/[secure-testing]/data/DSA/list
ViewVC logotype

Contents of /data/DSA/list

Parent Directory Parent Directory | Revision Log Revision Log


Revision 344 - (show annotations) (download)
Fri Feb 4 21:05:59 2005 UTC (8 years, 3 months ago) by joeyh
Original Path: sarge-checks/DSA/list
File size: 61435 byte(s)
kernel updates and python2.1 ok.
1 [04 Feb 2005] DSA-667-1 postgresql - privilege escalation
2 NOTE: no CAN given
3 - postgresql 7.4.7-1
4 NOTE: not fixed in testing at time of DSA
5 [04 Feb 2005] DSA-667-1 squid - several
6 {CAN-2005-0173 CAN-2005-0175 CAN-2005-0194 CAN-2005-0211}
7 - squid 2.5.7-7
8 NOTE: not fixed in testing at time of DSA
9 [04 Feb 2005] DSA-666-1 python2.2 - design flaw
10 {CAN-2005-0089}
11 - python2.2 2.2.3-14
12 - python2.3 2.3.4-20
13 - python2.4 2.4-5
14 NOTE: not fixed in testing at time of DSA
15 [04 Feb 2005] DSA-665-1 ncpfs - missing privilege release
16 {CAN-2005-0013}
17 - ncpfs (unfixed; bug #293446)
18 NOTE: not fixed in testing at time of DSA
19 [02 Feb 2005] DSA-664-1 cpio - broken file permissions
20 {CAN-1999-1572}
21 - cpio (unfixed; bug #293379)
22 NOTE: not fixed in testing at time of DSA
23 [02 Feb 2005] DSA-663-1 prozilla - buffer overflows
24 {CAN-2004-1120}
25 - prozilla 1.3.7.3-1
26 NOTE: fixed in testing at time of DSA
27 [01 Feb 2005] DSA-662-1 squirrelmail - several
28 {CAN-2005-0104 CAN-2005-0152}
29 NOTE: CAN-2005-0152 only exists in 1.2.6 version
30 - squirrelmail 1.4.4
31 NOTE: fixed in testing at time of DSA
32 [27 Jan 2005] DSA-661-1 f2c - insecure temporary files
33 {CAN-2005-0017 CAN-2005-0018}
34 - f2c 20020621-3.1
35 NOTE: not fixed in testing at time of DSA
36 [26 Jan 2005] DSA-660-1 kdebase - missing return value check
37 {CAN-2005-0078}
38 - kdebase 4:3.0.5
39 NOTE: fixed in testing at time of DSA
40 [26 Jan 2005] DSA-659-1 libpam-radius-auth - information leak, integer underflow
41 {CAN-2004-1340 CAN-2005-0108}
42 - libpam-radius-auth 1.3.16-3
43 NOTE: 1/2 fixed in testing at time of DSA
44 [25 Jan 2005] DSA-658-1 libdbi-perl - insecure temporary file
45 {CAN-2005-0077}
46 - libdbi-perl 1.46-6
47 NOTE: not fixed in testing at time of DSA
48 [25 Jan 2005] DSA-657-1 xine-lib - buffer overflow
49 {CAN-2004-1379}
50 - xine-lib 1-rc6a-1
51 NOTE: fixed in testing at time of DSA
52 [25 Jan 2005] DSA-656-1 vdr - insecure file access
53 {CAN-2005-0071}
54 - vdr 1.2.6-6
55 NOTE: not fixed in testing at time of DSA
56 [25 Jan 2005] DSA-655-1 zhcon - missing privilege release
57 {CAN-2005-0072}
58 - zhcon 1:0.2.3-8.1
59 NOTE: not fixed in testing at time of DSA
60 [21 Jan 2005] DSA-654-1 enscript - several
61 {CAN-2004-1184 CAN-2004-1185 CAN-2004-1186}
62 - enscript 1.6.4-6
63 NOTE: not fixed in testing at time of DSA
64 [21 Jan 2005] DSA-653-1 ethereal - buffer overflow
65 {CAN-2005-0084}
66 - ethereal 0.10.9-1
67 NOTE: not fixed in testing at time of DSA
68 [21 Jan 2005] DSA-652-1 unarj
69 {CAN-2004-0947 CAN-2004-1027}
70 NOTE: not-for-us (unarj)
71 [20 Jan 2005] DSA-651-1 squid - buffer overflow, integer overflow
72 {CAN-2005-0094 CAN-2005-0095}
73 - squid 2.5.7-4
74 NOTE: not fixed in testing at time of DSA
75 [20 Jan 2005] DSA-650-1 sword - missing input sanitising
76 {CAN-2005-0015}
77 - sword 1.5.7-7
78 NOTE: not fixed in testing at time of DSA
79 [20 Jan 2005] DSA-649-1 xtrlock - buffer overflow
80 {CAN-2005-0079}
81 - xtrlock 2.0-9
82 NOTE: fixed in testing at time of DSA
83 [19 Jan 2005] DSA-648-1 xpdf - buffer overflow
84 {CAN-2005-0064}
85 - xpdf 3.00-12
86 NOTE: not fixed in testing at time of DSA
87 [19 Jan 2005] DSA-647-1 mysql - insecure temporary files
88 {CAN-2005-0004}
89 - mysql-dfsg 4.0.23-3
90 - mysql-dfsg-4.1 4.1.8a-6
91 NOTE: not fixed in testing at time of DSA
92 [19 Jan 2005] DSA-646-1 imagemagick - buffer overflow
93 {CAN-2005-0005}
94 - imagemagick 6.0.6.2-2
95 NOTE: not fixed in testing at time of DSA
96 [19 Jan 2005] DSA-645-1 cupsys - buffer overflow
97 {CAN-2005-0064}
98 NOTE: cupsys not affected in sarge, though other programs are vulnerable
99 NOTE: see CAN/list
100 NOTE: not fixed in testing at time of DSA
101 [18 Jan 2005] DSA-644-1 chbg - buffer overflow
102 {CAN-2004-1264}
103 - chbg 1.5-4
104 NOTE: fixed in testing at time of DSA
105 [18 Jan 2005] DSA-643-1 queue - buffer overflows
106 {CAN-2004-0555}
107 - queue 1.30.1-5
108 NOTE: not fixed in testing at time of DSA
109 [17 Jan 2005] DSA-642-1 gallery - several
110 {CAN-2004-1106}
111 - gallery 1.4.4-pl4-1
112 NOTE: fixed in testing at time of DSA
113 [17 Jan 2005] DSA-641-1 playmidi - buffer overflow
114 {CAN-2005-0020}
115 - playmidi 2.4debian-3
116 NOTE: not fixed in testing at time of DSA
117 [17 Jan 2005] DSA-640-1 gatos - buffer overflow
118 {CAN-2005-0016}
119 - gatos 0.0.5-15
120 NOTE: not fixed in testing at time of DSA
121 [14 Jan 2005] DSA-639-1 mc - several
122 {CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176}
123 NOTE: unstable not vulnerable according to dsa
124 NOTE: fixed in testing at time of DSA
125 [13 Jan 2005] DSA-638-1 gopher - several
126 {CAN-2004-0560 CAN-2004-0561}
127 NOTE: not in sarge
128 [13 Jan 2005] DSA-637-1 exim-tls - buffer overflow
129 {CAN-2005-0021}
130 NOTE: not in sarge
131 [12 Jan 2005] DSA-636-1 glibc - insecure temporary files
132 {CAN-2004-0968}
133 - glibc 2.3.2.ds1-20
134 NOTE: fixed in testing at time of DSA
135 [12 Jan 2005] DSA-635-1 exim - buffer overflow
136 {CAN-2005-0021}
137 - exim4 4.34-10
138 NOTE: fixed in testing at time of DSA
139 - exim 3.36-13
140 NOTE: not fixed in testing at time of DSA
141 [11 Jan 2005] DSA-634-1 hylafax - weak hostname and username validation
142 {CAN-2004-1182}
143 - hylafax 4.2.1-1
144 NOTE: fixed in testing at time of DSA
145 [11 Jan 2005] DSA-633-1 bmv - insecure temporary file
146 {CAN-2003-0014}
147 - bmv 1.2-17
148 NOTE: fixed in testing at time of DSA
149 [10 Jan 2005] DSA-632-1 linpopup - buffer overflow
150 {CAN-2004-1282}
151 - linpopup 1.2.0-7
152 NOTE: fixed in testing at time of DSA
153 [10 Jan 2005] DSA-631-1 kdelibs - unsanitised input
154 {CAN-2004-1165}
155 - kdelibs 4:3.3.2-1
156 NOTE: not fixed in testing at time of DSA
157 [10 Jan 2005] DSA-630-1 lintian - insecure temporary directory
158 {CAN-2004-1000}
159 - lintian 1.23.6
160 NOTE: not fixed in testing at time of DSA
161 [07 Jan 2005] DSA-629-1 krb5 - buffer overflow
162 {CAN-2004-1189}
163 - krb5 1.3.6-1
164 NOTE: not fixed in testing at time of DSA
165 [06 Jan 2005] DSA-628-1 imlib2 - integer overflows
166 {CAN-2004-1026}
167 - imlib2 1.1.2-2.1
168 NOTE: not fixed in testing at time of DSA
169 [06 Jan 2005] DSA-627-1 namazu2 - unsanitised input
170 {CAN-2004-1318}
171 - namazu2 2.0.14-1
172 NOTE: not fixed in testing at time of DSA
173 [06 Jan 2005] DSA-626-1 tiff - unsanitised input
174 {CAN-2004-1183}
175 - libtiff4 3.6.1-5
176 NOTE: not fixed in testing at time of DSA
177 [05 Jan 2005] DSA-625-1 pcal - buffer overflows
178 {CAN-2004-1289}
179 - pcal 4.8.0-1
180 NOTE: not fixed in testing at time of DSA
181 [05 Jan 2005] DSA-624-1 zip - buffer overflow
182 {CAN-2004-1010}
183 - zip 2.30-8
184 NOTE: fixed in testing at time of DSA
185 [04 Jan 2005] DSA-623-1 nasm - buffer overflow
186 {CAN-2004-1287}
187 - nasm 0.98.38-1.1
188 [03 Jan 2005] DSA-622-1 htmlheadline - insecure temporary files
189 {CAN-2004-1181}
190 NOTE: not in unstable
191 [31 Dec 2004] DSA-621-1 cupsys - buffer overflow
192 {CAN-2004-1125}
193 - cupsys 1.1.22-2
194 [30 Dec 2004] DSA-620-1 perl - insecure temporary files / directories
195 {CAN-2004-0452 CAN-2004-0976}
196 - perl 5.8.4-5
197 [30 Dev 2004] DSA-619-1 xpdf - buffer overflow
198 {CAN-2004-1125}
199 - xpdf 3.00-11
200 [24 Dec 2004] DSA-618-1 imlib - buffer overflows, integer overflows
201 {CAN-2004-1025 CAN-2004-1026}
202 - imlib 1.9.14-17.1
203 - imlib-png2 1.9.14-16.1
204 [24 Dec 2004] DSA-617-1 libtiff - insufficient input validation
205 {CAN-2004-1308}
206 - libtiff4 3.6.1-4
207 [23 Dec 2004] DSA-616-1 telnetd-ssl - format string
208 {CAN-2004-0998}
209 - telnetd-ssl 0.17.24+0.1-6
210 [22 Dec 2004] DSA-615-1 debmake - insecure temporary file
211 {CAN-2004-1179}
212 - debmake 3.7.7
213 [21 Dec 2004] DSA-614-1 xzgv - integer overflows
214 {CAN-2004-0994}
215 - xzgv 0.8-3
216 [21 Dec 2004] DSA-613-1 ethereal - inifinite loop
217 {CAN-2004-114}
218 - ethereal 0.10.8-1
219 [21 Dec 2004] DSA-614-1 xzgv - integer overflows
220 {CAN-2004-0994}
221 - xzgv 0.8-3
222 [20 Dec 2004] DSA-612-1 a2ps - unsanitised input
223 {CAN-2004-1170}
224 - a2ps 4.13b-4.2
225 [20 Dec 2004] DSA-611-1 htget - buffer overflow
226 {CAN-2004-0852}
227 NOTE: htget not in sarge or unstable
228 [17 Dec 2004] DSA-610-1 cscope - insecure temporary file
229 {CAN-2004-0996}
230 - cscope 15.5-1
231 [14 Dec 2004] DSA-609-1 atari800 - buffer overflows
232 {CAN-2004-1076}
233 - atari800 1.3.2-1
234 [14 Dec 2004] DSA-608-1 zgv - integer overflows, unsanitised input
235 {CAN-2004-1095 CAN-2004-0999}
236 - zgv 5.7-1.3
237 NOTE: changelog says he only patched 1095, but diff comparison
238 NOTE: shows 0999 was also fixed.
239 [10 Dec 2004] DSA-607-1 xfree86 - several
240 {CAN-2004-0914}
241 - xfree86 4.3.0.dfsg.1-9
242 [08 Dec 2004] DSA-606-1 nfs-utils - wrong signal handler
243 {CAN-2004-1014}
244 - nfs-utils 1:1.0.6-3.1
245 [06 Dec 2004] DSA-605-1 viewcvs - settings not honored
246 {CAN-2004-0915}
247 - viewcvs 0.9.2+cvs.1.0.dev.2004.07.28-1.2
248 [03 Dec 2004] DSA-604-1 hpsockd - missing input sanitising
249 {CAN-2004-0993}
250 - hpsockd 0.14
251 [01 Dec 2004] DSA-603-1 openssl - insecure temporary file
252 {CAN-2004-0975}
253 - openssl 0.9.7e-1
254 [29 Nov 2004] DSA-602-1 libgd2 - integer overlow
255 {CAN-2004-0941 CAN-2004-0990}
256 NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
257 - libgd2 2.0.33-1.1
258 [29 Nov 2004] DSA-601-1 libgd1 - integer overflow
259 {CAN-2004-0941 CAN-2004-0990}
260 NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
261 - libgd 1.8.4-36.1
262 [25 Nov 2004] DSA-599-1 tetex-bin - integer overflows
263 {CAN-2004-0888}
264 - tetex-bin 2.0.2-23
265 [25 Nov 2004] DSA-598-1 yardradius - buffer overflow
266 {CAN-2004-0987}
267 - yardradius 1.0.20-15
268 [25 Nov 2004] DSA-597-1 cyrus-imapd - buffer overflow
269 {CAN-2004-1012 CAN-2004-1013}
270 - cyrus21-imapd 2.1.17-1
271 [24 Nov 2004] DSA-596-2 sudo - missing input sanitising
272 {CAN-2004-1051}
273 - sudo 1.6.8p3-1
274 [24 Nov 2004] DSA-596-1 sudo - missing input sanitising
275 {CAN-2004-1051}
276 - sudo 1.6.8p3-1
277 [24 Nov 2004] DSA-595-1 bnc - buffer overflow
278 {CAN-2004-1052}
279 NOTE: package not in sarge or sid
280 [17 Nov 2004] DSA-594-1 apache - buffer overflows
281 {CAN-2004-0940}
282 - apache 1.3.33-2
283 [16 Nov 2004] DSA-593-1 imagemagick - buffer overflow
284 {CAN-2004-0981}
285 - imagemagick 6:6.0.6.2-1.5
286 [12 Nov 2004] DSA-592-1 ez-ipupdate - format string
287 {CAN-2004-0980}
288 - ez-ipupdate 3.0.11b8-8
289 [09 Nov 2004] DSA-591-1 libgd2 - integer overflows
290 {CAN-2004-0990}
291 - libgd2 2.0.30-1
292 [09 Nov 2004] DSA-590-1 gnats - format string vulnerability
293 {CAN-2004-0623}
294 NOTE: DSA got version of fix for unstable wrong
295 - gnats 4.0-6.1
296 [09 Nov 2004] DSA-589-1 libgd - integer overflows
297 {CAN-2004-0990}
298 - libgd1 1.8.4-36.1
299 [08 Nov 2004] DSA-588-1 gzip - insecure temporary files
300 {CAN-2004-0970}
301 NOTE: dsa says sid not affected
302 [08 Nov 2004] DSA-587-1 freeamp - buffer overflow
303 {CAN-2004-0964}
304 NOTE: DSA says zinf not vulnerable in sarge
305 [08 Nov 2004] DSA-586-1 ruby - infinite loop
306 {CAN-2004-0983}
307 - ruby1.6 1.6.8-12
308 - ruby1.8 1.8.1+1.8.2pre2-4
309 [05 Nov 2004] DSA-585-1 shadow - programming error
310 {CAN-2004-1001}
311 - shadow 1:4.0.3-30.3
312 [04 Nov 2004] DSA-584-1 dhcp - format string vulnerability
313 {CAN-2004-1006}
314 - dhcp 2.0pl5-19.1
315 [03 Nov 2004] DSA-583-1 lvm10 - insecure temporary directory
316 {CAN-2004-0972}
317 [02 Nov 2004] DSA-582-1 libxml - buffer overflow
318 {CAN-2004-0989}
319 - libxml 1.8.17-9
320 - libxml2 2.6.11-5
321 [01 Nov 2004] DSA-581-1 xpdf - integer overflows
322 {CAN-2004-0888}
323 - xpdf 3.00-9
324 [01 Nov 2004] DSA-580-1 iptables - missing initialisation
325 {CAN-2004-0986}
326 - iptables 1.2.11-4
327 [01 Nov 2004] DSA-579-1 abiword - buffer overflow
328 {CAN-2004-0645}
329 NOTE: according to DSA, sid's abiword is not affected. sarge is same
330 [01 Nov 2004] DSA-578-1 mpg123 - buffer overflow
331 {CAN-2004-0982}
332 - mpg123 0.59r-17
333 [29 Oct 2004] DSA-577-1 postgresql - symlink vulnerability
334 {CAN-2004-0977}
335 - postgresql 7.4.6-1
336 [29 Oct 2004] DSA-576-1 squid - multiple
337 {CVE-1999-0710 CAN-2004-0918}
338 - squid 2.5.7-1
339 [28 Oct 2004] DSA-575-1 catdoc - insecure temporary file
340 {CAN-2003-0193}
341 - catdoc 0.91.5-2
342 [28 Oct 2004] DSA-574-1 cabextract - missing directory sanitising
343 {CAN-2004-0916}
344 - cabextract 1.1-1
345 [21 Oct 2004] DSA-573-1 cupsys - integer overflows
346 {CAN-2004-0888}
347 - cupsys 1.1.20final+rc1-10
348 {CAN-2004-0889}
349 - xpdf 3.00-10
350 TODO: kpdf and kfax not fixed in sarge, bug #278173 has a backported patch for the kpdf hole
351 - kpdf 4:3.3.1-1
352 - gpdf 2.8.0-1
353 - kfax 4:3.3.1-1
354 [21 Oct 2004] DSA-572-1 ecartis - multiple
355 {CAN-2004-0913}
356 - ecartis 1.0.0+cvs.20030911-8
357 [20 Oct 2004] DSA-571-1 libpng3 - buffer overflows, integer overflow
358 {CAN-2004-0955}
359 - libpng3 1.2.5.0-9
360 [20 Oct 2004] DSA-570-1 libpng - integer overflow
361 {CAN-2004-0955}
362 - libpng 1.0.15-8
363 [18 Oct 2004] DSA-569-1 netkit-telnet-ssl - invalid free(3)
364 {CAN-2004-0911}
365 - netkit-telnet-ssl 0.17.24+0.1-4
366 [16 Oct 2004] DSA-568-1 cyrus-sasl-mit - unsanitised input
367 {CAN-2004-0884}
368 NOTE removed from testing
369 NOTE maintainer reports hole not in cyrus-sasl2-mit
370 [15 Oct 2004] DSA-567-1 tiff - heap overflows
371 {CAN-2004-0803 CAN-2004-0804 CAN-2004-0886}
372 - tiff 3.6.1-2
373 - tiff3g 3.6.1-2
374 [14 Oct 2004] DSA-566-1 cupsys - unsanitised input
375 {CAN-2004-0923}
376 - cupsys 1.1.20final+rc1-9
377 [13 Oct 2004] DSA-565-1 sox - buffer overflows
378 {CAN-2004-0557}
379 - sox 12.17.4-9
380 [13 Oct 2004] DSA-564-1 mpg123 - missing user input sanitising
381 {CAN-2004-0805}
382 - mpg123 0.59r-16
383 [12 Oct 2004] DSA-563-1 cyrus-sasl - unsanitised input
384 {CAN-2004-0884}
385 - cyrus-sasl 1.5.28-6.2
386 - cyrus-sasl2 2.1.19-1.3
387 [11 Oct 2004] DSA-562-2 mysql - several vulnerabilities
388 {CAN-2004-0835 CAN-2004-0836 CAN-2004-0837}
389 - mysql 4.0.21-1
390 [11 Oct 2004] DSA-561-1 xfree86 - integer and stack overflows
391 {CAN-2004-0687 CAN-2004-0688}
392 - xfree86 4.3.0.dfsg.1-8
393 [07 Oct 2004] DSA-600-1 samba - arbitrary file access
394 {CAN-2004-0815}
395 NOTE: not affected according to DSA
396 [07 Oct 2004] DSA-560-1 lesstif1-1 - integer and stack overflows
397 {CAN-2004-0687 CAN-2004-0688}
398 - lesstif1-1 0.93.94-10
399 [06 Oct 2004] DSA-559-1 net-acct - insecure temporary file
400 {CAN-2004-0851}
401 - net-acct 0.71-7
402 [06 Oct 2004] DSA-558-1 libapache-mod-dav - null pointer dereference
403 {CAN-2004-0809}
404 - libapache-mod-dav 1.0.3-10
405 - apache2 2.0.51-1
406 [04 Oct 2004] DSA-557-1 pppoe - missing privilegue dropping
407 {CAN-2004-0564}
408 - pppoe 3.5-4
409 [03 Oct 2004] DSA-556-1 netkit-telnet - invalid free(3)
410 {CAN-2004-0911}
411 - netkit-telnet 0.17-26
412 [30 Sep 2004] DSA-555-1 freenet6 - file permissions
413 {CAN-2004-0563}
414 - freenet6 1.0-2.2
415 [27 Sep 2004] DSA-554-1 sendmail - pre-set password
416 {CAN-2004-0833}
417 - sendmail 8.13.1-13
418 [27 Sep 2004] DSA-553-1 getmail - symlink vulnerability
419 {CAN-2004-0880 CAN-2004-0881}
420 - getmail 3.2.5-1
421 [22 Sep 2004] DSA-552-1 imlib2 - unsanitised input
422 {CAN-2004-0802}
423 - imlib2 1.1.0-12.4
424 [21 Sep 2004] DSA-551-1 lukemftpd - incorrect internal variable handling
425 {CAN-2004-0794}
426 - lukemftpd 1.1-2.2
427 [20 Sep 2004] DSA-550-1 wv - buffer overflow
428 {CAN-2004-0645}
429 - wv 1.0.2-0.1
430 [17 Sep 2004] DSA-549-1 gtk+2.0 - multiple holes
431 {CAN-2004-0782 CAN-2004-0783 CAN-2004-0788}
432 - gtk+2.0 2.4.9-2
433 [16 Sep 2004] DSA-548-1 imlib - unsanitised input
434 {CAN-2004-0817}
435 - imlib 1.9.14-17
436 - imlib+png2 1.9.14-16.2
437 [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows
438 {CAN-2004-0827}
439 - imagemagic 6.0.6.2-1
440 [16 Sep 2004] DSA-546-1 gdk-pixbuf - multiple holes
441 {CAN-2004-0753 CAN-2004-0782 CAN-2004-0788}
442 - gdk-pixbuf 0.22.0-7
443 [15 Sep 2004] DSA-545-1 cupsys - denial of service
444 {CAN-2004-0558}
445 - cupsys 1.1.20final+rc1-6
446 [14 Sep 2004] DSA-544-1 webmin - insecure temporary directory
447 {CAN-2004-0559}
448 - webmin 1.160-1
449 - usermin 1.090-1
450 [31 Aug 2004] DSA-543-1 krb5 -- several vulnerabilities
451 {CAN-2004-0642 CAN-2004-0643 CAN-2004-0644 CAN-2004-0772}
452 - krb5 1.3.4-3
453 [31 Aug 2004] DSA-458-2 python2.2 - buffer overflow
454 {CAN-2004-0150}
455 NOTE: not affected according to DSA
456 [30 Aug 2004] DSA-542-1 qt - unsanitised input
457 {CAN-2004-0691 CAN-2004-0692 CAN-2004-0693}
458 - qt-x11-free 3.3.3-4
459 [25 Aug 2004] DSA-541 icecast-server - cross site scripting
460 {CAN-2004-0781}
461 - icecast-server 1.3.12-8
462 [18 Aug 2004] DSA-540 mysql-dfsg - insecure file creation
463 {CAN-2004-0457}
464 - mysql-dfsg 4.0.20-11
465 [18 Aug 2004] DSA-539 kdelibs - denial of service
466 {CAN-2004-0689}
467 - kdelibs 4:3.2.3-3.sarge.1
468 [17 Aug 2004] DSA-538 rsync - unauthorised directory traversal and file access
469 - rsync 2.6.2-3
470 [16 Aug 2004] DSA-537 ruby - insecure file permissions
471 {CAN-2004-0755}
472 - ruby1.8 1.8.1+1.8.2pre1-4
473 HELP: is ruby1.6 vulnerable?
474 [04 Aug 2004] DSA-536 libpng - several vulnerabilities
475 {CAN-2004-0597 CAN-2004-0598 CAN-2004-0599 CAN-2004-0768}
476 - libpng 1.0.15-6
477 - libpng3 1.2.5.0-7
478 [02 Aug 2004] DSA-535 squirrelmail - several vulnerabilities
479 {CAN-2004-0519 CAN-2004-0520 CAN-2004-0521 CAN-2004-0639}
480 - squirrelmail 2:1.4.3a-0.1
481 [22 Jul 2004] DSA-534 mailreader - directory traversal
482 {CAN-2002-1581}
483 - mailreader 2.3.29-9
484 [22 Jul 2004] DSA-533 courier - cross-site scripting
485 {CAN-2004-0591}
486 - courier 0.45.4-4
487 [22 Jul 2004] DSA-532 libapache-mod-ssl - several vulnerabilities
488 {CAN-2004-0488 CAN-2004-0700}
489 - libapache-mod-ssl 2.8.19-1
490 [20 Jul 2004] DSA-531 php4 - several vulnerabilities
491 {CAN-2004-0594 CAN-2004-0595}
492 ! php4 4:4.3.8-1
493 [17 Jul 2004] DSA-530 l2tpd - buffer overflow
494 {CAN-2004-0649}
495 - l2tpd 0.70-pre20031121-2
496 [17 Jul 2004] DSA-529 netkit-telnet-ssl - format string
497 {CAN-2004-0640}
498 ! netkit-telnet-ssl 0.17.24+0.1-2
499 [17 Jul 2004] DSA-528 ethereal - denial of service
500 {CAN-2004-0635}
501 - ethereal 0.10.5-1
502 [03 Jul 2004] DSA-527 pavuk - buffer overflow
503 {CAN-2004-0456}
504 NOTE: DSA is incorrect; pavuk is in sarge and unstable.
505 ! pavuk 0.9pl28-3
506 [03 Jul 2004] DSA-526 webmin - several vulnerabilities
507 {CAN-2004-0582 CAN-2004-0583}
508 - webmin 1.150-1
509 [24 Jun 2004] DSA-525 apache - buffer overflow
510 {CAN-2004-0492}
511 - apache 1.3.31-2
512 [19 Jun 2004] DSA-524 rlpr - several vulnerabilities
513 {CAN-2004-0393 CAN-2004-0454}
514 - rlpr 2.02-7.1
515 [19 Jun 2004] DSA-523 www-sql - buffer overflow
516 {CAN-2004-0455}
517 - www-sql 0.5.7-18
518 [19 Jun 2004] DSA-522 super - format string vulnerability
519 {CAN-2004-0579}
520 - super 3.23.0-1
521 [18 Jun 2004] DSA-521 sup - format string vulnerability
522 {CAN-2004-0451}
523 - sup 1.8-11
524 [16 Jun 2004] DSA-520 krb5 - buffer overflows
525 {CAN-2004-0523}
526 - krb5 1.3.3-2
527 [15 Jun 2004] DSA-519 cvs - several vulnerabilities
528 {CAN-2004-0416 CAN-2004-0417 CAN-2004-0418}
529 - cvs 1:1.12.9-1
530 [14 Jun 2004] DSA-518 kdelibs - unsanitised input
531 {CAN-2004-0411}
532 - kdelibs 3.2.3
533 [10 Jun 2004] DSA-517 cvs - buffer overflow
534 {CAN-2004-0414]
535 - cvs 1.12.9-1
536 [07 Jun 2004] DSA-516 postgresql - buffer overflow
537 {CAN-2004-0547}
538 - postgresql 07.03.0200-3.
539 [05 Jun 2004] DSA-515 lha - several vulnerabilities
540 {CAN-2004-0234 CAN-2004-0235}
541 ! lha 1.14i-8
542 NOTE: If 1.14i-8 cannot get into testing, the fix for 1.14i-2.0.1
543 from the DSA could to updated via t-p-u.
544 [04 Jun 2004] DSA-514 kernel-image-sparc-2.2 - failing function and TLB flush
545 {CAN-2004-0077}
546 - kernel-image-sparc-2.2 9.1
547 NOTE: did not check other versions of the kernel
548 [03 Jun 2004] DSA-513 log2mail - format string
549 {CAN-2004-0450}
550 ! log2mail 0.2.8-3
551 [02 Jun 2004] DSA-512 gallery - unauthenticated access
552 {CAN-2004-0522}
553 - gallery 1.4.3-pl2-1
554 [30 May 2004] DSA-511 ethereal - buffer overflows
555 {CAN-2004-0176
556 - ethereal 0.10.3-1
557 [29 May 2004] DSA-510 jftpgw - format string
558 {CAN-2004-0448}
559 - jftpgw 0.13.4-1
560 [29 May 2004] DSA-509 gatos - privilege escalation
561 {CAN-2004-0395}
562 - gatos 0.0.5-12
563 [22 May 2004] DSA-508 xpcd - buffer overflow
564 {CAN-2004-0402}
565 - xpcd 2.08-10
566 [19 May 2004] DSA-507 cadaver - buffer overflow
567 {CAN-2004-0398}
568 - cadaver 0.22.1-3
569 [19 May 2004] DSA-506 neon - buffer overflow
570 {CAN-2004-0398}
571 - neon 0.24.6.dfsg-1
572 [19 May 2004] DSA-505 cvs - heap overflow
573 {CAN-2004-0396}
574 - cvs 1.12.5-6
575 [18 May 2004] DSA-504 heimdal - missing input sanitising
576 {CAN-2004-0434}
577 - heimdal 0.6.2-1
578 [13 May 2004] DSA-503 mah-jong - missing argument check
579 {CAN-2004-0458}
580 - mah-jong 1.6.2-1
581 [11 May 2004] DSA-502 exim-tls - buffer overflow
582 {CAN-2004-0399 CAN-2004-0400}
583 NOTE: exim-tls not in sarge
584 [07 May 2004] DSA-501 exim - buffer overflow
585 {CAN-2004-0399 CAN-2004-0400}
586 - exim 3.36-11
587 - exim4 4.33-1
588 [01 May 2004] DSA-500 flim - insecure temporary file
589 {CAN-2004-0422}
590 - flim 1:1.14.6+0.20040415-1
591 [01 May 2004] DSA-499 rsync - directory traversal
592 {CAN-2004-0426}
593 - rsync 2.6.1-1
594 [30 Apr 2004] DSA-498 libpng - out of bound access
595 {CAN-2004-0421}
596 - libpng 1.0.15-5
597 - libpng3 1.2.5.0-6
598 [29 Apr 2004] DSA-497 mc - several vulnerabilities
599 {CAN-2004-0226 CAN-2004-0231 CAN-2004-0232}
600 - mc 1:4.6.0-4.6.1-pre1-2
601 [29 Apr 2004] DSA-496 eterm - missing input sanitising
602 {CAN-2003-0068}
603 - eterm 0.9.2-6
604 [26 Apr 2004] DSA-495 linux-kernel-2.4.16-arm - several vulnerabilities
605 {CAN-2003-0127 CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
606 NOTE: 2.4.16 not present. Did not check newer kernels.
607 [21 Apr 2004] DSA-494 ident2 - buffer overflow
608 {CAN-2004-0408}
609 - ident2 1.04-2
610 [21 Apr 2004] DSA-493 xchat - buffer overflow
611 {CAN-2004-0409}
612 - xchat 2.0.8-1
613 [18 Apr 2004] DSA-492 iproute - denial of service
614 {CAN-2003-0856}
615 - iproute 20010824-13.1
616 [17 Apr 2004] DSA-491 linux-kernel-2.4.19-mips - several vulnerabilities
617 {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
618 NOTE: 2.4.19 not present. Did not check newer kernels.
619 [17 Apr 2004] DSA-490 zope - arbitrary code execution
620 {CVE-2002-0688}
621 - zope 2.6.0-0.1
622 [17 Apr 2004] DSA-489 linux-kernel-2.4.17-mips+mipsel - several vulnerabilities
623 {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
624 NOTE: 2.4.17 not present. Did not check newer kernels.
625 [16 Apr 2004] DSA-488 logcheck - insecure temporary directory
626 {CAN-2004-0404}
627 - logcheck 1.1.1-13.2
628 [16 Apr 2004] DSA-487 neon - format string
629 {CAN-2004-0179}
630 - newo 0.24.5-1
631 [16 Apr 2004] DSA-486 cvs - several vulnerabilities
632 {CAN-2004-0180 CAN-2004-0405}
633 - cvs 1:1.12.5-4
634 [14 Apr 2004] DSA-485 ssmtp - format string
635 {CAN-2004-0156}
636 - ssmtp 2.60.7
637 [14 Apr 2004] DSA-484 xonix - failure to drop privileges
638 {CAN-2004-0157}
639 - xonix 1.4-21
640 [14 Apr 2004] DSA-483 mysql - insecure temporary file creation
641 {CAN-2004-0381}
642 - mysql-dfsg 4.0.18-4
643 {CAN-2004-0388}
644 ! mysql-dfsg 4.0.18-6
645 [14 Apr 2004] DSA-482 linux-kernel-2.4.17-apus+s390 - several vulnerabilities
646 {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
647 NOTE: 2.4.17 not present. Did not check newer kernels.
648 [14 Apr 2004] DSA-481 linux-kernel-2.4.17-ia64 - several vulnerabilities
649 {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
650 NOTE: 2.4.17 not present. Did not check newer kernels.
651 [14 Apr 2004] DSA-480 linux-kernel-2.4.17+2.4.18-hppa - several vulnerabilities
652 {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
653 NOTE: 2.4.17/18 not present. Did not check newer kernels.
654 [14 Apr 2004] DSA-479 linux-kernel-2.4.18-alpha+i386+powerpc - several vulnerabilities
655 {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
656 NOTE: 2.4.18 not present. Did not check newer kernels.
657 [06 Apr 2004] DSA-478 tcpdump - denial of service
658 {CAN-2004-0183 CAN-2004-0184}
659 - tcpdump 3.7.2-4
660 [06 Apr 2004] DSA-477 xine-ui - insecure temporary file creation
661 {CAN-2004-0372}
662 - xine-ui 0.99.1-1
663 [06 Apr 2004] DSA-476 heimdal - cross-realm
664 {CAN-2004-0371}
665 - heimdal 0.6.1-1
666 [05 Apr 2004] DSA-475 linux-kernel-2.4.18-hppa - several vulnerabilities
667 {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
668 NOTE: 2.4.18 not present. Did not check newer kernels.
669 [03 Apr 2004] DSA-474 squid - ACL bypass
670 {CAN-2004-0189}
671 - squid 2.5.5-1
672 [03 Apr 2004] DSA-473 oftpd - denial of service
673 {CAN-2004-0376}
674 - oftpd 20040304-1
675 [03 Apr 2004] DSA-472 fte - several vulnerabilities
676 {CAN-2003-0648}
677 - fte 0.50.0-1.1
678 [02 Apr 2004] DSA-471 interchange - missing input sanitising
679 {CAN-2004-0374}
680 - interchange 5.0.1-1
681 [01 Apr 2004] DSA-470 linux-kernel-2.4.17-hppa - several vulnerabilities
682 {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
683 NOTE: 2.4.17 not present. Did not check newer kernels.
684 [29 Mar 2004] DSA-469 pam-pgsql - missing input sanitising
685 {CAN-2004-0366}
686 - pam-pgsql 0.5.2-7.1
687 [24 Mar 2004] DSA-468 emil - several vulnerabilities
688 {CAN-2004-0152 CAN-2004-0153}
689 - emil 2.1.0-beta9-14
690 [23 Mar 2004] DSA-467 ecartis - several vulnerabilities
691 {CAN-2003-0781 CAN-2003-0782}
692 - ecartis 1.0.0+cvs.20030911
693 [18 Mar 2004] DSA-466 linux-kernel-2.2.10-powerpc-apus - failing function and TLB flush
694 {CAN-2004-0077}
695 NOTE: 2.2.10 not present. Did not check newer kernels.
696 [17 Mar 2004] DSA-465 openssl - several vulnerabilities
697 {CAN-2004-0079 CAN-2004-0081}
698 - openssl 0.9.7d-1
699 NOTE: CAN-2004-0081 only affects 0.9.6.
700 NOTE: 0.9.7d also fixes CAN-2004-0112
701 - openssl 0.9.6l
702 - openssl096 0.9.6m-1
703 [16 Mar 2004] DSA-464 gdk-pixbuf - broken image handling
704 {CAN-2004-0111}
705 - gdk-pixbuf 0.22.0-3
706 [12 Mar 2004] DSA-463 samba - privilege escalation
707 {CAN-2004-0186}
708 - samba 3.0.2-2
709 [12 Mar 2004] DSA-462 xitalk - missing privilege release
710 {CAN-2004-0151}
711 - xitalk 1.1.11-11
712 [11 Mar 2004] DSA-461 calife - buffer overflow
713 {CAN-2004-0188}
714 - calife 2.8.6-1
715 [10 Mar 2004] DSA-460 sysstat - insecure temporary file
716 {CAN-2004-0108}
717 - sysstat 5.0.2-1
718 [10 Mar 2004] DSA-459 kdelibs - cookie path traversal
719 {CAN-2003-0592}
720 - kdelibs 4:3.1.3-1
721 [09 Mar 2004] DSA-458 python2.2 - buffer overflow
722 {CAN-2004-0150}
723 NOTE: not affected according to DSA
724 [08 Mar 2004] DSA-457 wu-ftpd - several vulnerabilities
725 {CAN-2004-0148 CAN-2004-0185}
726 - wu-ftpd 2.6.2-17.1
727 [06 Mar 2004] DSA-456 linux-kernel-2.2.19-arm - failing function and TLB flush
728 {CAN-2004-0077}
729 NOTE: 2.2.19 not present. Did not check newer kernels.
730 [03 Mar 2004] DSA-455 libxml - buffer overflows
731 {CAN-2004-0110}
732 - libxml 1.8.17-5
733 - libxml2 2.6.6-1
734 [02 Mar 2004] DSA-454 linux-kernel-2.2.22-alpha - failing function and TLB flush
735 {CAN-2004-0077}
736 NOTE: 2.2.22 not present. Did not check newer kernels.
737 [02 Mar 2004] DSA-453 linux-kernel-2.2.20-i386+m68k+powerpc - failing function and TLB flush
738 {CAN-2004-0077}
739 NOTE: 2.2.20 not present. Did not check newer kernels.
740 [29 Feb 2004] DSA-452 libapache-mod-python - denial of service
741 {CAN-2003-0973}
742 - libapache-mod-python 2:2.7.10-1
743 [27 Feb 2004] DSA-451 xboing - buffer overflows
744 {CAN-2004-0149}
745 - xboing 2.4-26.1
746 [27 Feb 2004] DSA-450 linux-kernel-2.4.19-mips - several vulnerabilities
747 {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
748 NOTE: 2.4.19 not present. Did not check newer kernels.
749 [24 Feb 2004] DSA-449 metamail - buffer overflow, format string bugs
750 {CAN-2004-0104 CAN-2004-0105}
751 - metamail 2.7-45.2
752 [22 Feb 2004] DSA-448 pwlib - several vulnerabilities
753 {CAN-2004-0097}
754 - pwlib 1.5.2-4
755 [22 Feb 2004] DSA-447 hsftp - format string
756 {CAN-2004-0159}
757 ! hsftp 1.15-1
758 [21 Feb 2004] DSA-446 synaesthesia - insecure file creation
759 {CAN-2004-0160}
760 DSA notes not setuid anymore so ok
761 [21 Feb 2004] DSA-445 lbreakout2 - buffer overflow
762 {CAN-2004-0158}
763 - lbreakout2 2.4
764 [20 Feb 2004] DSA-444 linux-kernel-2.4.17-ia64 - missing function return value check
765 {CAN-2004-0077}
766 NOTE: 2.4.17 not present. Did not check newer kernels.
767 [19 Feb 2004] DSA-443 xfree86 - several vulnerabilities
768 {CAN-2003-0690}
769 - xfree86 4.3.0-0pre1v2
770 {CAN-2004-0083 CAN-2004-0084 CAN-2004-0106}
771 - xfree86 4.3.0-1
772 {CAN-2004-0093 CAN-2004-0094}
773 - xfree86 4.2.1-6
774 [19 Feb 2004] DSA-442 linux-kernel-2.4.17-s390 - several vulnerabilities
775 {CAN-2003-0001 CAN-2003-0244 CAN-2003-0246 CAN-2003-0247 CAN-2003-0248 CAN-2003-0364 CAN-2003-0961 CAN-2003-0985 CAN-2004-0077 CVE-2002-0429}
776 NOTE: 2.4.17 not present. Did not check newer kernels.
777 [18 Feb 2004] DSA-441 linux-kernel-2.4.17-mips+mipsel - missing function return value check
778 {CAN-2004-0077}
779 NOTE: 2.4.17 not present. Did not check newer kernels.
780 [18 Feb 2004] DSA-440 linux-kernel-2.4.17-powerpc-apus - several vulnerabilities
781 {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
782 NOTE: 2.4.17 not present. Did not check newer kernels.
783 [18 Feb 2004] DSA-439 linux-kernel-2.4.16-arm - several vulnerabilities
784 {CAN-2003-0961 CAN-2003-0985 CAN-2004-0077}
785 NOTE: 2.4.16 not present. Did not check newer kernels.
786 [18 Feb 2004] DSA-438 linux-kernel-2.4.18-alpha+i386+powerpc - missing function return value check
787 {CAN-2004-0077}
788 NOTE: 2.4.17 not present. Did not check newer kernels.
789 [11 Feb 2004] DSA-437 cgiemail - open mail relay
790 {CAN-2002-1575}
791 - cgiemail 1.6-20
792 [08 Feb 2004] DSA-436 mailman - several vulnerabilities
793 {CAN-2003-0991}
794 NOTE: apparently specific to mailman 2.0, not 2.1
795 {CAN-2003-0965}
796 - mailman 2.1.4-1
797 {CAN-2003-0038}
798 - mailman 2.1.1-1
799 [06 Feb 2004] DSA-435 mpg123 - heap overflow
800 {CAN-2003-0865}
801 - mpg123 0.59r-15
802 [05 Feb 2004] DSA-434 gaim - several vulnerabilities
803 {CAN-2004-0005 CAN-2004-0006 CAN-2004-0007 CAN-2004-0008}
804 - gaim 1:0.75-2
805 [04 Feb 2004] DSA-433 kernel-patch-2.4.17-mips - integer overflow
806 {CAN-2003-0961}
807 NOTE: 2.4.17 not present. Did not check newer kernels.
808 [03 Feb 2004] DSA-432 crawl - buffer overflow
809 {CAN-2004-0103}
810 - crawl 4.0.0beta26-4
811 [01 Feb 2004] DSA-431 perl - information leak
812 {CAN-2003-0618}
813 - perl 5.8.3-3
814 [28 Jan 2004] DSA-430 trr19 - missing privilege release
815 {CAN-2004-0047}
816 - trr19 1.0beta5-17.1
817 [26 Jan 2004] DSA-429 gnupg - cryptographic weakness
818 {CAN-2003-0971}
819 - gnupg 1.2.4-1
820 [20 Jan 2004] DSA-428 slocate - buffer overflow
821 {CAN-2003-0848}
822 - slocate 2.7-3
823 [19 Jan 2004] DSA-427 linux-kernel-2.4.17-mips+mipsel - missing boundary check
824 {CAN-2003-0985}
825 NOTE: 2.4.17 not present. Did not check newer kernels.
826 [18 Jan 2004] DSA-426 netpbm-free - insecure temporary files
827 {CAN-2003-0924}
828 - netpbm-free 2:9.25-9
829 [16 Jan 2004] DSA-425 tcpdump - multiple vulnerabilities
830 {CAN-2003-1029 CAN-2003-0989 CAN-2004-0055 CAN-2004-0057}
831 HELP: No idea if this is fixed, we have a new upstream version
832 HELP: that came out after these advisories, but neither the debian nor
833 HELP: the upstream changelog seem to mention them.
834 NOTE: Mailed maintainer.
835 [16 Jan 2004] DSA-424 mc - buffer overflow
836 {CAN-2003-1023}
837 - mc 1:4.6.0-4.6.1-pre1-1
838 [15 Jan 2004] DSA-423 linux-kernel-2.4.17-ia64 - several vulnerabilities
839 {CAN-2003-0001 CAN-2003-0018 CAN-2003-0127 CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0961 CAN-2003-0985}
840 NOTE: 2.4.17 not present. Did not check newer kernels.
841 [13 Jan 2004] DSA-422 cvs - remote vulnerability
842 - cvs 1.11.11
843 [12 Jan 2004] DSA-421 mod-auth-shadow - password expiration
844 {CAN-2004-0041}
845 - mod-auth-shadow 1.4-1
846 [12 Jan 2004] DSA-420 jitterbug - improperly sanitised input
847 {CAN-2004-0028}
848 - jitterbug 1.6.2-4.5
849 [09 Jan 2004] DSA-419 phpgroupware - missing filename sanitising, SQL injection
850 {CAN-2004-0016 CAN-2004-0017}
851 - phpgroupware 0.9.14.007-4
852 [07 Jan 2004] DSA-418 vbox3 - privilege leak
853 {CAN-2004-0015}
854 - vbox3 0.1.8
855 [07 Jan 2004] DSA-417 linux-kernel-2.4.18-powerpc+alpha - missing boundary check
856 {CAN-2003-0961 CAN-2003-0985}
857 NOTE: 2.4.18 not present. Did not check newer kernels.
858 [06 Jan 2004] DSA-416 fsp - buffer overflow, directory traversal
859 {CAN-2003-1022 CAN-2004-0011}
860 - fsp 2.81.b18-1
861 [06 Jan 2004] DSA-415 zebra - denial of service
862 {CAN-2003-0795 CAN-2003-0858}
863 - quagga 0.96.4x-4
864 [06 Jan 2004] DSA-414 jabber - denial of service
865 {CAN-2004-0013}
866 - jabber 1.4.3-1
867 [06 Jan 2004] DSA-413 linux-kernel-2.4.18 - missing boundary check
868 {CAN-2003-0985}
869 NOTE: 2.4.18 not present. Did not check newer kernels.
870 [05 Jan 2004] DSA-412 nd - buffer overflows
871 {CAN-2004-0014}
872 - nd 0.8.2-1
873 [05 Jan 2004] DSA-411 mpg321 - format string vulnerability
874 {CAN-2003-0969}
875 - mpg321 0.2.10.3
876 [05 Jan 2004] DSA-410 libnids - buffer overflow
877 {CAN-2003-0850}
878 - libnids 1.18-1
879 [05 Jan 2004] DSA-409 bind - denial of service
880 {CAN-2003-0914}
881 - bind 1:8.4.3-1
882 [05 Jan 2004] DSA-408 screen - integer overflow
883 {CAN-2003-0972}
884 - screen 4.0.2-0.1
885 [05 Jan 2004] DSA-407 ethereal - buffer overflows
886 {CAN-2003-0925 CAN-2003-0926 CAN-2003-0927 CAN-2003-1012 CAN-2003-1013
887 - ethereal 0.10.0-1
888 [05 Jan 2004] DSA-406 lftp - buffer overflow
889 - lftp 2.6.10-1
890 [30 Dec 2003] DSA-405 xsok - missing privilege release
891 {CAN-2003-0949}
892 - xsok 1.02-11
893 [04 Dec 2003] DSA-404 rsync - heap overflow
894 {CAN-2003-0962}
895 - rsync 2.5.6-1.1
896 [01 Dec 2003] DSA-403 kernel-image-2.4.18-1-alpha, kernel-image-2.4.18-1-i386, kernel-source-2.4.18 - local root exploit
897 {CAN-2003-0961}
898 NOTE: 2.4.18 not present in sarge, did not check newer kernels.
899 [17 Nov 2003] DSA-402 minimalist - unsanitised input
900 {CAN-2003-0902}
901 - minimalist 2.4-1
902 [17 Nov 2003] DSA-401 hylafax - format strings
903 {CAN-2003-0886}
904 - hylafax 1:4.1.8-1
905 [11 Nov 2003] DSA-400 omega-rpg - buffer overflow
906 {CAN-2003-0932}
907 - omega-rpg 0.90-pa9-11
908 [10 Nov 2003] DSA-399 epic4 - buffer overflow
909 {CAN-2003-0328}
910 - epic4 1:1.1.11.20030409-2
911 [10 Nov 2003] DSA-398 conquest - buffer overflow
912 {CAN-2003-0933}
913 - conquest 7.2-5
914 [07 Nov 2003] DSA-397 postgresql - buffer overflow
915 {CAN-2003-0901}
916 - postgresql 7.3.4
917 [29 Oct 2003] DSA-396 thttpd - missing input sanitizing, wrong calculation
918 {CAN-2002-1562 CAN-2003-0899}
919 - thttpd 2.23beta1-2.3
920 [15 Oct 2003] DSA-395 tomcat4 - incorrect input handling
921 {CAN-2003-0866}
922 ! tomcat4 4.1.24-2
923 NOTE another RC (unreproducible?) bug and missing deps (#263201)
924 NOTE are keeping the fix out of testing
925 [11 Oct 2003] DSA-394 openssl095 - ASN.1 parsing vulnerability
926 {CAN-2003-0543 CAN-2003-0544 CAN-2003-0545}
927 - openssl 0.9.7c
928 - openssl096 0.9.6k
929 [01 Oct 2003] DSA-393 openssl - denial of service
930 {CAN-2003-0543 CAN-2003-0544 CAN-2003-0545}
931 - openssl 0.9.7c
932 - openssl096 0.9.6k
933 [29 Sep 2003] DSA-392 webfs - buffer overflows, file and directory exposure
934 {CAN-2003-0832 CAN-2003-0833}
935 - webfs 1.20
936 [28 Sep 2003] DSA-391 freesweep - buffer overflow
937 {CAN-2003-0828}
938 - freesweep 0.88-4.1
939 [26 Sep 2003] DSA-390 marbles - buffer overflow
940 {CAN-2003-0830}
941 NOTE not present in sid, sarge
942 [20 Sep 2003] DSA-389 ipmasq - insecure packet filtering rules
943 {CAN-2003-0785}
944 - ipmasq 3.5.12
945 [19 Sep 2003] DSA-388 kdebase - several vulnerabilities
946 {CAN-2003-0690 CAN-2003-0692}
947 - kdebase 4:3.2
948 [18 Sep 2003] DSA-387 gopher - buffer overflows
949 {CAN-2003-0805}
950 - gopher 3.0.6
951 [18 Sep 2003] DSA-386 libmailtools-perl - input validation bug
952 {CAN-2002-1271}
953 - libmailtools-perl 1.51
954 [18 Sep 2003] DSA-385 hztty - buffer overflows
955 {CAN-2003-0783}
956 - hztty 2.0-6
957 [17 Sep 2003] DSA-384 sendmail - buffer overflows
958 {CAN-2003-0681 CAN-2003-0694}
959 - sendmail 8.12.10-1
960 [17 Sep 2003] DSA-383 ssh-krb5 - possible remote vulnerability
961 {CAN-2003-0693}
962 {CAN-2003-0695}
963 {CAN-2003-0682}
964 HELP: Screwy changelog does not make sense. Filed bug.
965 [16 Sep 2003] DSA-382 ssh - possible remote vulnerability
966 {CAN-2003-0693}
967 - openssh 1:3.6.1p2-6.0
968 {CAN-2003-0695}
969 - openssh 1:3.7.1
970 {CAN-2003-0682}
971 - openssh 1:3.6.1p2-9
972 [13 Sep 2003] DSA-381 mysql - buffer overflow
973 {CAN-2003-0780}
974 - mysql-dfsg 4.0.15-1
975 [12 Sep 2003] DSA-380 xfree86 - buffer overflows, denial of service
976 {CAN-2003-0063}
977 - xfree86 4.2.1-11
978 {CAN-2003-0071}
979 - xfree86 4.2.1-11
980 {CAN-2002-0164}
981 - xfree86 4.2.1-11
982 {CAN-2003-0730}
983 - xfree86 4.2.1-12
984 [11 Sep 2003] DSA-379 sane-backends - several vulnerabilities
985 {CAN-2003-0773 CAN-2003-0774 CAN-2003-0775 CAN-2003-0776 CAN-2003-0777 CAN-2003-0778}
986 - sane-backends 1.0.11-1
987 [07 Sep 2003] DSA-378 mah-jong - buffer overflows, denial of service
988 {CAN-2003-0705 CAN-2003-0706}
989 - mah-jong 1.5.6-2
990 [04 Sep 2003] DSA-377 wu-ftpd - insecure program execution
991 {CVE-1999-0997}
992 - wu-ftpd 2.6.2-15
993 [04 Sep 2003] DSA-376 exim - buffer overflow
994 {CAN-2003-0743}
995 - exim 3.36-8
996 [29 Aug 2003] DSA-375 node - buffer overflow, format string
997 {CAN-2003-0707 CAN-2003-0708}
998 - node 0.3.2-1
999 [26 Aug 2003] DSA-374 libpam-smb - buffer overflow
1000 {CAN-2003-0686}
1001 NOTE: not in sid/sarge
1002 [16 Aug 2003] DSA-373 autorespond - buffer overflow
1003 {CAN-2003-0654}
1004 - autorespond 2.0.4-1
1005 [16 Aug 2003] DSA-372 netris - buffer overflow
1006 {CAN-2003-0685}
1007 - netris 0.52-1
1008 [11 Aug 2003] DSA-371 perl - cross-site scripting
1009 {CAN-2003-0615}
1010 - perl 5.8.0-19
1011 [08 Aug 2003] DSA-370 pam-pgsql - format string
1012 {CAN-2003-0672}
1013 - pam-pgsql 0.5.2-7
1014 [08 Aug 2003] DSA-369 zblast - buffer overflow
1015 {CAN-2003-0613}
1016 - zblast 1.2.1-7
1017 [08 Aug 2003] DSA-368 xpcd - buffer overflow
1018 {CAN-2003-0649}
1019 - xpcd 2.08-9
1020 [08 Aug 2003] DSA-367 xtokkaetama - buffer overflow
1021 {CAN-2003-0652}
1022 - xtokkaetama 1.0b-9
1023 [05 Aug 2003] DSA-366 eroaster - insecure temporary file
1024 {CAN-2003-0656}
1025 - eroaster 2.2.0-0.5-1
1026 [05 Aug 2003] DSA-365 phpgroupware - several vulnerabilities
1027 {CAN-2003-0504 CAN-2003-0599 CAN-2003-0657}
1028 - phpgroupware 0.9.14.007-1)
1029 [04 Aug 2003] DSA-364 man-db - buffer overflows, arbitrary command execution
1030 {CAN-2003-0620 CAN-2003-0645}
1031 - man-db 2.4.1-13
1032 [03 Aug 2003] DSA-363 postfix - denial of service, bounce-scanning
1033 {CAN-2003-0468 CAN-2003-0540}
1034 - postfix 1.1.12
1035 [02 Aug 2003] DSA-362 mindi - insecure temporary file
1036 {CAN-2003-0617}
1037 - mindi 0.86-1
1038 [01 Aug 2003] DSA-361 kdelibs, kdelibs-crypto - several vulnerabilities
1039 {CAN-2003-0459 CAN-2003-0370}
1040 - kdelibs 4:3.1.3-1
1041 [01 Aug 2003] DSA-360 xfstt - several vulnerabilities
1042 {CAN-2003-0581}
1043 - xfstt 1.5-1
1044 {CAN-2003-0625}
1045 - xfstt 1.5.1-1
1046 [31 Jul 2003] DSA-359 atari800 - buffer overflows
1047 {CAN-2003-0630}
1048 - atari800 1.3.1-2
1049 [31 Jul 2003] DSA-358 linux-kernel-2.4.18 - several vulnerabilities
1050 {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}
1051 NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.
1052 [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit
1053 {CAN-2003-0466}
1054 - wu-ftpd 2.6.2-12
1055 [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows
1056 {CAN-2003-0611}
1057 - xtokkaetama 1.0b-8
1058 [30 Jul 2003] DSA-355 gallery - cross-site scripting
1059 {CAN-2003-0614}
1060 - gallery 1.3.4-3
1061 [29 Jul 2003] DSA-354 xconq - buffer overflows
1062 {CAN-2003-0607}
1063 - xconq 7.4.1-2.1
1064 [29 Jul 2003] DSA-353 sup - insecure temporary file
1065 {CAN-2003-0606}
1066 - sup 1.8-9
1067 [22 Jul 2003] DSA-352 fdclone - insecure temporary directory
1068 {CAN-2003-0596}
1069 - fdclone 2.04-1
1070 [16 Jul 2003] DSA-351 php4 - cross-site scripting
1071 {CAN-2003-0442}
1072 - php4 4:4.3.2+rc3-1
1073 [15 Jul 2003] DSA-350 falconseye - buffer overflow
1074 {CAN-2003-0358}
1075 NOTE: not in testing, fixed in unstable
1076 - falconseye 1.9.3-9
1077 [14 Jul 2003] DSA-349 nfs-utils - buffer overflow
1078 {CAN-2003-0252}
1079 - nfs-utils 1:1.0.3-2
1080 [11 Jul 2003] DSA-348 traceroute-nanog - integer overflow, buffer overflow
1081 {CAN-2003-0453}
1082 - traceroute-nanog 6.1.1-1.3
1083 [08 Jul 2003] DSA-347 teapop - SQL injection
1084 {CAN-2003-0515}
1085 - teapop 0.3.5-2
1086 [08 Jul 2003] DSA-346 phpsysinfo - directory traversal
1087 {CAN-2003-0536}
1088 - phpsysinfo 2.1-1
1089 [08 Jul 2003] DSA-345 xbl - buffer overflow
1090 {CAN-2003-0535}
1091 - xbl 1.0k-6
1092 [08 Jul 2003] DSA-344 unzip - directory traversal
1093 {CAN-2003-0282}
1094 - unzip 5.50-3
1095 [08 Jul 2003] DSA-343 skk, ddskk - insecure temporary file
1096 {CAN-2003-0539}
1097 - skk 10.62a-6
1098 - ddskk 12.1.cvs.20030622-1
1099 [07 Jul 2003] DSA-342 mozart - unsafe mailcap configuration
1100 {CAN-2003-0538}
1101 NOTE: mozart is not in sarge
1102 - mozart 1.2.5.20030212-2
1103 [07 Jul 2003] DSA-341 liece - insecure temporary file
1104 {CAN-2003-0537}
1105 - liece 2.0+0.20030527cvs-1
1106 [06 Jul 2003] DSA-340 x-face-el - insecure temporary file
1107 - x-face-el 1.3.6.23-1
1108 [06 Jul 2003] DSA-339 semi - insecure temporary file
1109 {CAN-2003-0440}
1110 - semi 1.14.5+20030609-1
1111 [29 Jun 2003] DSA-338 proftpd - SQL injection
1112 {CAN-2003-0500}
1113 - proftpd 1.2.8-8
1114 [29 Jun 2003] DSA-337 gtksee - buffer overflow
1115 {CAN-2003-0444}
1116 ! gtksee 0.5.6-1
1117 [29 Jun 2003] DSA-336 linux-kernel-2.2.20 - several vulnerabilities
1118 {CAN-2002-1380 CVE-2002-0429 CAN-2003-0001 CAN-2003-0127 CAN-2003-0364 CAN-2003-0246 CAN-2003-0244 CAN-2003-0247 CAN-2003-0248}
1119 - kernel-source-2.2.25 2.2.25-3
1120 NOTE: did not check newer kernels
1121 [28 Jun 2003] DSA-335 mantis - incorrect permissions
1122 {CAN-2003-0499}
1123 - mantis 0.17.5-6
1124 [28 Jun 2003] DSA-334 xgalaga - buffer overflows
1125 {CAN-2003-0454}
1126 - xgalaga 2.0.34-22
1127 [27 Jun 2003] DSA-333 acm - integer overflow
1128 {CVE-2002-0391}
1129 - acm 5.0-10
1130 [27 Jun 2003] DSA-332 linux-kernel-2.4.17 - several vulnerabilities
1131 {CVE-2002-0429 CAN-2003-0001 CAN-2003-0127 CAN-2003-0244 CAN-2003-0246 CAN-2003-0247 CAN-2003-0248 CAN-2003-0364}
1132 NOTE: note in the archive, and did not check newer kernels
1133 [27 Jun 2003] DSA-331 imagemagick - insecure temporary file
1134 {CAN-2003-0455}
1135 - imagemagick 4:5.5.7-1
1136 [23 Jun 2003] DSA-330 tcptraceroute - failure to drop root privileges
1137 {CAN-2003-0489}
1138 - tcptraceroute 1.4-4
1139 [20 Jun 2003] DSA-329 osh - buffer overflows
1140 {CAN-2003-0452}
1141 - osh 1.7-12
1142 [19 Jun 2003] DSA-328 webfs - buffer overflow
1143 {CAN-2003-0445}
1144 - webfs 1.20
1145 [19 Jun 2003] DSA-327 xbl - buffer overflows
1146 {CAN-2003-0451}
1147 - xbl 1.0k-5
1148 [19 Jun 2003] DSA-326 orville-write - buffer overflows
1149 {CAN-2003-0441}
1150 - orville-write 2.54-1
1151 [19 Jun 2003] DSA-325 eldav - insecure temporary file
1152 {CAN-2003-0438}
1153 - eldav 0.7.2-1
1154 [18 Jun 2003] DSA-324 ethereal - several vulnerabilities
1155 {CAN-2003-0428 CAN-2003-0429 CAN-2003-0431 CAN-2003-0432}
1156 - ethereal 0.9.13-1.
1157 [16 Jun 2003] DSA-323 noweb - insecure temporary files
1158 {CAN-2003-0381}
1159 - noweb 2.10c-2
1160 [16 Jun 2003] DSA-322 typespeed - buffer overflow
1161 {CAN-2003-0435}
1162 - typespeed 0.4.4
1163 [13 Jun 2003] DSA-321 radiusd-cistron - buffer overflow
1164 {CAN-2003-0450}
1165 - radiusd-cistron 1.6.6-2
1166 [13 Jun 2003] DSA-320 mikmod - buffer overflow
1167 {CAN-2003-0427}
1168 - mikmod 3.1.6-6
1169 [12 Jun 2003] DSA-319 webmin - session ID spoofing
1170 {CAN-2003-0101}
1171 - webmin 1.070-1
1172 [12 Jun 2003] DSA-318 lyskom-server - denial of service
1173 {CAN-2003-0366}
1174 - lyskom-server 2.0.7-2
1175 [11 Jun 2003] DSA-317 cupsys - denial of service
1176 {CAN-2003-0195}
1177 - cupsys 1.1.19final-1
1178 [11 Jun 2003] DSA-316 nethack - buffer overflow, incorrect permissions
1179 {CAN-2003-0358 CAN-2003-0359}
1180 - nethack 3.4.1-1
1181 - slashem 0.0.6E4F8-6
1182 - jnethack 1.1.5-15
1183 NOTE: DSA contains some strange non-nethack version numbers
1184 [11 Jun 2003] DSA-315 gnocatan - buffer overflows, denial of service
1185 {CAN-2003-0433}
1186 HELP: no mention of any security fixes in debian changelog,
1187 HELP: upstream changelog. Mailed maintainer.
1188 [11 Jun 2003] DSA-314 atftp - buffer overflow
1189 {CAN-2003-0380}
1190 - atftp 0.6.2
1191 [11 Jun 2003] DSA-313 ethereal - buffer overflows, integer overflows
1192 {CAN-2003-0356 CAN-2003-0357}
1193 - ethereal 0.9.12-1
1194 [09 Jun 2003] DSA-312 kernel-patch-2.4.18-powerpc - several vulnerabilities
1195 {CVE-2002-0429 CAN-2003-0001 CAN-2003-0127 CAN-2003-0244 CAN-2003-0246 CAN-2003-0247 CAN-2003-0248}
1196 NOTE: not in unstable/testing. Did not check other versions.
1197 [08 Jun 2003] DSA-311 linux-kernel-2.4.18 - several vulnerabilities
1198 {CVE-2002-0429 CAN-2003-0001 CAN-2003-0127 CAN-2003-0244 CAN-2003-0246 CAN-2003-0247 CAN-2003-0248 CAN-2003-0364}
1199 NOTE: not in unstable/testing. Did not check other versions.
1200 [08 Jun 2003] DSA-310 xaos - improper setuid-root execution
1201 {CAN-2003-0385}
1202 - xaos 3.1r-4
1203 [06 Jun 2003] DSA-309 eterm - buffer overflow
1204 {CAN-2003-0382}
1205 - eterm 0.9.2-1
1206 [06 Jun 2003] DSA-308 gzip - insecure temporary files
1207 {CVE-1999-1332 CAN-2003-0367}
1208 - gzip 1.3.5-6
1209 [27 May 2003] DSA-307 gps - multiple vulnerabilities
1210 {CAN-2003-0361 CAN-2003-0360 CAN-2003-0362}
1211 - gps 1.1.0-1
1212 [19 May 2003] DSA-306 ircii-pana - buffer overflows, integer overflow
1213 {CAN-2003-0321 CAN-2003-0322 CAN-2003-0328}
1214 - ircii-pana 1:1.0-0c19-8
1215 [15 May 2003] DSA-305 sendmail - insecure temporary files
1216 {CAN-2003-0308}
1217 - sendmail 8.12.9-2
1218 [15 May 2003] DSA-304 lv - privilege escalation
1219 {CAN-2003-0188}
1220 - lv 4.49.5-2
1221 [15 May 2003] DSA-303 mysql - privilege escalation
1222 {CAN-2003-0073}
1223 - mysql-dfsg 4.0.12-2
1224 {CAN-2003-0150}
1225 HELP: not sure if this is fixed
1226 [07 May 2003] DSA-302 fuzz - privilege escalation
1227 {CAN-2003-0261}
1228 - fuzz 0.6-7.1
1229 [07 May 2003] DSA-301 libgtop - buffer overflow
1230 {CAN-2001-0928}
1231 - libgtop 1.0.13-4
1232 [06 May 2003] DSA-300 balsa - buffer overflow
1233 {CAN-2003-0167}
1234 - balse 2.0.10
1235 [06 May 2003] DSA-299 leksbot - improper setuid-root execution
1236 {CAN-2003-0262}
1237 - lexbot 1.2-5
1238 [02 May 2003] DSA-298 epic4 - buffer overflows
1239 {CAN-2003-0323}
1240 - epic4 1:1.1.11.20030409-1
1241 [01 May 2003] DSA-297 snort - integer overflow, buffer overflow
1242 {CAN-2003-0033 CAN-2003-0209}
1243 - snort 2.0.0-1
1244 [30 Apr 2003] DSA-296 kdebase - insecure execution
1245 {CAN-2003-0204}
1246 - kdebase 4:3.1.0-1
1247 [30 Apr 2003] DSA-295 pptpd - buffer overflow
1248 {CAN-2003-0213}
1249 - pptpd 1.1.4-0.b3.2
1250 [23 Apr 2003] DSA-294 gkrellm-newsticker - missing quoting, incomplete parser
1251 {CAN-2003-0205 CAN-2003-0206}
1252 NOTE: not in unstable/testing
1253 [23 Apr 2003] DSA-293 kdelibs - insecure execution
1254 {CAN-2003-0204}
1255 - kdebase 4:3.1.0-1
1256 [22 Apr 2003] DSA-292 mime-support - insecure temporary file creation
1257 {CAN-2003-0214}
1258 - mime-support 3.23-1
1259 [22 Apr 2003] DSA-291 ircii - buffer overflows
1260 {CAN-2003-0323}
1261 - ircii 20030315-1
1262 [17 Apr 2003] DSA-290 sendmail-wide - char-to-int conversion
1263 {CAN-2003-0161}
1264 - sendmail-wide 8.12.9+3.5Wbeta-1
1265 [17 Apr 2003] DSA-289 rinetd - incorrect memory resizing
1266 {CAN-2003-0212}
1267 - rinetd 0.61-2
1268 [17 Apr 2003] DSA-288 openssl - several vulnerabilities
1269 {CAN-2003-0147 CAN-2003-0131}
1270 - openssl 0.9.7b-1
1271 - openssl096 0.9.6j-1
1272 [15 Apr 2003] DSA-287 epic - buffer overflows
1273 {CAN-2003-0324}
1274 - epic4 1:1.1.11.20030409-1
1275 [14 Apr 2003] DSA-286 gs-common - insecure temporary file
1276 {CAN-2003-0207}
1277 - gs-common 0.3.3.1
1278 [14 Apr 2003] DSA-285 lprng - insecure temporary file
1279 {CAN-2003-0136}
1280 - lprng 3.8.20-4.
1281 [12 Apr 2003] DSA-284 kdegraphics - insecure execution
1282 {CAN-2003-0204}
1283 - kdegraphics 4:3.1.0-1
1284 [11 Apr 2003] DSA-283 xfsdump - insecure file creation
1285 {CAN-2003-0173}
1286 - xfsdump 2.2.8-1
1287 [09 Apr 2003] DSA-282 glibc - integer overflow
1288 {CAN-2003-0028}
1289 - glibc 2.3.1-16
1290 [08 Apr 2003] DSA-281 moxftp - buffer overflow
1291 {CAN-2003-0203}
1292 - moxftp 2.2-18.20
1293 [07 Apr 2003] DSA-280 samba - buffer overflow
1294 {CAN-2003-0201 CAN-2003-0196}
1295 - samba 3.0
1296 [07 Apr 2003] DSA-279 metrics - insecure temporary file creation
1297 {CAN-2003-0202}
1298 NOTE: note in unstable/testing
1299 [04 Apr 2003] DSA-278 sendmail - char-to-int conversion
1300 {CAN-2003-0161}
1301 - sendmail 8.12.9-1
1302 [03 Apr 2003] DSA-277 apcupsd - buffer overflows, format string
1303 {CAN-2003-0098 CAN-2003-0099}
1304 - apcupsd 3.8.5-1.2
1305 [03 Apr 2003] DSA-276 linux-kernel-s390 - local privilege escalation
1306 {CAN-2003-0127}
1307 NOTE: this version is not in sarge, did not check others
1308 [02 Apr 2003] DSA-275 lpr-ppd - buffer overflow
1309 {CAN-2003-0144}
1310 - lpr-ppd 1:0.72-3
1311 [28 Mar 2003] DSA-274 mutt - buffer overflow
1312 {CAN-2003-0167}
1313 - mutt 1.4.0
1314 [28 Mar 2003] DSA-273 krb4 - Cryptographic weakness
1315 {CAN-2003-0138 CAN-2003-0139}
1316 - krb4 1.2.2-1
1317 [28 Mar 2003] DSA-272 dietlibc - integer overflow
1318 {CAN-2003-0028}
1319 - dietlibc 0.22-2
1320 [27 Mar 2003] DSA-271 ecartis - unauthorized password change
1321 {CAN-2003-0162}
1322 - ecartis 1.0.0+cvs.20030321-1
1323 [27 Mar 2003] DSA-270 linux-kernel-mips - local privilege escalation
1324 {CAN-2003-0127}
1325 NOTE: not in unstable/testing, did not check other versions
1326 [26 Mar 2003] DSA-269 heimdal - Cryptographic weakness
1327 {CAN-2003-0138}
1328 - heimdal 0.5.2-1
1329 [25 Mar 2003] DSA-268 mutt - buffer overflow
1330 {CAN-2003-0140}
1331 - mutt 1.5.4-1
1332 [24 Mar 2003] DSA-267 lpr - buffer overflow
1333 {CAN-2003-0144}
1334 - lpr 1:2000.05.07-4.20
1335 [24 Mar 2003] DSA-266 krb5 - several vulnerabilities
1336 {CAN-2003-0028}
1337 - krb5 1.3.3-2
1338 NOTE: changelog does not mention this one, verified patch from
1339 NOTE: Tom Yu was applied to this version.
1340 {CAN-2003-0072}
1341 - krb5 1.2.7-3
1342 NOTE: changelog does not mention this one, verified patch from
1343 NOTE: upstream was applied to this version.
1344 {CAN-2003-0082}
1345 - krb5 1.3.3-2
1346 {CAN-2003-0138 VU#623217}
1347 - krb5 1.2.7-3
1348 {CAN-2003-0139 VU#442569}
1349 - krb5 1.2.7-3
1350 [21 Mar 2003] DSA-265 bonsai - several vulnerabilities
1351 {CAN-2003-0152 CAN-2003-0153 CAN-2003-0154 CAN-2003-0155}
1352 - bonsai 1.3+cvs20030317-1
1353 [19 Mar 2003] DSA-264 lxr - missing filename sanitizing
1354 {CAN-2003-0156}
1355 - lxr 0.3-4
1356 [17 Mar 2003] DSA-263 netpbm-free - math overflow errors
1357 {CAN-2003-0146}
1358 - netpbm-free 2:9.20-9
1359 [15 Mar 2003] DSA-262 samba - remote exploit
1360 {CAN-2003-0085 CAN-2003-0086}
1361 - samba 2.2.8
1362 [14 Mar 2003] DSA-261 tcpdump - infinite loop
1363 {CAN-2003-0093 CAN-2003-0145}
1364 NOTE: DSA reports sid was not affected, sarge has sid version
1365 [13 Mar 2003] DSA-260 file - buffer overflow
1366 {CAN-2003-0102}
1367 - file 3.40-1.1
1368 [12 Mar 2003] DSA-259 qpopper - mail user privilege escalation
1369 {CAN-2003-0143}
1370 - qpopper 4.0.4-9
1371 [10 Mar 2003] DSA-258 ethereal - format string vulnerability
1372 {CAN-2003-0081}
1373 - ethereal 0.9.9-2
1374 [04 Mar 2003] DSA-257 sendmail - remote exploit
1375 {CAN-2002-1337}
1376 - sendmail 8.12.8
1377 [28 Feb 2003] DSA-256 mhc - insecure temporary file
1378 {CAN-2003-0120}
1379 - mhc 0.25+20030224-1
1380 [27 Feb 2003] DSA-255 tcpdump - infinite loop
1381 {CAN-2003-0108 CAN-2002-0380}
1382 - tcpdump 3.7.1-1.2
1383 [27 Feb 2003] DSA-254 traceroute-nanog - buffer overflow
1384 {CAN-2002-1051 CAN-2002-1364 CAN-2002-1386 CAN-2002-1387}
1385 - traceroute-nanog 6.3.0-1
1386 [24 Feb 2003] DSA-253 openssl - information leak
1387 {CAN-2003-0078}
1388 - openssl 0.9.7a-1
1389 [21 Feb 2003] DSA-252 slocate - buffer overflow
1390 {CAN-2003-0056}
1391 - slocate 2.7-1
1392 [14 Feb 2003] DSA-251 w3m - missing HTML quoting
1393 {CAN-2002-1335 CAN-2002-1348}
1394 - w3m 0.3.2.2-1
1395 [12 Feb 2003] DSA-250 w3mmee-ssl - missing HTML quoting
1396 {CAN-2002-1335 CAN-2002-1348}
1397 NOTE: not in sid/sarge
1398 [11 Feb 2003] DSA-249 w3mmee - missing HTML quoting
1399 {CAN-2002-1335 CAN-2002-1348}
1400 - w3mmee 0.3.p24.17-3
1401 [31 Jan 2003] DSA-248 hypermail - buffer overflows
1402 {CAN-2003-0057}
1403 - hypermail 2.1.6-1
1404 [30 Jan 2003] DSA-247 courier-ssl - missing input sanitizing
1405 {CAN-2003-0040}
1406 - courier 0.40.2-3
1407 [29 Jan 2003] DSA-246 tomcat - information exposure, cross site scripting
1408 {CAN-2003-0042 CAN-2003-0043 CAN-2003-0044}
1409 NOTE: tomcat not in sid/sarge
1410 NOTE: tomcat4 not affected
1411 [28 Jan 2003] DSA-245 dhcp3 - ignored counter boundary
1412 {CAN-2003-0039}
1413 - dhcp3 1.1.2-1
1414 [27 Jan 2003] DSA-244 noffle - buffer overflows
1415 {CAN-2003-0037}
1416 - noffle 1.1.2-1
1417 [24 Jan 2003] DSA-243 kdemultimedia - several vulnerabilities
1418 {CAN-2002-1393}
1419 - kdemultimedia 4:3.1
1420 [24 Jan 2003] DSA-242 kdebase - several vulnerabilities
1421 {CAN-2002-1393}
1422 - kdebase 4:3.1
1423 [24 Jan 2003] DSA-241 kdeutils - several vulnerabilities
1424 {CAN-2002-1393}
1425 - kdeutils 4:3.1
1426 [23 Jan 2003] DSA-240 kdegames - several vulnerabilities
1427 {CAN-2002-1393}
1428 - kdegames 4:3.1
1429 [23 Jan 2003] DSA-239 kdesdk - several vulnerabilities
1430 {CAN-2002-1393}
1431 - kdesdk 4:3.1
1432 [23 Jan 2003] DSA-238 kdepim - several vulnerabilities
1433 {CAN-2002-1393}
1434 - kdepim 4:3.1
1435 [22 Jan 2003] DSA-237 kdenetwork - several vulnerabilities
1436 {CAN-2002-1393}
1437 - kdenetwork 4:3.1
1438 [22 Jan 2003] DSA-236 kdelibs - several vulnerabilities
1439 {CAN-2002-1393}
1440 - kdelibs 4:3.1
1441 [22 Jan 2003] DSA-235 kdegraphics - several vulnerabilities
1442 {CAN-2002-1393}
1443 - kdegraphics 4:3.1
1444 [22 Jan 2003] DSA-234 kdeadmin - several vulnerabilities
1445 {CAN-2002-1393}
1446 - kdeadmin 4:3.1
1447 [21 Jan 2003] DSA-233 cvs - doubly freed memory
1448 {CAN-2003-0015}
1449 - cvs 1.11.2-5.1
1450 [20 Jan 2003] DSA-232 cupsys - several vulnerabilities
1451 {CAN-2002-1366 CAN-2002-1367 CAN-2002-1368 CAN-2002-1369 CAN-2002-1371 CAN-2002-1372 CAN-2002-1383 CAN-2002-1384}
1452 - cupsys 1.1.18-1
1453 [17 Jan 2003] DSA-231 dhcp3 - stack overflows
1454 {CAN-2003-0026}
1455 - dhcp3 3.0+3.0.1rc11-1
1456 [16 Jan 2003] DSA-230 bugzilla - insecure permissions, spurious backup files
1457 NOTE: not in testing due to 3 newer security holes
1458 {CAN-2003-0012}
1459 - bugzilla 2.16.2
1460 {CAN-2003-0013}
1461 - bugzilla 2.16.2
1462 [15 Jan 2003] DSA-229 imp - SQL injection
1463 {CAN-2003-0025}
1464 NOTE: I think imp3 is ok.
1465 [14 Jan 2003] DSA-228 libmcrypt - buffer overflows and memory leak
1466 {CAN-2003-0031 CAN-2003-0032}
1467 - libmcrypt 2.5.5-1
1468 [13 Jan 2003] DSA-227 openldap2 - buffer overflows and other bugs
1469 {CAN-2002-1378 CAN-2002-1379 CAN-2002-1508}
1470 - openldap2 2.0.27-3
1471 [10 Jan 2003] DSA-226 xpdf-i - integer overflow
1472 {CAN-2002-1384}
1473 - xpdf 2.01-2
1474 [09 Jan 2003] DSA-225 tomcat4 - source disclosure
1475 {CAN-2002-1394}
1476 ! tomcat4 4.1.16-1
1477 NOTE another RC (unreproducible?) bug and missing deps (#263201)
1478 NOTE are keeping the fix out of testing
1479 NOTE this is the second unfixed security hole in tomcat4 in testing..
1480 [08 Jan 2003] DSA-224 canna - buffer overflow and more
1481 {CAN-2002-1158 CAN-2002-1159}
1482 - canna 3.6p1-1
1483 [07 Jan 2003] DSA-223 geneweb - information exposure
1484 {CAN-2002-1390}
1485 - geneweb 4.09-1
1486 [06 Jan 2003] DSA-222 xpdf - integer overflow
1487 {CAN-2002-1384}
1488 - xpdf 2.01-2
1489 [03 Jan 2003] DSA-221 mhonarc - cross site scripting
1490 {CAN-2002-1388}
1491 - mhonarc 2.5.14-1
1492 [02 Jan 2003] DSA-220 squirrelmail - cross site scripting
1493 {CAN-2002-1341}
1494 - squirrelmail 1:1.3.2-2
1495
1496 ------- These processed by Djoumé SALVETTI <salvetti@crans.org> -----
1497
1498 [31 Dec 2002] DSA-219 dhcpcd - remote command execution
1499 {CAN-2002-1403}
1500 - dhcpcd 1.3.22pl2-2
1501 [30 Dec 2002] DSA-218 bugzilla - cross site scripting
1502 NOTE: not in testing, fixed in unstable (bugzilla 2.16.2-1).
1503 [27 Dec 2002] DSA-217 typespeed - buffer overflow
1504 {CAN-2002-1389}
1505 - typespeed 0.4.2-2
1506 [24 Dec 2002] DSA-216 fetchmail - buffer overflow
1507 {CAN-2002-1365}
1508 - fetchmail 6.2.0-1
1509 [23 Dec 2002] DSA-215 cyrus-imapd - buffer overflow
1510 {CAN-2002-1580}
1511 - cyrus-imapd 1.5.19-9.10
1512 [20 Dec 2002] DSA-214 kdnetwork - buffer overflows
1513 {CAN-2002-1306}
1514 - kdenetwork 2.2.2-14.20
1515 NOTE: there is a typo in the DSA, the name of the package is kdenetwork.
1516 [19 Dec 2002] DSA-213 libpng - buffer overflow
1517 {CAN-2002-1363}
1518 - libpng 1.0.12-7
1519 - libpng3 1.2.5-8
1520 [17 Dec 2002] DSA-212 mysql - multiple problems
1521 {CAN-2002-1373 CAN-2002-1374 CAN-2002-1375 CAN-2002-1376}
1522 - mysql-dfsg 4.0.7.gamma-1
1523 [13 Dec 2002] DSA-211 micq - denial of service
1524 {CAN-2002-1362}
1525 NOTE: not in testing nor unstable (was fixed in 0.4.9.4-1)
1526 [13 Dec 2002] DSA-210 lynx - CRLF injection
1527 {CAN-2002-1405}
1528 - lynx 2.8.4.1b-4
1529 NOTE: lynx-ssl not in testing nor unstable.
1530 [12 Dec 2002] DSA-209 wget - directory traversal
1531 {CAN-2002-1344}
1532 - wget 1.8.2-8
1533 [12 Dec 2002] DSA-208 perl - broken safe compartment
1534 {CAN-2002-1323}
1535 - perl 5.8.0-14
1536 [11 Dec 2002] DSA-207 tetex-bin - arbitrary command execution
1537 {CAN-2002-0836}
1538 - tetex-bin 1.0.7+20021025-4
1539 [10 Dec 2002] DSA-206 tcpdump - denial of service
1540 {CAN-2002-1350}
1541 - tcpdump 3.7.2-1
1542 [10 Dec 2002] DSA-205 gtetrinet - buffer overflow
1543 - gtetrinet 0.4.4-1
1544 NOTE: no CAN not CVE for this one
1545 [05 Dec 2002] DSA-204 kdelibs - arbitrary program execution
1546 {CAN-2002-1281 CAN-2002-1282}
1547 - kdelibs 4:3.1.0-1
1548 [04 Dec 2002] DSA-203 smb2www - arbitrary command execution
1549 {CAN-2002-1342}
1550 - smb2www 980804-17
1551 [03 Dec 2002] DSA-202 im - insecure temporary files
1552 {CAN-2002-1395}
1553 - im 141-20
1554 [02 Dec 2002] DSA-201 freeswan - denial of service
1555 {CAN-2002-0666 VU#459371}
1556 - freeswan 1.99-1
1557 [22 Nov 2002] DSA-200 samba - remote exploit
1558 {CAN-2002-1318}
1559 - samba 2.99.cvs.20020713-1
1560 [19 Nov 2002] DSA-199 mhonarc - cross site scripting
1561 {CAN-2002-1307}
1562 - mhonarc 2.5.13-1
1563 [18 Nov 2002] DSA-198 nullmailer - denial of service
1564 {CAN-2002-1313}
1565 - nullmailer 1.00RC5-17
1566 [15 Nov 2002] DSA-197 courier - buffer overflow
1567 {CAN-2002-1311}
1568 - courier 0.40.0-1
1569 [14 Nov 2002] DSA-196 bind - several vulnerabilities
1570 {CAN-2002-0029 CAN-2002-1219 CAN-2002-1220 CAN-2002-1221}
1571 - bind 8.3.3-3
1572 [13 Nov 2002] DSA-195 apache-perl - several vulnerabilities
1573 {CAN-2002-0839 CAN-2002-0840 CAN-2002-0843 CAN-2001-0131 CAN-2002-1233}
1574 - apache-perl 1.3.26-1.1-1.27-3-1
1575 [12 Nov 2002] DSA-194 masqmail - buffer overflows
1576 {CAN-2002-1279}
1577 - masqmail 0.2.15-1
1578 [11 Nov 2002] DSA-193 kdenetwork - buffer overflow
1579 {CAN-2002-1247}
1580 - kdenetwok 2.2.2-14.3
1581 [08 Nov 2002] DSA-192 html2ps - arbitrary code execution
1582 {CAN-2002-1275}
1583 - html2ps 1.0b3-2
1584 [07 Nov 2002] DSA-191 squirrelmail - cross site scripting
1585 {CAN-2002-1131 CAN-2002-1132 CAN-2002-1276}
1586 - squirrelmail 1.2.8-1.1
1587 [07 Nov 2002] DSA-190 wmaker - buffer overflow
1588 {CAN-2002-1277}
1589 - wmaker 0.80.1-4
1590 [06 Nov 2002] DSA-189 luxman - local root exploit
1591 {CAN-2002-1245}
1592 - luxman 0.41-19
1593 [05 Nov 2002] DSA-188 apache-ssl - several vulnerabilities
1594 {CAN-2002-0839 CAN-2002-0840 CAN-2002-0843}
1595 - apache 1.3.27-0.1
1596 {CAN-2001-0131 CAN-2002-1233}
1597 - apache 1.3.27-1
1598 HELP: note sure about this
1599 NOTE: I have mailed maintainers
1600 {NO-CAN Several buffer overflows in ApacheBench}
1601 HELP: I don't know about this
1602 NOTE: I have mailed maintainers
1603 [04 Nov 2002] DSA-187 apache - several vulnerabilities
1604 {CAN-2002-0839 CAN-2002-0840 CAN-2002-0843}
1605 - apache 1.3.27-0.1
1606 {CAN-2001-0131 CAN-2002-1233}
1607 - apache 1.3.27-1
1608 HELP: note sure about this
1609 NOTE: I have mailed maintainers
1610 {NO-CAN Several buffer overflows in ApacheBench}
1611 HELP: I don't know about this
1612 NOTE: I have mailed maintainers
1613 [01 Nov 2002] DSA-186 log2mail - buffer overflow
1614 {CAN-2002-1251}
1615 - log2mail 0.2.6-1
1616 [31 Oct 2002] DSA-185 heimdal - buffer overflow
1617 {CAN-2002-1235}
1618 - heimdal 0.4e-22
1619 [30 Oct 2002] DSA-184 krb4 - buffer overflow
1620 {CAN-2002-1235}
1621 - krb4 1.1-11-8
1622 [29 Oct 2002] DSA-183 krb5 - buffer overflow
1623 {CAN-2002-1235}
1624 - krb5 1.2.6-2
1625 [28 Oct 2002] DSA-182 kdegraphics - buffer overflow
1626 {CAN-2002-0838}
1627 - kdegraphics 2.2.2-6.9
1628 [22 Oct 2002] DSA-181 libapache-mod-ssl - cross site scripting
1629 {CAN-2002-1157}
1630 - libapache-mod-ssl 2.8.9-2.3
1631 [21 Oct 2002] DSA-180 nis - information leak
1632 {CAN-2002-1232}
1633 - nis 3.9-6.2
1634 [18 Oct 2002] DSA-179 gnome-gv - buffer overflow
1635 {CAN-2002-0838}
1636 - gnome-gv 1.99.7-9
1637 [17 Oct 2002] DSA-178 heimdal - remote command execution
1638 {CAN-2002-1225 CAN-2002-1226}
1639 - heimdal 0.4e-21
1640 [17 Oct 2002] DSA-177 pam - serious security violation
1641 {CAN-2002-1227}
1642 - pam 0.76-6
1643 [16 Oct 2002] DSA-176 gv - buffer overflow
1644 {CAN-2002-0838}
1645 - gv 3.5.8-27
1646 [15 Oct 2002] DSA-175 syslog-ng - buffer overflow
1647 {CAN-2002-1200}
1648 - syslog-ng 1.5.21-1
1649 [14 Oct 2002] DSA-174 heartbeat - buffer overflow
1650 {CAN-2002-1215}
1651 - heartbeat 0.4.9.2-1
1652 [09 Oct 2002] DSA-173 bugzilla - privilege escalation
1653 {CAN-2002-1196}
1654 NOTE: not in testing, fixed in unstable (bugzilla 2.16.0-2.1)
1655 [08 Oct 2002] DSA-172 tkmail - insecure temporary files
1656 {CAN-2002-1193}
1657 NOTE: not in testing nor unstable (was fixed in 4.0beta9-9)
1658 [07 Oct 2002] DSA-171 fetchmail - buffer overflows
1659 {CAN-2002-1175 CAN-2002-1174}
1660 - fetchmail 6.1.0-1
1661 NOTE: fetchmail-ssl not in testing, fixed in unstable (fetchmail-ssl 6.1.0-1)
1662 [04 Oct 2002] DSA-170 tomcat4 - source code disclosure
1663 {CAN-2002-1148}
1664 ! tomcat4 4.1.12-1
1665 NOTE: only 4.0.4-4 in testing (which seems to be vulnerable)
1666 [25 Sep 2002] DSA-169 htcheck - cross site scripting
1667 {CAN-2002-1195}
1668 - htcheck 1.1-1.2
1669 [18 Sep 2002] DSA-168 php - bypassing safe_mode, CRLF injection
1670 {CAN-2002-0985 CAN-2002-0986}
1671 - php3 3.0.18-23.2
1672 - php4 4.2.3-3
1673 NOTE: php3 is not in testing, it seems to be wait for tiff and gcc transition
1674 NOTE: and is out of date on alpha and arm
1675 [16 Sep 2002] DSA-167 kdelibs - cross site scripting
1676 {CAN-2002-1151}
1677 - kdelibs 2.2.2-14
1678 NOTE: there is a typo in the DSA that mentionned Konquerer instead of kdelibs
1679 [13 Sep 2002] DSA-166 purity - buffer overflows
1680 {CAN-2002-1124}
1681 - purity 1-16
1682 [12 Sep 2002] DSA-165 postgresql - buffer overflows
1683 {CAN-2002-0972 CAN-2002-1398 CAN-2002-1400 CAN-2002-1401 CVE-2002-1402}
1684 - postgresql 7.2.2-2
1685 [10 Sep 2002] DSA-164 cacti - arbitrary code execution
1686 {CAN-2002-1477 CAN-2002-1478}
1687 - cacti 0.6.8a-2
1688 [09 Sep 2002] DSA-163 mhonarc - cross site scripting
1689 {CVE-2002-0738}
1690 - mhonarc 2.5.11-1
1691 [06 Sep 2002] DSA-162 ethereal - buffer overflow
1692 {CAN-2002-0834}
1693 - ethereal 0.9.6-1
1694 [04 Sep 2002] DSA-161 mantis - privilege escalation
1695 {CAN-2002-1115 CAN-2002-1116}
1696 - mantis 0.17.5-2
1697 [03 Sep 2002] DSA-160 scrollkeeper - insecure temporary file creation
1698 {CAN-2002-0662}
1699 - scrollkeeper 0.3.11-2
1700 [28 Aug 2002] DSA-159 python - insecure temporary files
1701 {CAN-2002-1119}
1702 - python2.1 2.1.3-6a
1703 - python2.2 2.2.1-8
1704 NOTE: python1.5 not in testing nor unstable (was fixed in 1.5.2-24)
1705 NOTE: python2.3 is not vulnerable
1706 [27 Aug 2002] DSA-158 gaim - arbitrary program execution
1707 {CVE-2002-0989}
1708 - gaim 0.59.1-2
1709 [23 Aug 2002] DSA-157 irssi-text - denial of service
1710 {CAN-2002-0983}
1711 - irssi-text 0.8.5-2
1712 [22 Aug 2002] DSA-156 epic4-script-light - arbitrary script execution
1713 {CVE-2002-0984}
1714 - epic4-script-light 2.7.30p5-2
1715 [17 Aug 2002] DSA-155 kdelibs - privacy escalation with Konqueror
1716 {CAN-2002-0970}
1717 - kdelibs 4:2.2.2-14
1718 [15 Aug 2002] DSA-154 fam - privilege escalation
1719 {CVE-2002-0875}
1720 - fam 2.6.8-1
1721 [14 Aug 2002] DSA-153 mantis - cross site code execution and privilege escalation
1722 {CAN-2002-1114 CAN-2002-1113 CAN-2002-1112 CAN-2002-1111 CAN-2002-1110}
1723 - mantis 0.17.4a-2
1724 [13 Aug 2002] DSA-152 l2tpd - missing random seed
1725 {CVE-2002-0872 CVE-2002-0873}
1726 NOTE: not in testing (was fixed in unstable 0.68-1)
1727 [13 Aug 2002] DSA-151 xinetd - pipe exposure
1728 {CVE-2002-0871}
1729 - xinetd 2.3.7-1
1730 [13 Aug 2002] DSA-150 interchange - illegal file exposition
1731 {CAN-2002-0874}
1732 - interchange 4.8.6-1
1733 [13 Aug 2002] DSA-149 glibc - integer overflow
1734 {CVE-2002-0391}
1735 - glibc 2.2.5-13
1736 [12 Aug 2002] DSA-148 hylafax - buffer overflows and format string vulnerabilities
1737 {CVE-2002-1049 CVE-2002-1050 CAN-2001-1034}
1738 - hylafax 4.1.2-2.1
1739 [08 Aug 2002] DSA-147 mailman - cross-site scripting
1740 {CAN-2002-0388 CAN-2002-0855}
1741 - mailman 2.0.12-1
1742 [08 Aug 2002] DSA-146 dietlibc - integer overflow
1743 {CVE-2002-0391}
1744 - dietlibc 0.20-0cvs20020808
1745 [07 Aug 2002] DSA-145 tinyproxy - doubly freed memory
1746 {CVE-2002-0847}
1747 - tinyproxy 1.4.3-3
1748 [06 Aug 2002] DSA-144 wwwoffle - improper input handling
1749 {CVE-2002-0818}
1750 - wwwoffle 2.7d-1
1751 [05 Aug 2002] DSA-143 krb5 - integer overflow
1752 {CVE-2002-0391}
1753 - krb5 1.2.5-2
1754 [05 Aug 2002] DSA-142 openafs - integer overflow
1755 {CVE-2002-0391}
1756 - openafs 1.2.6-1
1757 [01 Aug 2002] DSA-141 mpack - buffer overflow
1758 {CAN-2002-1425}
1759 - mpack 1.5-9
1760 [05 Aug 2002] DSA-140 libpng - buffer overflow
1761 {CAN-2002-0660 CAN-2002-0728}
1762 - libpng 1.0.12-4
1763 - libpng3 1.2.1-2
1764 [01 Aug 2002] DSA-139 super - format string vulnerability
1765 {CVE-2002-0817}
1766 - super 3.18.0-3
1767 [01 Aug 2002] DSA-138 gallery - remote exploit
1768 {CAN-2002-1412}
1769 - gallery 1.3-3
1770 [30 Jul 2002] DSA-137 mm - insecure temporary files
1771 {CVE-2002-0658}
1772 - mm 1.1.3-7
1773 [30 Jul 2002] DSA-136 openssl - multiple remote exploits
1774 {CAN-2002-0655 CAN-2002-0656 CAN-2002-0657 CAN-2002-0659}
1775 - openssl 0.9.6e-1

  ViewVC Help
Powered by ViewVC 1.1.5