/[secure-testing]/data/DSA/list
ViewVC logotype

Diff of /data/DSA/list

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

sarge-checks/DSA/list revision 221 by joeyh, Fri Dec 31 17:07:58 2004 UTC data/DSA/list revision 1434 by jmm-guest, Tue Jul 19 08:01:18 2005 UTC
# Line 1  Line 1 
1    [19 Jul 2005] DSA-761-1 heartbeat - insecure temporary files
2            {CAN-2005-2231}
3            - heartbeat 1.2.3-12
4            NOTE: not fixed in testing at time of DSA (only 0/2 days old)
5    [18 Jul 2005] DSA-760-1 ekg - several
6            {CAN-2005-1850 CAN-2005-1851 CAN-2005-1916}
7            - ekg 1.5+20050712+1.6rc2-1 (low)
8            NOTE: not fixed in testing at time of DSA (waiting on dependencies, not built on five archs)
9    [18 Jul 2005] DSA-759-1 phppgadmin - missing input sanitising
10            {CAN-2005-2256}
11            - phppgadmin 3.5.4-1 (medium)
12            NOTE: not fixed in testing at time of DSA (only 0/10 days old)
13    [18 Jul 2005] DSA-758-1 heimdal - buffer overflow
14            {CAN-2005-2040}
15            - heimdal 0.6.3-11 (medium)
16            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
17    [17 Jul 2005] DSA-757-1 krb5 - buffer overflow, double-free memory
18            {CAN-2005-1689 CAN-2005-1174 CAN-2005-1175}
19            - krb5 1.3.6-4 (medium)
20            NOTE: not fixed in testing at time of DSA (waiting on dependencies, not built on m68k)
21    [14 Jul 2005] DSA-746-1 phpgroupware - remote command execution
22            {CAN-2005-1921}
23            - phpgroupware 0.9.16.006-1 (high)
24            NOTE: fixed in testing at time of DSA
25    [13 Jul 2005] DSA-756-1 squirrelmail - several
26            {CAN-2005-1769 CAN-2005-2095}
27            - squirrelmail 2:1.4.4-6 (medium)
28            NOTE: not fixed in testing at time of DSA (only 0/2 days old)
29    [13 Jul 2005] DSA-755-1 tiff - buffer overflow
30            {CAN-2005-1544}
31            - tiff 3.7.2-3 (medium)
32            NOTE: fixed in testing at time of DSA
33    [13 Jul 2005] DSA-754-1 centericq - insecure temporary file
34            {CAN-2005-1914}
35            - centericq 4.20.0-7 (low)
36            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
37    [12 Jul 2005] DSA-753-1 gedit - format string
38            {CAN-2005-1686}
39            - gedit 2.10.3-1 (low)
40            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
41    [11 Jul 2005] DSA-752-1 gzip - several
42            {CAN-2005-0988 CAN-2005-1228}
43            - gzip 1.3.5-10
44            NOTE: fixed in testing at time of DSA
45    [11 Jul 2005] DSA-751-1 squid - IP spoofind
46            {CAN-2005-1519}
47            - squid 2.5.9-9
48            NOTE: fixed in testing at time of DSA
49    [10 Jul 2005] DSA-748-1 ruby1.8 - bad default value
50            {CAN-2005-1992}
51            - ruby1.8 1.8.2-8 (medium)
52            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
53    [11 Jul 2005] DSA-750-1 dhcpcd - out-of-bound memory access
54            {CAN-2005-1848}
55            - dhcpcd 1.3.22pl4-22
56            NOTE: fixed in testing at time of DSA
57    [10 Jul 2005] DSA-749-1 ettercap - format string error
58            {CAN-2005-1796}
59            - ettercap 0.7.3-1 (medium)
60            NOTE: fixed in testing at time of DSA
61    [10 Jul 2005] DSA-747-1 egroupware - input validation error
62            {CAN-2005-1921}
63            - egroupware 1.0.0.007-3.dfsg-1 (high)
64            NOTE: not fixed in testing at time of DSA (only 1/2 days old)
65    [10 Jul 2005] DSA-745-1 drupal - arbitrary command execution
66            {CAN-2005-1921 CAN-2005-2106 CAN-2005-2116}
67            - drupal 4.5.4-1 (high)
68            NOTE: fixed in testing at time of DSA
69    [08 Jul 2005] DSA-744-1 fuse - programming error
70            {CAN-2005-1858}
71            - fuse 2.3.0-1
72            NOTE: fixed in testing at time of DSA
73    [08 Jul 2005] DSA-743-1 ht - buffer overflows, integer overflows
74            {CAN-2005-1545 CAN-2005-1546}
75            - ht 0.8.0-3
76            NOTE: fixed in testing at time of DSA
77    [09 Jul 2005] DSA-742-1 cvs - buffer overflow
78            {CAN-2005-0753}
79            - cvs 1:1.12.9-13 (high)
80            NOTE: fixed in testing at time of DSA
81    [07 Jul 2005] DSA-741-1 bzip2 - infinite loop
82            {CAN-2005-1260}
83            - bzip2 1.0.2-7 (low)
84            NOTE: fixed in testing at time of DSA
85    [06 Jul 2005] DSA-740-1 zlib - buffer overflow
86            {CAN-2005-2096}
87            - zlib 1.2.2-7 (medium)
88            NOTE: anything statically linking zlib needs rebuild
89            TODO: check rest/coord with Kurt Roeckx
90            - aide (unfixed; bug #317523; medium)
91            NOTE: not fixed in testing at time of DSA (embargoed disclosure)
92    [06 Jul 2005] DSA-739-1 trac - missing input sanitising
93            {CAN-2005-2007}
94            - trac 0.8.4-1 (medium)
95            NOTE: fixed in testing at time of DSA
96    [19 May 2005] DSA-725-2 ppxp - missing privilege release
97            {CAN-2005-0392}
98            - ppxp 0.2001080415-11
99            NOTE: fixed in testing at time of DSA
100    [05 Jul 2005] DSA-738-1 razor - email header parsing error
101            {CAN-2005-2024}
102            - razor 2.720-1 (low)
103            NOTE: not fixed in testing at time of DSA (not built on arm)
104    [05 Jul 2005] DSA-737-1 clamav - various DOS vulnerabilities
105            {CAN-2005-1922 CAN-2005-1923 CAN-2005-2056 CAN-2005-2070}
106            - clamav 0.86.1-1 (medium)
107            NOTE: not fixed in testing at time of DSA (uploaded with low urgency only, one fix missing for sid)
108    [05 Jul 2005] DSA-734-1 gaim - denial of service
109            {CAN-2005-1269 CAN-2005-1934}
110            - gaim 1.3.1-1
111            NOTE: not fixed in testing at time of DSA (not built on sparc)
112    [01 Jul 2005] DSA-736-2 spamassassin - mail header parsing error
113            {CAN-2005-1266}
114            - spamassassin 3.0.4-1 (medium)
115            NOTE: fixed in testing at time of DSA
116    [01 Jul 2005] DSA-736-1 spamassassin - mail header parsing error
117            {CAN-2005-1266}
118            - spamassassin 3.0.4-1 (medium)
119            NOTE: fixed in testing at time of DSA
120    [08 Jul 2005] DSA-735-2 sudo - pathname validation race
121            {CAN-2005-1993}
122            - sudo 1.6.8p9-1 (medium)
123            NOTE: fixed in testing at time of DSA
124    [01 Jul 2005] DSA-735-2 sudo - pathname validation race
125            {CAN-2005-1993}
126            - sudo 1.6.8p9-1 (medium)
127            NOTE: fixed in testing at time of DSA
128    [01 Jul 2005] DSA-735-1 sudo - pathname validation race
129            {CAN-2005-1993}
130            - sudo 1.6.8p9-1 (medium)
131            NOTE: not fixed in testing at time of DSA
132    [30 Jun 2005] DSA-733-1 crip - insecure temporary files
133            {CAN-2005-0393}
134            - crip 3.5-1sarge2 (low)
135            NOTE: not fixed in testing at time of DSA (reserved)
136    [03 Jun 2005] DSA-732-1 mailutils - several
137            {CAN-2005-1520 CAN-2005-1521 CAN-2005-1522 CAN-2005-1523}
138            - mailutils 0.6.1-4
139            NOTE: fixed in testing at time of DSA
140    [02 Jun 2005] DSA-731-1 krb4 - buffer overflows
141            {CAN-2005-0468 CAN-2005-0468}
142            - krb4 1.2.2-11.2
143            NOTE: fixed in testing at time of DSA
144    [27 May 2005] DSA-730-1 bzip2 - race condition
145            {CAN-2005-0953}
146            - bzip2 1.0.2-6
147            NOTE: fixed in testing at time of DSA
148    [26 May 2005] DSA-729-1 php4 - missing input sanitising
149            {CAN-2005-0525}
150            - php4 4.3.10-10
151            NOTE: fixed in testing at time of DSA
152    [25 May 2005] DSA-728-1 qpopper - missing privilege release
153            {CAN-2005-1151 CAN-2005-1152}
154            - qpopper 4.0.5-4sarge1
155            NOTE: fixed in testing at time of DSA by security team
156    [20 May 2005] DSA-727-1 libconvert-uulib-perl - buffer overflow
157            {CAN-2005-1349}
158            - libconvert-uulib-perl 1.0.5.1-1
159            NOTE: fixed in testing at time of DSA
160    [20 May 2005] DSA-726-1 oops - format string vulnerability
161            {CAN-2005-1121}
162            - oops (unfixed; bug #307360)
163            NOTE: not in testing at time of DSA
164    [19 May 2005] DSA-725-1 ppxp - missing privilege release
165            {CAN-2005-0392}
166            - ppxp 0.2001080415-11
167            NOTE: not fixed in testing at time of DSA
168    [18 May 2005] DSA-724-1 phpsysinfo - design flaw
169            {CAN-2005-0870}
170            - phpsysinfo 2.3-3
171            NOTE: fixed in testing at time of DSA
172    [09 May 2005] DSA-723-1 xfree86 - buffer overflow
173            {CAN-2005-0605}
174            - xfree86 4.3.0.dfsg.1-13
175            NOTE: not fixed in testing at time of DSA
176    [09 May 2005] DSA-722-1 smail - buffer overflow
177            {CAN-2005-0892}
178            NOTE: Package not in testing at time of DSA
179    [06 May 2005] DSA-721-1 squid - design flaw
180            {CAN-2005-1345}
181            - squid 2.5.9-7
182            NOTE: not fixed in testing at time of DSA
183    [03 May 2005] DSA-720-1 smartlist - wrong input processing
184            {CAN-2005-0157}
185            - smartlist 3.15-18
186            NOTE: fixed in testing at time of DSA
187    [28 Apr 2005] DSA-719-1 prozilla - format string problems
188            {CAN-2005-0523}
189            - prozilla 1:1.3.7.4-1
190            NOTE: fixed in testing at time of DSA
191    [28 Apr 2005] DSA-718-1 ethereal - buffer overflow
192            {CAN-2005-0739}
193            - ethereal 0.10.10-1
194            NOTE: fixed in testing at time of DSA
195    [27 Apr 2005] DSA-717-1 lsh-utils - buffer overflow, typo
196            {CAN-2003-0826 CAN-2005-0814}
197            - lsh-utils 2.0.1-2
198            NOTE: fixed in testing at time of DSA
199    [27 Apr 2005] DSA-716-1 gaim - denial of service
200            {CAN-2005-0472}
201            - gaim 1.1.3-1
202            NOTE: fixed in testing at time of DSA
203    [27 Apr 2005] DSA-715-1 cvs - several
204            {CAN-2004-1342 CAN-2004-1343}
205            - cvs 1.12.9-12
206            NOTE: not fixed in testing at time of DSA
207    [26 Apr 2005] DSA-714-1 kdelibs - several
208            {CAN-2005-1046}
209            - kdelibs 4:3.3.2-5
210            NOTE: not fixed in testing at time of DSA
211    [21 Apr 2005] DSA-701-2 samba - integer overflows
212            NOTE: only a bug in the backported fix to stable, testing is ok
213    [21 Apr 2005] DSA-713-1 junkbuster - several
214            {CAN-2005-1108 CAN-2005-1109}
215            NOTE: package not in testing/unstable
216    [19 Apr 2005] DSA-712-1 geneweb - insecure file operations
217            {CAN-2005-0391}
218            - geneweb 4.10-7
219            NOTE: fixed in testing at time of DSA
220    [19 Apr 2005] DSA-711-1 info2www - missing input sanitising
221            {CAN-2004-1341}
222            - info2www 1.2.2.9-23
223            NOTE: fixed in testing at time of DSA
224    [18 Apr 2005] DSA-710-1 gtkhtml - null pointer dereference
225            {CAN-2003-0541}
226            - gtkhtml 1.0.4-6.2
227            NOTE: fixed in testing at time of DSA
228    [15 Apr 2005] DSA-709-1 libexif - buffer overflow
229            {CAN-2005-0664}
230            - libexif 0.6.9-5
231    [15 Apr 2005] DSA-708-1 php3 - missing input sanitising
232            {CAN-2005-0525}
233            - php3 3.0.18-31
234    [13 Apr 2005] DSA-707-1 mysql - several
235            {CAN-2004-0957 CAN-2005-0709 CAN-2005-0710 CAN-2005-0711}
236            - mysql-dfsg 4.0.24-5
237            - mysql-dfsg-4.1 4.1.10a-6
238            NOTE: not fixed in testing at time of DSA
239    [13 Apr 2005] DSA-706-1 axel - buffer overflow
240            {CAN-2005-0390}
241            - axel 1.0b-1
242            NOTE: fixed in testing at time of DSA
243    [04 Apr 2005] DSA-705-1 wu-ftpd - missing input sanitising
244            {CAN-2005-0256 CAN-2003-0854}
245            - wu-ftpd 2.6.2-19
246    [04 Apr 2005] DSA-704-1 remstats - tempfile, missing input sanitising
247            {CAN-2005-0387 CAN-2005-0388}
248            - remstats 1.0.13a-5
249            NOTE: not fixed in testing at time of DSA
250    [01 Apr 2005] DSA-703-1 krb5 - buffer overflows
251            {CAN-2005-0468 CAN-2005-0469}
252            - krb5 1.3.6-1
253    [01 Apr 2005] DSA-702-1 imagemagick - several
254            {CAN-2005-0397 CAN-2005-0759 CAN-2005-0760 CAN-2005-0762}
255            - imagemagick 6.0.6.2-2.2
256    [31 Mar 2005] DSA-701-1 samba - integer overflows
257            {CAN-2004-1154}
258            - samba 3.0.10-1
259    [30 Mar 2005] DSA-700-1 mailreader - missing input sanitising
260            {CAN-2005-0386}
261            - mailreader 2.3.29-11
262            NOTE: not fixed in testing at time of DSA
263    [29 Mar 2005] DSA-699-1 netkit-telnet-ssl - buffer overflow
264            {CAN-2005-0469}
265            - netkit-telnet-ssl 0.17.24+0.1-7.1
266            NOTE: not fixed in testing at time of DSA
267    [29 Mar 2005] DSA-698-1 mc - buffer overflow
268            {CAN-2005-0763}
269            NOTE: Not clear which unstable/testing version fixed this,
270            NOTE: but advisory says it's fixed.
271    [29 Mar 2005] DSA-697-1 netkit-telnet - buffer overflow
272            {CAN-2005-0469}
273            - netkit-telnet 0.17-28
274            NOTE: not fixed in testing at time of DSA
275    [22 Mar 2005] DSA-696-1 perl - design flaw
276            {CAN-2005-0448}
277            - perl 5.8.4-8
278            NOTE: fixed in testing at time of DSA
279    [21 Mar 2005] DSA-695-1 xli - buffer overflow, input sanitising, integer overflow
280            {CAN-2001-0775 CAN-2005-0638 CAN-2005-0639}
281            - xli 1.17.0-18
282            NOTE: not fixed in testing at time of DSA
283    [21 Mar 2005] DSA-694-1 xloadimage - missing input sanitising, integer overflow
284            {CAN-2005-0638 CAN-2005-0639}
285            - xloadimage 4.1-14.2
286            NOTE: not fixed in testing at time of DSA
287    [14 Mar 2005] DSA-693-1 luxman - buffer overflow
288            {CAN-2005-0385}
289            NOTE: not fixed in testing at time of DSA
290            NOTE: not in unstable at time of DSA though DSA claimed it was
291            - luxman 0.41-20
292    [14 Mar 2005] DSA-662-2 squirrelmail - several
293            NOTE: only an update to a prior DSA, did not affct sid/sarge.
294    [08 Mar 2005] DSA-692-1 kppp - design flaw
295            {CAN-2005-0205}
296            - kppp 4:3.1.6
297            NOTE: fixed in testing at time of DSA
298    [07 Mar 2005] DSA-691-1 abuse - several
299            {CAN-2005-0098 CAN-2005-0099}
300            NOTE: not in unstable/testing
301    [25 Feb 2005] DSA-690-1 bsmtpd - missing input sanitising
302            {CAN-2005-0107}
303            - bsmtpd 2.3pl8b-16
304            NOTE: not fixed in testing at time of DSA
305    [23 Feb 2005] DSA-689-1 libapache-mod-python - missing input sanitising
306            {CAN-2005-0088}
307            - libapache-mod-python 2.7.10-4
308            NOTE: fixed in testing at time of DSA
309            - libapache2-mod-python 3.1.3-3
310            NOTE: fixed in testing at time of DSA
311    [23 Feb 2005] DSA-688-1 squid - mising input sanitising
312            {CAN-2005-0446}
313            - squid 2.5.8-3
314            NOTE: fixed in testing at time of DSA
315    [21 Feb 2005] DSA-674-3 mailman - cross-site scripting, directory traversal
316            NOTE: only fixed bug in DSA
317    [18 Feb 2005] DSA-687-1 bidwatcher - format string
318            {CAN-2005-0158}
319            - bidwatcher 1.3.17-1
320            NOTE: not fixed in testing at time of DSA
321    [17 Feb 2005] DSA-686-1 gftp - missing input sanitising
322            {CAN-2005-0372}
323            - gftp 2.0.18-1
324            NOTE: not fixed in testing at time of DSA
325    [17 Feb 2005] DSA-685-1 emacs21 - format string
326            {CAN-2005-0100}
327            - emacs21 21.3+1-9
328            NOTE: not fixed in testing at time of DSA
329    [16 Feb 2005] DSA-684-1 typespeed - format string
330            {CAN-2005-0105}
331            - typespeed 0.4.4-8
332            NOTE: not fixed in testing at time of DSA
333    [15 Feb 2005] DSA-683-1 postgresql - buffer overflows
334            {CAN-2005-0245 CAN-2005-0247}
335            - postgresql 7.4.7-2
336            NOTE: fixed in testing at time of DSA
337    [15 Feb 2005] DSA-682-1 awstats - missing input sanitising
338            {CAN-2005-0363}
339            - awstats 6.2-1.2
340            NOTE: not fixed in testing at time of DSA
341    [14 Feb 2005] DSA-681-1 synaesthesia - privilege escalation
342            {CAN-2005-0070}
343            NOTE: does not apply for sarge, program is not setuid anymore
344    [14 Feb 2005] DSA-680-1 htdig - unsanitised input
345            {CAN-2005-0085}
346            - htdig 3.1.6-11
347            NOTE: fixed in testing at time of DSA
348    [14 Feb 2005] DSA-679-1 toolchain-source - insecure temporary files
349            {CAN-2005-0159}
350            - toolchain-source 3.4-5
351            NOTE: not fixed in testing at time of DSA
352    [11 Feb 2005] DSA-678-1 netkit-rwho - missing input validation
353            {CAN-2004-1180}
354            - netkit-rwho 0.17-8
355            NOTE: not fixed in testing at time of DSA
356    [11 Feb 2005] DSA-677-1 sympa - buffer overflow
357            {CAN-2005-0073}
358            - sympa 4.1.2-2.1
359            NOTE: not fixed in testing at time of DSA
360    [11 Feb 2005] DSA-676-1 xpcd - buffer overflow
361            {CAN-2005-0074}
362            - xpcd 2.08-11.1
363            NOTE: not fixed in testing at time of DSA
364    [11 Feb 2005] DSA-674-2 mailman - cross-site scripting, directory traversal
365            NOTE: only fixed bug in DSA
366    [10 Feb 2005] DSA-675-1 hztty - privilege escalation
367            {CAN-2005-0019}
368            - hztty 2.0-6.1
369            NOTE: not fixed in testing at time of DSA
370    [10 Feb 2005] DSA-674-1 mailman - cross-site scripting, directory traversal
371            {CAN-2004-1177}
372            - mailman 2.1.5-5
373            NOTE: fixed in testing at time of DSA
374            {CAN-2005-0202}
375            - mailman 2.1.5-6
376            NOTE: not fixed in testing at time of DSA
377    [10 Feb 2005] DSA-673-1 evolution - integer overflow
378            {CAN-2005-0102}
379            - evolution 2.0.3-1.2
380            NOTE: fixed in testing at time of DSA
381    [09 Feb 2005] DSA-672-1 xview - buffer overflows
382            {CAN-2005-0076}
383            - xview 3.2p1.4-19
384            NOTE: not fixed in testing at time of DSA
385    [08 Feb 2005] DSA-671-1 xemacs21 - format string
386            {CAN-2005-0100}
387            NOTE: not fixed in testing at time of DSA
388            - xemacs21 21.4.16-2
389    [08 Feb 2005] DSA-670-1 emacs20 - format string
390            {CAN-2005-0100}
391            NOTE: also affects emacs21 in unstable, fixed
392    [04 Feb 2005] DSA-689-1 php3 - several
393            {CAN-2004-0594 CAN-2004-0595}
394            - php3 3.0.18-27
395            NOTE: fixed in testing at time of DSA
396    [04 Feb 2005] DSA-668-1 postgresql - privilege escalation
397            {CAN-2005-0227}
398            - postgresql 7.4.7-1
399            NOTE: not fixed in testing at time of DSA
400    [04 Feb 2005] DSA-667-1 squid - several
401            {CAN-2005-0173 CAN-2005-0175 CAN-2005-0194 CAN-2005-0211}
402            - squid 2.5.7-7
403            NOTE: not fixed in testing at time of DSA
404    [04 Feb 2005] DSA-666-1 python2.2 - design flaw
405            {CAN-2005-0089}
406            - python2.2 2.2.3-14
407            - python2.3 2.3.4-20
408            - python2.4 2.4-5
409            NOTE: not fixed in testing at time of DSA
410    [04 Feb 2005] DSA-665-1 ncpfs - missing privilege release
411            {CAN-2005-0013}
412            - ncpfs 2.2.6-1
413            NOTE: not fixed in testing at time of DSA
414    [02 Feb 2005] DSA-664-1 cpio - broken file permissions
415            {CAN-1999-1572}
416            - cpio 2.5-1.2
417            NOTE: not fixed in testing at time of DSA
418    [02 Feb 2005] DSA-663-1 prozilla - buffer overflows
419            {CAN-2004-1120}
420            - prozilla 1.3.7.3-1
421            NOTE: fixed in testing at time of DSA
422    [01 Feb 2005] DSA-662-1 squirrelmail - several
423            {CAN-2005-0104 CAN-2005-0152}
424            NOTE: CAN-2005-0152 only exists in 1.2.6 version
425            - squirrelmail 1.4.4
426            NOTE: fixed in testing at time of DSA
427    [20 Apr 2005] DSA-661-2 f2c - insecure temporary files
428            {CAN-2005-0017 CAN-2005-0018}
429            - f2c 20020621-3.3
430            NOTE: not fixed in testing at time of DSA
431    [26 Jan 2005] DSA-660-1 kdebase - missing return value check
432            {CAN-2005-0078}
433            - kdebase 4:3.0.5
434            NOTE: fixed in testing at time of DSA
435    [26 Jan 2005] DSA-659-1 libpam-radius-auth - information leak, integer underflow
436            {CAN-2004-1340 CAN-2005-0108}
437            - libpam-radius-auth 1.3.16-3
438            NOTE: 1/2 fixed in testing at time of DSA
439    [25 Jan 2005] DSA-658-1 libdbi-perl - insecure temporary file
440            {CAN-2005-0077}
441            - libdbi-perl 1.46-6
442            NOTE: not fixed in testing at time of DSA
443    [25 Jan 2005] DSA-657-1 xine-lib - buffer overflow
444            {CAN-2004-1379}
445            - xine-lib 1-rc6a-1
446            NOTE: fixed in testing at time of DSA
447    [25 Jan 2005] DSA-656-1 vdr - insecure file access
448            {CAN-2005-0071}
449            - vdr 1.2.6-6
450            NOTE: not fixed in testing at time of DSA
451    [25 Jan 2005] DSA-655-1 zhcon - missing privilege release
452            {CAN-2005-0072}
453            - zhcon 1:0.2.3-8.1
454            NOTE: not fixed in testing at time of DSA
455    [21 Jan 2005] DSA-654-1 enscript - several
456            {CAN-2004-1184 CAN-2004-1185 CAN-2004-1186}
457            - enscript 1.6.4-6
458            NOTE: not fixed in testing at time of DSA
459    [21 Jan 2005] DSA-653-1 ethereal - buffer overflow
460            {CAN-2005-0084}
461            - ethereal 0.10.9-1
462            NOTE: not fixed in testing at time of DSA
463    [21 Jan 2005] DSA-652-1 unarj
464            {CAN-2004-0947 CAN-2004-1027}
465            NOTE: not-for-us (unarj)
466    [20 Jan 2005] DSA-651-1 squid - buffer overflow, integer overflow
467            {CAN-2005-0094 CAN-2005-0095}
468            - squid 2.5.7-4
469            NOTE: not fixed in testing at time of DSA
470    [20 Jan 2005] DSA-650-1 sword - missing input sanitising
471            {CAN-2005-0015}
472            - sword 1.5.7-7
473            NOTE: not fixed in testing at time of DSA
474    [20 Jan 2005] DSA-649-1 xtrlock - buffer overflow
475            {CAN-2005-0079}
476            - xtrlock 2.0-9
477            NOTE: fixed in testing at time of DSA
478    [19 Jan 2005] DSA-648-1 xpdf - buffer overflow
479            {CAN-2005-0064}
480            - xpdf 3.00-12
481            NOTE: not fixed in testing at time of DSA
482    [19 Jan 2005] DSA-647-1 mysql - insecure temporary files
483            {CAN-2005-0004}
484            - mysql-dfsg 4.0.23-3
485            - mysql-dfsg-4.1 4.1.8a-6
486            NOTE: not fixed in testing at time of DSA
487    [19 Jan 2005] DSA-646-1 imagemagick - buffer overflow
488            {CAN-2005-0005}
489            - imagemagick 6.0.6.2-2
490            NOTE: not fixed in testing at time of DSA
491    [19 Jan 2005] DSA-645-1 cupsys - buffer overflow
492            {CAN-2005-0064}
493            NOTE: cupsys not affected in sarge, though other programs are vulnerable
494            NOTE: see CAN/list
495            NOTE: not fixed in testing at time of DSA
496    [18 Jan 2005] DSA-644-1 chbg - buffer overflow
497            {CAN-2004-1264}
498            - chbg 1.5-4
499            NOTE: fixed in testing at time of DSA
500    [18 Jan 2005] DSA-643-1 queue - buffer overflows
501            {CAN-2004-0555}
502            - queue 1.30.1-5
503            NOTE: not fixed in testing at time of DSA
504    [17 Jan 2005] DSA-642-1 gallery - several
505            {CAN-2004-1106}
506            - gallery 1.4.4-pl4-1
507            NOTE: fixed in testing at time of DSA
508    [17 Jan 2005] DSA-641-1 playmidi - buffer overflow
509            {CAN-2005-0020}
510            - playmidi 2.4debian-3
511            NOTE: not fixed in testing at time of DSA
512    [17 Jan 2005] DSA-640-1 gatos - buffer overflow
513            {CAN-2005-0016}
514            - gatos 0.0.5-15
515            NOTE: not fixed in testing at time of DSA
516    [14 Jan 2005] DSA-639-1 mc - several
517            {CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176}
518            NOTE: unstable not vulnerable according to DSA
519            NOTE: DSA was wrong..
520            - mc 1:4.6.0-4.6.1-pre3-1
521            NOTE: not fixed in testing at time of DSA
522    [13 Jan 2005] DSA-638-1 gopher - several
523            {CAN-2004-0560 CAN-2004-0561}
524            NOTE: not in sarge
525    [13 Jan 2005] DSA-637-1 exim-tls - buffer overflow
526            {CAN-2005-0021}
527            NOTE: not in sarge
528    [12 Jan 2005] DSA-636-1 glibc - insecure temporary files
529            {CAN-2004-0968}
530            - glibc 2.3.2.ds1-20
531            NOTE: fixed in testing at time of DSA
532    [12 Jan 2005] DSA-635-1 exim - buffer overflow
533            {CAN-2005-0021}
534            - exim4 4.34-10
535            NOTE: fixed in testing at time of DSA
536            - exim 3.36-13
537            NOTE: not fixed in testing at time of DSA
538    [11 Jan 2005] DSA-634-1 hylafax - weak hostname and username validation
539            {CAN-2004-1182}
540            - hylafax 4.2.1-1
541            NOTE: fixed in testing at time of DSA
542    [11 Jan 2005] DSA-633-1 bmv - insecure temporary file
543            {CAN-2003-0014}
544            - bmv 1.2-17
545            NOTE: fixed in testing at time of DSA
546    [10 Jan 2005] DSA-632-1 linpopup - buffer overflow
547            {CAN-2004-1282}
548            - linpopup 1.2.0-7
549            NOTE: fixed in testing at time of DSA
550    [10 Jan 2005] DSA-631-1 kdelibs - unsanitised input
551            {CAN-2004-1165}
552            - kdelibs 4:3.3.2-1
553            NOTE: not fixed in testing at time of DSA
554    [10 Jan 2005] DSA-630-1 lintian - insecure temporary directory
555            {CAN-2004-1000}
556            - lintian 1.23.6
557            NOTE: not fixed in testing at time of DSA
558    [07 Jan 2005] DSA-629-1 krb5 - buffer overflow
559            {CAN-2004-1189}
560            - krb5 1.3.6-1
561            NOTE: not fixed in testing at time of DSA
562    [06 Jan 2005] DSA-628-1 imlib2 - integer overflows
563            {CAN-2004-1026}
564            - imlib2 1.1.2-2.1
565            NOTE: not fixed in testing at time of DSA
566    [06 Jan 2005] DSA-627-1 namazu2 - unsanitised input
567            {CAN-2004-1318}
568            - namazu2 2.0.14-1
569            NOTE: not fixed in testing at time of DSA
570    [06 Jan 2005] DSA-626-1 tiff - unsanitised input
571            {CAN-2004-1183}
572            - libtiff4 3.6.1-5
573            NOTE: not fixed in testing at time of DSA
574    [05 Jan 2005] DSA-625-1 pcal - buffer overflows
575            {CAN-2004-1289}
576            - pcal 4.8.0-1
577            NOTE: not fixed in testing at time of DSA
578    [05 Jan 2005] DSA-624-1 zip - buffer overflow
579            {CAN-2004-1010}
580            - zip 2.30-8
581            NOTE: fixed in testing at time of DSA
582    [04 Jan 2005] DSA-623-1 nasm - buffer overflow
583            {CAN-2004-1287}
584            - nasm 0.98.38-1.1
585    [03 Jan 2005] DSA-622-1 htmlheadline - insecure temporary files
586            {CAN-2004-1181}
587            NOTE: not in unstable
588  [31 Dec 2004] DSA-621-1 cupsys - buffer overflow  [31 Dec 2004] DSA-621-1 cupsys - buffer overflow
589          {CAN-2004-1125}          {CAN-2004-1125}
590          - cupsys 1.1.22-2          - cupsys 1.1.22-2
# Line 43  Line 630 
630          - atari800 1.3.2-1          - atari800 1.3.2-1
631  [14 Dec 2004] DSA-608-1 zgv - integer overflows, unsanitised input  [14 Dec 2004] DSA-608-1 zgv - integer overflows, unsanitised input
632          {CAN-2004-1095 CAN-2004-0999}          {CAN-2004-1095 CAN-2004-0999}
633          - zgv (unfixed; no bug or other info yet for reserved CAN-2004-0999)          - zgv 5.7-1.3
634            NOTE: changelog says he only patched 1095, but diff comparison
635            NOTE: shows 0999 was also fixed.
636  [10 Dec 2004] DSA-607-1 xfree86 - several  [10 Dec 2004] DSA-607-1 xfree86 - several
637          {CAN-2004-0914}          {CAN-2004-0914}
638          - xfree86 4.3.0.dfsg.1-9          - xfree86 4.3.0.dfsg.1-9
639  [08 Dec 2004] DSA-606-1 nfs-utils - wrong signal handler  [08 Dec 2004] DSA-606-1 nfs-utils - wrong signal handler
640          {CAN-2004-1014}          {CAN-2004-1014}
641          - nfs-utils (unfixed; bug #284971)          - nfs-utils 1:1.0.6-3.1
642  [06 Dec 2004] DSA-605-1 viewcvs - settings not honored  [06 Dec 2004] DSA-605-1 viewcvs - settings not honored
643          {CAN-2004-0915}          {CAN-2004-0915}
644          - viewcvs 0.9.2+cvs.1.0.dev.2004.07.28-1.2          - viewcvs 0.9.2+cvs.1.0.dev.2004.07.28-1.2
# Line 58  Line 647 
647          - hpsockd 0.14          - hpsockd 0.14
648  [01 Dec 2004] DSA-603-1 openssl - insecure temporary file  [01 Dec 2004] DSA-603-1 openssl - insecure temporary file
649          {CAN-2004-0975}          {CAN-2004-0975}
650          - openssl 0.9.7e-1          - openssl 0.9.7e-3
651  [29 Nov 2004] DSA-602-1 libgd2 - integer overlow  [29 Nov 2004] DSA-602-1 libgd2 - integer overlow
652          {CAN-2004-0941 CAN-2004-0990}          {CAN-2004-0941 CAN-2004-0990}
653          NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new          NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
# Line 103  Line 692 
692          - gnats 4.0-6.1          - gnats 4.0-6.1
693  [09 Nov 2004] DSA-589-1 libgd - integer overflows  [09 Nov 2004] DSA-589-1 libgd - integer overflows
694          {CAN-2004-0990}          {CAN-2004-0990}
695          - libgd1 (unfixed; bug #280134)          - libgd1 1.8.4-36.1
696  [08 Nov 2004] DSA-588-1 gzip - insecure temporary files  [08 Nov 2004] DSA-588-1 gzip - insecure temporary files
697          {CAN-2004-0970}          {CAN-2004-0970}
698          NOTE: dsa says sid not affected          NOTE: dsa says sid not affected
# Line 155  Line 744 
744          - cupsys 1.1.20final+rc1-10          - cupsys 1.1.20final+rc1-10
745          {CAN-2004-0889}          {CAN-2004-0889}
746          - xpdf 3.00-10          - xpdf 3.00-10
747          TODO: kpdf and kfax not fixed in sarge, bug #278173 has a backported patch for the kpdf hole          NOTE: kpdf and kfax are fixed in sarge, bug #278173 and #280373 for reference
748          - kpdf 4:3.3.1-1          - kpdf 4:3.3.1-1
749          - gpdf 2.8.0-1          - gpdf 2.8.0-1
750          - kfax 4:3.3.1-1          - kfax 4:3.3.1-1
# Line 241  Line 830 
830  [16 Sep 2004] DSA-548-1 imlib - unsanitised input  [16 Sep 2004] DSA-548-1 imlib - unsanitised input
831          {CAN-2004-0817}          {CAN-2004-0817}
832          - imlib 1.9.14-17          - imlib 1.9.14-17
833          NOTE: changelog claims it was fixed, but it apparently was not          - imlib+png2 1.9.14-16.2
         - imlib+png2 (unfixed; bug #285025)  
834  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows
835          {CAN-2004-0827}          {CAN-2004-0827}
836          - imagemagic 6.0.6.2-1          - imagemagic 6.0.6.2-1
# Line 361  Line 949 
949          {CAN-2004-0522}          {CAN-2004-0522}
950          - gallery 1.4.3-pl2-1          - gallery 1.4.3-pl2-1
951  [30 May 2004] DSA-511 ethereal - buffer overflows  [30 May 2004] DSA-511 ethereal - buffer overflows
952          {CAN-2004-0176          {CAN-2004-0176}
953          - ethereal 0.10.3-1          - ethereal 0.10.3-1
954  [29 May 2004] DSA-510 jftpgw - format string  [29 May 2004] DSA-510 jftpgw - format string
955          {CAN-2004-0448}          {CAN-2004-0448}

Legend:
Removed from v.221  
changed lines
  Added in v.1434

  ViewVC Help
Powered by ViewVC 1.1.5