0082}
1556     - krb5 1.3.3-2
1557     {CAN-2003-0138 VU#623217}
1558     - krb5 1.2.7-3
1559     {CAN-2003-0139 VU#442569}
1560     - krb5 1.2.7-3
1561     [21 Mar 2003] DSA-265 bonsai - several vulnerabilities
1562     {CAN-2003-0152 CAN-2003-0153 CAN-2003-0154 CAN-2003-0155}
1563     - bonsai 1.3+cvs20030317-1
1564     [19 Mar 2003] DSA-264 lxr - missing filename sanitizing
1565     {CAN-2003-0156}
1566     - lxr 0.3-4
1567     [17 Mar 2003] DSA-263 netpbm-free - math overflow errors
1568     {CAN-2003-0146}
1569     - netpbm-free 2:9.20-9
1570     [15 Mar 2003] DSA-262 samba - remote exploit
1571     {CAN-2003-0085 CAN-2003-0086}
1572     - samba 2.2.8
1573     [14 Mar 2003] DSA-261 tcpdump - infinite loop
1574     {CAN-2003-0093 CAN-2003-0145}
1575     NOTE: DSA reports sid was not affected, sarge has sid version
1576     [13 Mar 2003] DSA-260 file - buffer overflow
1577     {CAN-2003-0102}
1578     - file 3.40-1.1
1579     [12 Mar 2003] DSA-259 qpopper - mail user privilege escalation
1580     {CAN-2003-0143}
1581     - qpopper 4.0.4-9
1582     [10 Mar 2003] DSA-258 ethereal - format string vulnerability
1583     {CAN-2003-0081}
1584     - ethereal 0.9.9-2
1585     [04 Mar 2003] DSA-257 sendmail - remote exploit
1586     {CAN-2002-1337}
1587     - sendmail 8.12.8
1588     [28 Feb 2003] DSA-256 mhc - insecure temporary file
1589     {CAN-2003-0120}
1590     - mhc 0.25+20030224-1
1591     [27 Feb 2003] DSA-255 tcpdump - infinite loop
1592     {CAN-2003-0108 CAN-2002-0380}
1593     - tcpdump 3.7.1-1.2
1594     [27 Feb 2003] DSA-254 traceroute-nanog - buffer overflow
1595     {CAN-2002-1051 CAN-2002-1364 CAN-2002-1386 CAN-2002-1387}
1596     - traceroute-nanog 6.3.0-1
1597     [24 Feb 2003] DSA-253 openssl - information leak
1598     {CAN-2003-0078}
1599     - openssl 0.9.7a-1
1600     [21 Feb 2003] DSA-252 slocate - buffer overflow
1601     {CAN-2003-0056}
1602     - slocate 2.7-1
1603     [14 Feb 2003] DSA-251 w3m - missing HTML quoting
1604     {CAN-2002-1335 CAN-2002-1348}
1605     - w3m 0.3.2.2-1
1606     [12 Feb 2003] DSA-250 w3mmee-ssl - missing HTML quoting
1607     {CAN-2002-1335 CAN-2002-1348}
1608     NOTE: not in sid/sarge
1609     [11 Feb 2003] DSA-249 w3mmee - missing HTML quoting
1610     {CAN-2002-1335 CAN-2002-1348}
1611     - w3mmee 0.3.p24.17-3
1612     [31 Jan 2003] DSA-248 hypermail - buffer overflows
1613     {CAN-2003-0057}
1614     - hypermail 2.1.6-1
1615     [30 Jan 2003] DSA-247 courier-ssl - missing input sanitizing
1616     {CAN-2003-0040}
1617     - courier 0.40.2-3
1618     [29 Jan 2003] DSA-246 tomcat - information exposure, cross site scripting
1619     {CAN-2003-0042 CAN-2003-0043 CAN-2003-0044}
1620     NOTE: tomcat not in sid/sarge
1621     NOTE: tomcat4 not affected
1622     [28 Jan 2003] DSA-245 dhcp3 - ignored counter boundary
1623     {CAN-2003-0039}
1624     - dhcp3 1.1.2-1
1625     [27 Jan 2003] DSA-244 noffle - buffer overflows
1626     {CAN-2003-0037}
1627     - noffle 1.1.2-1
1628     [24 Jan 2003] DSA-243 kdemultimedia - several vulnerabilities
1629     {CAN-2002-1393}
1630     - kdemultimedia 4:3.1
1631     [24 Jan 2003] DSA-242 kdebase - several vulnerabilities
1632     {CAN-2002-1393}
1633     - kdebase 4:3.1
1634     [24 Jan 2003] DSA-241 kdeutils - several vulnerabilities
1635     {CAN-2002-1393}
1636     - kdeutils 4:3.1
1637     [23 Jan 2003] DSA-240 kdegames - several vulnerabilities
1638     {CAN-2002-1393}
1639     - kdegames 4:3.1
1640     [23 Jan 2003] DSA-239 kdesdk - several vulnerabilities
1641     {CAN-2002-1393}
1642     - kdesdk 4:3.1
1643     [23 Jan 2003] DSA-238 kdepim - several vulnerabilities
1644     {CAN-2002-1393}
1645     - kdepim 4:3.1
1646     [22 Jan 2003] DSA-237 kdenetwork - several vulnerabilities
1647     {CAN-2002-1393}
1648     - kdenetwork 4:3.1
1649     [22 Jan 2003] DSA-236 kdelibs - several vulnerabilities
1650     {CAN-2002-1393}
1651     - kdelibs 4:3.1
1652     [22 Jan 2003] DSA-235 kdegraphics - several vulnerabilities
1653     {CAN-2002-1393}
1654     - kdegraphics 4:3.1
1655     [22 Jan 2003] DSA-234 kdeadmin - several vulnerabilities
1656     {CAN-2002-1393}
1657     - kdeadmin 4:3.1
1658     [21 Jan 2003] DSA-233 cvs - doubly freed memory
1659     {CAN-2003-0015}
1660     - cvs 1.11.2-5.1
1661     [20 Jan 2003] DSA-232 cupsys - several vulnerabilities
1662     {CAN-2002-1366 CAN-2002-1367 CAN-2002-1368 CAN-2002-1369 CAN-2002-1371 CAN-2002-1372 CAN-2002-1383 CAN-2002-1384}
1663     - cupsys 1.1.18-1
1664     [17 Jan 2003] DSA-231 dhcp3 - stack overflows
1665     {CAN-2003-0026}
1666     - dhcp3 3.0+3.0.1rc11-1
1667     [16 Jan 2003] DSA-230 bugzilla - insecure permissions, spurious backup files
1668     NOTE: not in testing due to 3 newer security holes
1669     {CAN-2003-0012}
1670     - bugzilla 2.16.2
1671     {CAN-2003-0013}
1672     - bugzilla 2.16.2
1673     [15 Jan 2003] DSA-229 imp - SQL injection
1674     {CAN-2003-0025}
1675     NOTE: I think imp3 is ok.
1676     [14 Jan 2003] DSA-228 libmcrypt - buffer overflows and memory leak
1677     {CAN-2003-0031 CAN-2003-0032}
1678     - libmcrypt 2.5.5-1
1679     [13 Jan 2003] DSA-227 openldap2 - buffer overflows and other bugs
1680     {CAN-2002-1378 CAN-2002-1379 CAN-2002-1508}
1681     - openldap2 2.0.27-3
1682     [10 Jan 2003] DSA-226 xpdf-i - integer overflow
1683     {CAN-2002-1384}
1684     - xpdf 2.01-2
1685     [09 Jan 2003] DSA-225 tomcat4 - source disclosure
1686     {CAN-2002-1394}
1687     ! tomcat4 4.1.16-1
1688     NOTE another RC (unreproducible?) bug and missing deps (#263201)
1689     NOTE are keeping the fix out of testing
1690     NOTE this is the second unfixed security hole in tomcat4 in testing..
1691     [08 Jan 2003] DSA-224 canna - buffer overflow and more
1692     {CAN-2002-1158 CAN-2002-1159}
1693     - canna 3.6p1-1
1694     [07 Jan 2003] DSA-223 geneweb - information exposure
1695     {CAN-2002-1390}
1696     - geneweb 4.09-1
1697     [06 Jan 2003] DSA-222 xpdf - integer overflow
1698     {CAN-2002-1384}
1699     - xpdf 2.01-2
1700     [03 Jan 2003] DSA-221 mhonarc - cross site scripting
1701     {CAN-2002-1388}
1702     - mhonarc 2.5.14-1
1703     [02 Jan 2003] DSA-220 squirrelmail - cross site scripting
1704     {CAN-2002-1341}
1705     - squirrelmail 1:1.3.2-2
1706    
1707     ------- These processed by Djoumé SALVETTI <salvetti@crans.org> -----
1708    
1709     [31 Dec 2002] DSA-219 dhcpcd - remote command execution
1710     {CAN-2002-1403}
1711     - dhcpcd 1.3.22pl2-2
1712     [30 Dec 2002] DSA-218 bugzilla - cross site scripting
1713     NOTE: not in testing, fixed in unstable (bugzilla 2.16.2-1).
1714     [27 Dec 2002] DSA-217 typespeed - buffer overflow
1715     {CAN-2002-1389}
1716     - typespeed 0.4.2-2
1717     [24 Dec 2002] DSA-216 fetchmail - buffer overflow
1718     {CAN-2002-1365}
1719     - fetchmail 6.2.0-1
1720     [23 Dec 2002] DSA-215 cyrus-imapd - buffer overflow
1721     {CAN-2002-1580}
1722     - cyrus-imapd 1.5.19-9.10
1723     [20 Dec 2002] DSA-214 kdnetwork - buffer overflows
1724     {CAN-2002-1306}
1725     - kdenetwork 2.2.2-14.20
1726     NOTE: there is a typo in the DSA, the name of the package is kdenetwork.
1727     [19 Dec 2002] DSA-213 libpng - buffer overflow
1728     {CAN-2002-1363}
1729     - libpng 1.0.12-7
1730     - libpng3 1.2.5-8
1731     [17 Dec 2002] DSA-212 mysql - multiple problems
1732     {CAN-2002-1373 CAN-2002-1374 CAN-2002-1375 CAN-2002-1376}
1733     - mysql-dfsg 4.0.7.gamma-1
1734     [13 Dec 2002] DSA-211 micq - denial of service
1735     {CAN-2002-1362}
1736     NOTE: not in testing nor unstable (was fixed in 0.4.9.4-1)
1737     [13 Dec 2002] DSA-210 lynx - CRLF injection
1738     {CAN-2002-1405}
1739     - lynx 2.8.4.1b-4
1740     NOTE: lynx-ssl not in testing nor unstable.
1741     [12 Dec 2002] DSA-209 wget - directory traversal
1742     {CAN-2002-1344}
1743     - wget 1.8.2-8
1744     [12 Dec 2002] DSA-208 perl - broken safe compartment
1745     {CAN-2002-1323}
1746     - perl 5.8.0-14
1747     [11 Dec 2002] DSA-207 tetex-bin - arbitrary command execution
1748     {CAN-2002-0836}
1749     - tetex-bin 1.0.7+20021025-4
1750     [10 Dec 2002] DSA-206 tcpdump - denial of service
1751     {CAN-2002-1350}
1752     - tcpdump 3.7.2-1
1753     [10 Dec 2002] DSA-205 gtetrinet - buffer overflow
1754     - gtetrinet 0.4.4-1
1755     NOTE: no CAN not CVE for this one
1756     [05 Dec 2002] DSA-204 kdelibs - arbitrary program execution
1757     {CAN-2002-1281 CAN-2002-1282}
1758     - kdelibs 4:3.1.0-1
1759     [04 Dec 2002] DSA-203 smb2www - arbitrary command execution
1760     {CAN-2002-1342}
1761     - smb2www 980804-17
1762     [03 Dec 2002] DSA-202 im - insecure temporary files
1763     {CAN-2002-1395}
1764     - im 141-20
1765     [02 Dec 2002] DSA-201 freeswan - denial of service
1766     {CAN-2002-0666 VU#459371}
1767     - freeswan 1.99-1
1768     [22 Nov 2002] DSA-200 samba - remote exploit
1769     {CAN-2002-1318}
1770     - samba 2.99.cvs.20020713-1
1771     [19 Nov 2002] DSA-199 mhonarc - cross site scripting
1772     {CAN-2002-1307}
1773     - mhonarc 2.5.13-1
1774     [18 Nov 2002] DSA-198 nullmailer - denial of service
1775     {CAN-2002-1313}
1776     - nullmailer 1.00RC5-17
1777     [15 Nov 2002] DSA-197 courier - buffer overflow
1778     {CAN-2002-1311}
1779     - courier 0.40.0-1
1780     [14 Nov 2002] DSA-196 bind - several vulnerabilities
1781     {CAN-2002-0029 CAN-2002-1219 CAN-2002-1220 CAN-2002-1221}
1782     - bind 8.3.3-3
1783     [13 Nov 2002] DSA-195 apache-perl - several vulnerabilities
1784     {CAN-2002-0839 CAN-2002-0840 CAN-2002-0843 CAN-2001-0131 CAN-2002-1233}
1785     - apache-perl 1.3.26-1.1-1.27-3-1
1786     [12 Nov 2002] DSA-194 masqmail - buffer overflows
1787     {CAN-2002-1279}
1788     - masqmail 0.2.15-1
1789     [11 Nov 2002] DSA-193 kdenetwork - buffer overflow
1790     {CAN-2002-1247}
1791     - kdenetwok 2.2.2-14.3
1792     [08 Nov 2002] DSA-192 html2ps - arbitrary code execution
1793     {CAN-2002-1275}
1794     - html2ps 1.0b3-2
1795     [07 Nov 2002] DSA-191 squirrelmail - cross site scripting
1796     {CAN-2002-1131 CAN-2002-1132 CAN-2002-1276}
1797     - squirrelmail 1.2.8-1.1
1798     [07 Nov 2002] DSA-190 wmaker - buffer overflow
1799     {CAN-2002-1277}
1800     - wmaker 0.80.1-4
1801     [06 Nov 2002] DSA-189 luxman - local root exploit
1802     {CAN-2002-1245}
1803     - luxman 0.41-19
1804     [05 Nov 2002] DSA-188 apache-ssl - several vulnerabilities
1805     {CAN-2002-0839 CAN-2002-0840 CAN-2002-0843}
1806     - apache 1.3.27-0.1
1807     {CAN-2001-0131 CAN-2002-1233}
1808     - apache 1.3.27-1
1809     HELP: note sure about this
1810     NOTE: I have mailed maintainers
1811     {NO-CAN Several buffer overflows in ApacheBench}
1812     HELP: I don't know about this
1813     NOTE: I have mailed maintainers
1814     [04 Nov 2002] DSA-187 apache - several vulnerabilities
1815     {CAN-2002-0839 CAN-2002-0840 CAN-2002-0843}
1816     - apache 1.3.27-0.1
1817     {CAN-2001-0131 CAN-2002-1233}
1818     - apache 1.3.27-1
1819     HELP: note sure about this
1820     NOTE: I have mailed maintainers
1821     {NO-CAN Several buffer overflows in ApacheBench}
1822     HELP: I don't know about this
1823     NOTE: I have mailed maintainers
1824     [01 Nov 2002] DSA-186 log2mail - buffer overflow
1825     {CAN-2002-1251}
1826     - log2mail 0.2.6-1
1827     [31 Oct 2002] DSA-185 heimdal - buffer overflow
1828     {CAN-2002-1235}
1829     - heimdal 0.4e-22
1830     [30 Oct 2002] DSA-184 krb4 - buffer overflow
1831     {CAN-2002-1235}
1832     - krb4 1.1-11-8
1833     [29 Oct 2002] DSA-183 krb5 - buffer overflow
1834     {CAN-2002-1235}
1835     - krb5 1.2.6-2
1836     [28 Oct 2002] DSA-182 kdegraphics - buffer overflow
1837     {CAN-2002-0838}
1838     - kdegraphics 2.2.2-6.9
1839     [22 Oct 2002] DSA-181 libapache-mod-ssl - cross site scripting
1840     {CAN-2002-1157}
1841     - libapache-mod-ssl 2.8.9-2.3
1842     [21 Oct 2002] DSA-180 nis - information leak
1843     {CAN-2002-1232}
1844     - nis 3.9-6.2
1845     [18 Oct 2002] DSA-179 gnome-gv - buffer overflow
1846     {CAN-2002-0838}
1847     - gnome-gv 1.99.7-9
1848     [17 Oct 2002] DSA-178 heimdal - remote command execution
1849 joeyh 164 {CAN-2002-1225 CAN-2002-1226}
1850 joeyh 2 - heimdal 0.4e-21
1851     [17 Oct 2002] DSA-177 pam - serious security violation
1852     {CAN-2002-1227}
1853     - pam 0.76-6
1854     [16 Oct 2002] DSA-176 gv - buffer overflow
1855     {CAN-2002-0838}
1856     - gv 3.5.8-27
1857     [15 Oct 2002] DSA-175 syslog-ng - buffer overflow
1858     {CAN-2002-1200}
1859     - syslog-ng 1.5.21-1
1860     [14 Oct 2002] DSA-174 heartbeat - buffer overflow
1861     {CAN-2002-1215}
1862     - heartbeat 0.4.9.2-1
1863     [09 Oct 2002] DSA-173 bugzilla - privilege escalation
1864     {CAN-2002-1196}
1865     NOTE: not in testing, fixed in unstable (bugzilla 2.16.0-2.1)
1866     [08 Oct 2002] DSA-172 tkmail - insecure temporary files
1867     {CAN-2002-1193}
1868     NOTE: not in testing nor unstable (was fixed in 4.0beta9-9)
1869     [07 Oct 2002] DSA-171 fetchmail - buffer overflows
1870 joeyh 164 {CAN-2002-1175 CAN-2002-1174}
1871 joeyh 2 - fetchmail 6.1.0-1
1872     NOTE: fetchmail-ssl not in testing, fixed in unstable (fetchmail-ssl 6.1.0-1)
1873     [04 Oct 2002] DSA-170 tomcat4 - source code disclosure
1874     {CAN-2002-1148}
1875     ! tomcat4 4.1.12-1
1876     NOTE: only 4.0.4-4 in testing (which seems to be vulnerable)
1877     [25 Sep 2002] DSA-169 htcheck - cross site scripting
1878     {CAN-2002-1195}
1879     - htcheck 1.1-1.2
1880     [18 Sep 2002] DSA-168 php - bypassing safe_mode, CRLF injection
1881     {CAN-2002-0985 CAN-2002-0986}
1882     - php3 3.0.18-23.2
1883     - php4 4.2.3-3
1884     NOTE: php3 is not in testing, it seems to be wait for tiff and gcc transition
1885     NOTE: and is out of date on alpha and arm
1886     [16 Sep 2002] DSA-167 kdelibs - cross site scripting
1887     {CAN-2002-1151}
1888     - kdelibs 2.2.2-14
1889     NOTE: there is a typo in the DSA that mentionned Konquerer instead of kdelibs
1890     [13 Sep 2002] DSA-166 purity - buffer overflows
1891     {CAN-2002-1124}
1892     - purity 1-16
1893     [12 Sep 2002] DSA-165 postgresql - buffer overflows
1894     {CAN-2002-0972 CAN-2002-1398 CAN-2002-1400 CAN-2002-1401 CVE-2002-1402}
1895     - postgresql 7.2.2-2
1896     [10 Sep 2002] DSA-164 cacti - arbitrary code execution
1897     {CAN-2002-1477 CAN-2002-1478}
1898     - cacti 0.6.8a-2
1899     [09 Sep 2002] DSA-163 mhonarc - cross site scripting
1900     {CVE-2002-0738}
1901     - mhonarc 2.5.11-1
1902     [06 Sep 2002] DSA-162 ethereal - buffer overflow
1903     {CAN-2002-0834}
1904     - ethereal 0.9.6-1
1905     [04 Sep 2002] DSA-161 mantis - privilege escalation
1906     {CAN-2002-1115 CAN-2002-1116}
1907     - mantis 0.17.5-2
1908     [03 Sep 2002] DSA-160 scrollkeeper - insecure temporary file creation
1909     {CAN-2002-0662}
1910     - scrollkeeper 0.3.11-2
1911     [28 Aug 2002] DSA-159 python - insecure temporary files
1912     {CAN-2002-1119}
1913     - python2.1 2.1.3-6a
1914     - python2.2 2.2.1-8
1915     NOTE: python1.5 not in testing nor unstable (was fixed in 1.5.2-24)
1916     NOTE: python2.3 is not vulnerable
1917     [27 Aug 2002] DSA-158 gaim - arbitrary program execution
1918     {CVE-2002-0989}
1919     - gaim 0.59.1-2
1920     [23 Aug 2002] DSA-157 irssi-text - denial of service
1921     {CAN-2002-0983}
1922     - irssi-text 0.8.5-2
1923     [22 Aug 2002] DSA-156 epic4-script-light - arbitrary script execution
1924     {CVE-2002-0984}
1925     - epic4-script-light 2.7.30p5-2
1926     [17 Aug 2002] DSA-155 kdelibs - privacy escalation with Konqueror
1927     {CAN-2002-0970}
1928     - kdelibs 4:2.2.2-14
1929     [15 Aug 2002] DSA-154 fam - privilege escalation
1930     {CVE-2002-0875}
1931     - fam 2.6.8-1
1932     [14 Aug 2002] DSA-153 mantis - cross site code execution and privilege escalation
1933     {CAN-2002-1114 CAN-2002-1113 CAN-2002-1112 CAN-2002-1111 CAN-2002-1110}
1934     - mantis 0.17.4a-2
1935     [13 Aug 2002] DSA-152 l2tpd - missing random seed
1936     {CVE-2002-0872 CVE-2002-0873}
1937     NOTE: not in testing (was fixed in unstable 0.68-1)
1938     [13 Aug 2002] DSA-151 xinetd - pipe exposure
1939     {CVE-2002-0871}
1940     - xinetd 2.3.7-1
1941     [13 Aug 2002] DSA-150 interchange - illegal file exposition
1942     {CAN-2002-0874}
1943     - interchange 4.8.6-1
1944     [13 Aug 2002] DSA-149 glibc - integer overflow
1945     {CVE-2002-0391}
1946     - glibc 2.2.5-13
1947     [12 Aug 2002] DSA-148 hylafax - buffer overflows and format string vulnerabilities
1948     {CVE-2002-1049 CVE-2002-1050 CAN-2001-1034}
1949     - hylafax 4.1.2-2.1
1950     [08 Aug 2002] DSA-147 mailman - cross-site scripting
1951     {CAN-2002-0388 CAN-2002-0855}
1952     - mailman 2.0.12-1
1953     [08 Aug 2002] DSA-146 dietlibc - integer overflow
1954     {CVE-2002-0391}
1955     - dietlibc 0.20-0cvs20020808
1956     [07 Aug 2002] DSA-145 tinyproxy - doubly freed memory
1957     {CVE-2002-0847}
1958     - tinyproxy 1.4.3-3
1959     [06 Aug 2002] DSA-144 wwwoffle - improper input handling
1960     {CVE-2002-0818}
1961     - wwwoffle 2.7d-1
1962     [05 Aug 2002] DSA-143 krb5 - integer overflow
1963     {CVE-2002-0391}
1964     - krb5 1.2.5-2
1965     [05 Aug 2002] DSA-142 openafs - integer overflow
1966     {CVE-2002-0391}
1967     - openafs 1.2.6-1
1968     [01 Aug 2002] DSA-141 mpack - buffer overflow
1969     {CAN-2002-1425}
1970     - mpack 1.5-9
1971     [05 Aug 2002] DSA-140 libpng - buffer overflow
1972     {CAN-2002-0660 CAN-2002-0728}
1973     - libpng 1.0.12-4
1974     - libpng3 1.2.1-2
1975     [01 Aug 2002] DSA-139 super - format string vulnerability
1976     {CVE-2002-0817}
1977     - super 3.18.0-3
1978     [01 Aug 2002] DSA-138 gallery - remote exploit
1979     {CAN-2002-1412}
1980     - gallery 1.3-3
1981     [30 Jul 2002] DSA-137 mm - insecure temporary files
1982     {CVE-2002-0658}
1983     - mm 1.1.3-7
1984     [30 Jul 2002] DSA-136 openssl - multiple remote exploits
1985     {CAN-2002-0655 CAN-2002-0656 CAN-2002-0657 CAN-2002-0659}
1986     - openssl 0.9.6e-1

  ViewVC Help
Powered by ViewVC 1.1.5