/[secure-testing]/data/DSA/list
ViewVC logotype

Diff of /data/DSA/list

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

sarge-checks/DSA/list revision 172 by joeyh, Sat Dec 4 02:48:59 2004 UTC data/DSA/list revision 1822 by jmm-guest, Mon Sep 5 17:13:42 2005 UTC
# Line 1  Line 1 
1    [05 Sep 2005] DSA-801-1 ntp - programming error
2            {CAN-2005-2496}
3            - ntp 1:4.2.0a+stable-4 (medium)
4            NOTE: not fixed in testing at time of DSA (RC bugs)
5    [02 Sep 2005] DSA-800-1 pcre3 - integer overflow
6            {CAN-2005-2491}
7            - pcre3 6.3-0.1etch1 (high)
8            NOTE: not fixed in testing at time of DSA (glibc transition)
9            NOTE: however, fixed in secure-testing archive
10    [02 Sep 2005] DSA-799-1 webcalendar - input validation
11            {CAN-2005-2717}
12            - webcalendar (unfixed; bug #326223; high)
13            NOTE: not fixed in testing at time of DSA (coordinated disclosure)
14    [02 Sep 2005] DSA-798-1 phpgroupware - several
15            {CAN-2005-2498 CAN-2005-2600 CAN-2005-2761}
16            - phpgroupware 0.9.16.008-1 (high)
17            NOTE: not fixed in testing at time of DSA (too young)
18    [01 Sep 2005] DSA-797-1 zsync - buffer overflow
19            {CAN-2005-1849 CAN-2005-2096}
20            - zsync 0.4.0-2 (medium)
21            NOTE: fixed in testing at time of DSA
22    [01 Sep 2005] DSA-796-1 affix - unsafe use of popen
23            {CAN-2005-2716}
24            - affix 2.1.2-3 (medium)
25            NOTE: not fixed in testing at time of DSA (glibc transition, builds)
26    [01 Sep 2005] DSA-795-2 proftpd - format string error
27            {CAN-2005-2390}
28            - proftpd 1.2.10-20 (medium)
29            NOTE: fixed in testing at time of DSA
30            NOTE: Initial -1 release had a build problem
31    [01 Sep 2005] DSA-794-1 polygen - programming error
32            {CAN-2005-2656}
33            - polygen 1.0.6-9 (low)
34            NOTE: not fixed in testing at time of DSA (too young)
35    [21 Aug 2005] DSA-779-2 mozilla-firefox - several
36            NOTE: Essentially 1.0.6 with rolled-back version number, backported version had regressions
37            {CAN-2005-2260 CAN-2005-2261 CAN-2005-2262 CAN-2005-2263 CAN-2005-2264 CAN-2005-2265 CAN-2005-2266 CAN-2005-2267 CAN-2005-2268 CAN-2005-2269 CAN-2005-2270}
38            - mozilla-firefox 1.0.6-1 (medium)
39            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
40            NOTE: Fixed in DTSA, which will have the same regressions, should be checked/reverted
41    [01 Sep 2005] DSA-793-1 courier - missing input sanitising
42            {CAN-2005-2724}
43            - courier 0.47-8 (medium)
44            NOTE: not fixed in testing at time of DSA (glibc transition, too young)
45    [31 Aug 2005] DSA-792-1 pstotext - missing input sanitising
46            {CAN-2005-2536}
47            - pstotext 1.9-2 (medium)
48            NOTE: not fixed in testing at time of DSA (glibc transition, builds)
49    [30 Aug 2005] DSA-791-1 maildrop - missing privilege release
50            {CAN-2005-2655}
51            - maildrop 1.5.3-1.1etch1 (medium)
52            NOTE: not fixed in testing at time of DSA (glibc transition)
53            NOTE: but fixed in secure-testing repo
54    [30 Aug 2005] DSA-790-1 phpldapadmin - programming error
55            {CAN-2005-2654}
56            - phpldapadmin 0.9.6c-5 (medium)
57            NOTE: fixed in testing at time of DSA
58    [29 Aug 2005] DSA-789-1 php4 - several
59            {CAN-2005-1751 CAN-2005-1921 CAN-2005-2498}
60            - php4 4:4.4.0-2 (high)
61            NOTE: not fixed in testing at time of DSA (not uploaded yet)
62    [29 Aug 2005] DSA-788-1 kismet - several
63            {CAN-2005-2626 CAN-2005-2627}
64            - kismet 2005.08.R1-1 (medium)
65            NOTE: not fixed in testing at time of DSA (glibc transition)
66            NOTE: but fixed in secure-testing repo
67    [26 Aug 2005] DSA-787-1 backup-manager - insecure permissions and tempfile
68            {CAN-2005-1855 CAN-2005-1856}
69            - backup-manager 0.5.8-2 (medium)
70            NOTE: fixed in testing at time of DSA
71    [26 Aug 2005] DSA-786-1 simpleproxy - format string vulnerability
72            {CAN-2005-1857}
73            - simpleproxy 3.2-4 (medium)
74            NOTE: not fixed in testing at time of DSA (embargoed disclosure)
75    [25 Aug 2005] DSA-785-1 libpam-ldap - authentication bypass
76            {CAN-2005-2641}
77            - libpam-ldap 178-1sarge1 (medium)
78            NOTE: not fixed in testing at time of DSA (embargoed disclosure)
79    [25 Aug 2005] DSA-784-1 courier - programming error
80            {CAN-2005-2151}
81            - courier 0.47-6 (low)
82            NOTE: not fixed in testing at time of DSA (glibc transition)
83    [24 Aug 2005] DSA-783-1 mysql-dfsg-4.1 - insecure temporary file
84            {CAN-2005-1636}
85            - mysql-dfsg-4.1 4.1.12 (medium)
86            NOTE: not fixed in testing at time of DSA (glibc transition)
87            - mysql-dfsg-5.0 5.0.11beta-3 (medium)
88            NOTE: not fixed in testing at time of DSA (glibc transition)
89    [23 Aug 2005] DSA-782-1 bluez-utils - missing input sanitising
90            {CAN-2005-2547}
91            - bluez-utils 2.19-1 (high)
92            NOTE: not fixed in testing at time of DSA (missing builds)
93    [23 Aug 2005] DSA-781-1 mozilla-thunderbird - several
94            {CAN-2005-0989 CAN-2005-1159 CAN-2005-1160 CAN-2005-1532 CAN-2005-2261 CAN-2005-2265 CAN-2005-2266 CAN-2005-2269 CAN-2005-2270}
95            - mozilla-thunderbird 1.0.6-1 (medium)
96            NOTE: not fixed in testing at time of DSA (missing builds)
97    [22 Aug 2005] DSA-780-1 kdegraphics - wrong input sanitising
98            {CAN-2005-2097}
99            - kdegraphics (unfixed; bug #322458; low)
100            NOTE: not fixed in testing at time of DSA (nor in unstable; C++ ABI transition)
101    [21 Aug 2005] DSA-779-1 mozilla-firefox - several
102            {CAN-2005-2260 CAN-2005-2261 CAN-2005-2262 CAN-2005-2263 CAN-2005-2264 CAN-2005-2265 CAN-2005-2266 CAN-2005-2267 CAN-2005-2268 CAN-2005-2269 CAN-2005-2270}
103            - mozilla-firefox 1.0.6-1 (medium)
104            NOTE: not fixed in testing at time of DSA (build and deps)
105    [19 Aug 2005] DSA-778-1 mantis - missing input sanitising
106            {CAN-2005-2556 CAN-2005-2557}
107            - mantis 0.19.2-4 (medium)
108            NOTE: not fixed in testing at time of DSA (nor unstable)
109    [17 Aug 2005] DSA-777-1 mozilla - frame injection spoofing
110            {CAN-2004-0718 CAN-2005-1937}
111            - mozilla-browser 1.7.10-1 (medium)
112            NOTE: not fixed in testing at time of DSA (waiting on builds)
113    [16 Aug 2005] DSA-776-1 clamav - integer overflows, infinite loop
114            {CAN-2005-2450}
115            - clamav 0.86.2-1 (medium)
116            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
117    [12 Aug 2005] DSA-775-1 mozilla-firefox - frame injection spoofing
118            {CAN-2004-0718 CAN-2005-1937}
119            - mozilla-firefox 1.0.4-3 (medium)
120            NOTE: IMO the information about the sid fix in the DSA is wrong, pinged security@
121            NOTE: fixed in testing at time of DSA
122    [12 Aug 2005] DSA-774-1 fetchmail - buffer overflow
123            {CAN-2005-2335}
124            - fetchmail 6.2.5-16 (medium)
125            NOTE: fixed in testing at time of DSA
126    [11 Aug 2005] DSA-773-1 New amd64 packages fix several bugs
127            NOTE: amd64 catch-up DSA, no new holes
128    [03 Aug 2005] DSA-772-1 apt-cacher - missing input sanitising
129            {CAN-2005-1854}
130            - apt-cacher 0.9.10 (high)
131            NOTE: not fixed in testing at time of DSA (not uploaded to unstable yet)
132    [01 Aug 2005] DSA-771-1 pdns - several
133            {CAN-2005-2301 CAN-2005-2302}
134            - pdns 2.9.18-1 (medium)
135            NOTE: not fixed in testing at time of DSA (too young)
136    [29 Jul 2005] DSA-770-1 gopher - insecure tmpfile handling
137            {CAN-2005-1853}
138            - gopher 3.0.10
139            NOTE: not fixed in testing at time of DSA (Debian server outage)
140    [29 Jul 2005] DSA-769-1 gaim - memory alignment bug
141            {CAN-2005-2370}
142            - gaim 1:1.4.0-5 (high)
143            NOTE: not fixed in testing at time of DSA (?)
144    [27 Jul 2005] DSA-768-1 phpbb2 - missing input validation
145            {CAN-2005-2161}
146            - phpbb2 2.0.13-6sarge1
147            NOTE: not fixed in testing at time of DSA (Debian server outage)
148    [27 Jul 2005] DSA-767-1 ekg - integer overflows
149            {CAN-2005-1852}
150            - ekg 1.5+20050718+1.6rc3-1 (medium)
151            NOTE: not fixed in testing at time of DSA (Debian server outage)
152    [26 Jul 2005] DSA-766-1 webcalendar - authorisation failure
153            {CAN-2005-2320}
154            - webcalendar (unfixed; bug #315671; medium)
155            NOTE: not fixed in testing at time of DSA (Debian server outage)
156    [22 Jul 2005] DSA-765-1 heimdal - buffer overflow
157            {CAN-2005-0469}
158            - heimdal 0.6.3-10 (medium)
159            NOTE: fixed in testing at time of DSA
160    [21 Jul 2005] DSA-764-1 cacti - several
161            {CAN-2005-1524 CAN-2005-1525 CAN-2005-1526 CAN-2005-2148 CAN-2005-2149}
162            - cacti 0.8.6f-1 (high)
163            NOTE: fixed in testing at time of DSA
164            NOTE: DSA information is incorrect, sid fix is 6f, not 6e
165    [20 Jul 2005] DSA-763-1 zlib - buffer overflow
166            {CAN-2005-1849}
167            - zlib 1.2.3-1 (medium)
168            NOTE: not fixed in testing at time of DSA (only 1/2 days old, not built on s390)
169    [19 Jul 2005] DSA-762-1 affix - several
170            {CAN-2005-2250 CAN-2005-2277}
171            - affix 2.1.2-2 (medium)
172            NOTE: not fixed in testing at time of DSA (only 2/2 days old)
173    [19 Jul 2005] DSA-761-2 heartbeat - insecure temporary files
174            {CAN-2005-2231}
175            - heartbeat 1.2.3-12 (medium)
176            NOTE: not fixed in testing at time of DSA (only 0/2 days old)
177    [18 Jul 2005] DSA-760-1 ekg - several
178            {CAN-2005-1850 CAN-2005-1851 CAN-2005-1916}
179            - ekg 1.5+20050712+1.6rc2-1 (low)
180            NOTE: not fixed in testing at time of DSA (waiting on dependencies, not built on five archs)
181    [18 Jul 2005] DSA-759-1 phppgadmin - missing input sanitising
182            {CAN-2005-2256}
183            - phppgadmin 3.5.4-1 (medium)
184            NOTE: not fixed in testing at time of DSA (only 0/10 days old)
185    [18 Jul 2005] DSA-758-1 heimdal - buffer overflow
186            {CAN-2005-2040}
187            - heimdal 0.6.3-11 (medium)
188            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
189    [17 Jul 2005] DSA-757-1 krb5 - buffer overflow, double-free memory
190            {CAN-2005-1689 CAN-2005-1174 CAN-2005-1175}
191            - krb5 1.3.6-4 (medium)
192            NOTE: not fixed in testing at time of DSA (waiting on dependencies, not built on m68k)
193    [14 Jul 2005] DSA-746-1 phpgroupware - remote command execution
194            {CAN-2005-1921}
195            - phpgroupware 0.9.16.006-1 (high)
196            NOTE: fixed in testing at time of DSA
197    [13 Jul 2005] DSA-756-1 squirrelmail - several
198            {CAN-2005-1769 CAN-2005-2095}
199            - squirrelmail 2:1.4.4-6 (medium)
200            NOTE: not fixed in testing at time of DSA (only 0/2 days old)
201    [13 Jul 2005] DSA-755-1 tiff - buffer overflow
202            {CAN-2005-1544}
203            - tiff 3.7.2-3 (medium)
204            NOTE: fixed in testing at time of DSA
205    [13 Jul 2005] DSA-754-1 centericq - insecure temporary file
206            {CAN-2005-1914}
207            - centericq 4.20.0-7 (low)
208            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
209    [12 Jul 2005] DSA-753-1 gedit - format string
210            {CAN-2005-1686}
211            - gedit 2.10.3-1 (low)
212            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
213    [11 Jul 2005] DSA-752-1 gzip - several
214            {CAN-2005-0988 CAN-2005-1228}
215            - gzip 1.3.5-10
216            NOTE: fixed in testing at time of DSA
217    [11 Jul 2005] DSA-751-1 squid - IP spoofind
218            {CAN-2005-1519}
219            - squid 2.5.9-9
220            NOTE: fixed in testing at time of DSA
221    [10 Jul 2005] DSA-748-1 ruby1.8 - bad default value
222            {CAN-2005-1992}
223            - ruby1.8 1.8.2-8 (medium)
224            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
225    [11 Jul 2005] DSA-750-1 dhcpcd - out-of-bound memory access
226            {CAN-2005-1848}
227            - dhcpcd 1.3.22pl4-22
228            NOTE: fixed in testing at time of DSA
229    [10 Jul 2005] DSA-749-1 ettercap - format string error
230            {CAN-2005-1796}
231            - ettercap 0.7.3-1 (medium)
232            NOTE: fixed in testing at time of DSA
233    [10 Jul 2005] DSA-747-1 egroupware - input validation error
234            {CAN-2005-1921}
235            - egroupware 1.0.0.007-3.dfsg-1 (high)
236            NOTE: not fixed in testing at time of DSA (only 1/2 days old)
237    [10 Jul 2005] DSA-745-1 drupal - arbitrary command execution
238            {CAN-2005-1921 CAN-2005-2106 CAN-2005-2116}
239            - drupal 4.5.4-1 (high)
240            NOTE: fixed in testing at time of DSA
241    [08 Jul 2005] DSA-744-1 fuse - programming error
242            {CAN-2005-1858}
243            - fuse 2.3.0-1
244            NOTE: fixed in testing at time of DSA
245    [08 Jul 2005] DSA-743-1 ht - buffer overflows, integer overflows
246            {CAN-2005-1545 CAN-2005-1546}
247            - ht 0.8.0-3
248            NOTE: fixed in testing at time of DSA
249    [09 Jul 2005] DSA-742-1 cvs - buffer overflow
250            {CAN-2005-0753}
251            - cvs 1:1.12.9-13 (high)
252            NOTE: fixed in testing at time of DSA
253    [07 Jul 2005] DSA-741-1 bzip2 - infinite loop
254            {CAN-2005-1260}
255            - bzip2 1.0.2-7 (low)
256            NOTE: fixed in testing at time of DSA
257    [06 Jul 2005] DSA-740-1 zlib - buffer overflow
258            {CAN-2005-2096}
259            - zlib 1.2.2-7 (medium)
260            NOTE: anything statically linking zlib needs rebuild
261            TODO: check rest/coord with Kurt Roeckx
262            - aide (unfixed; bug #317523; medium)
263            NOTE: not fixed in testing at time of DSA (embargoed disclosure)
264    [06 Jul 2005] DSA-739-1 trac - missing input sanitising
265            {CAN-2005-2007}
266            - trac 0.8.4-1 (medium)
267            NOTE: fixed in testing at time of DSA
268    [19 May 2005] DSA-725-2 ppxp - missing privilege release
269            {CAN-2005-0392}
270            - ppxp 0.2001080415-11
271            NOTE: fixed in testing at time of DSA
272    [05 Jul 2005] DSA-738-1 razor - email header parsing error
273            {CAN-2005-2024}
274            - razor 2.720-1 (low)
275            NOTE: not fixed in testing at time of DSA (not built on arm)
276    [05 Jul 2005] DSA-737-1 clamav - various DOS vulnerabilities
277            {CAN-2005-1922 CAN-2005-1923 CAN-2005-2056 CAN-2005-2070}
278            - clamav 0.86.1-1 (medium)
279            NOTE: not fixed in testing at time of DSA (uploaded with low urgency only, one fix missing for sid)
280    [05 Jul 2005] DSA-734-1 gaim - denial of service
281            {CAN-2005-1269 CAN-2005-1934}
282            - gaim 1.3.1-1
283            NOTE: not fixed in testing at time of DSA (not built on sparc)
284    [01 Jul 2005] DSA-736-2 spamassassin - mail header parsing error
285            {CAN-2005-1266}
286            - spamassassin 3.0.4-1 (medium)
287            NOTE: fixed in testing at time of DSA
288    [01 Jul 2005] DSA-736-1 spamassassin - mail header parsing error
289            {CAN-2005-1266}
290            - spamassassin 3.0.4-1 (medium)
291            NOTE: fixed in testing at time of DSA
292    [08 Jul 2005] DSA-735-2 sudo - pathname validation race
293            {CAN-2005-1993}
294            - sudo 1.6.8p9-1 (medium)
295            NOTE: fixed in testing at time of DSA
296    [01 Jul 2005] DSA-735-2 sudo - pathname validation race
297            {CAN-2005-1993}
298            - sudo 1.6.8p9-1 (medium)
299            NOTE: fixed in testing at time of DSA
300    [01 Jul 2005] DSA-735-1 sudo - pathname validation race
301            {CAN-2005-1993}
302            - sudo 1.6.8p9-1 (medium)
303            NOTE: not fixed in testing at time of DSA
304    [30 Jun 2005] DSA-733-1 crip - insecure temporary files
305            {CAN-2005-0393}
306            - crip 3.5-1sarge2 (low)
307            NOTE: not fixed in testing at time of DSA (reserved)
308    [03 Jun 2005] DSA-732-1 mailutils - several
309            {CAN-2005-1520 CAN-2005-1521 CAN-2005-1522 CAN-2005-1523}
310            - mailutils 0.6.1-4
311            NOTE: fixed in testing at time of DSA
312    [02 Jun 2005] DSA-731-1 krb4 - buffer overflows
313            {CAN-2005-0468 CAN-2005-0468}
314            - krb4 1.2.2-11.2
315            NOTE: fixed in testing at time of DSA
316    [27 May 2005] DSA-730-1 bzip2 - race condition
317            {CAN-2005-0953}
318            - bzip2 1.0.2-6
319            NOTE: fixed in testing at time of DSA
320    [26 May 2005] DSA-729-1 php4 - missing input sanitising
321            {CAN-2005-0525}
322            - php4 4.3.10-10
323            NOTE: fixed in testing at time of DSA
324    [25 May 2005] DSA-728-1 qpopper - missing privilege release
325            {CAN-2005-1151 CAN-2005-1152}
326            - qpopper 4.0.5-4sarge1
327            NOTE: fixed in testing at time of DSA by security team
328    [20 May 2005] DSA-727-1 libconvert-uulib-perl - buffer overflow
329            {CAN-2005-1349}
330            - libconvert-uulib-perl 1.0.5.1-1
331            NOTE: fixed in testing at time of DSA
332    [20 May 2005] DSA-726-1 oops - format string vulnerability
333            {CAN-2005-1121}
334            - oops (unfixed; bug #307360)
335            NOTE: not in testing at time of DSA
336    [19 May 2005] DSA-725-1 ppxp - missing privilege release
337            {CAN-2005-0392}
338            - ppxp 0.2001080415-11
339            NOTE: not fixed in testing at time of DSA
340    [18 May 2005] DSA-724-1 phpsysinfo - design flaw
341            {CAN-2005-0870}
342            - phpsysinfo 2.3-3
343            NOTE: fixed in testing at time of DSA
344    [09 May 2005] DSA-723-1 xfree86 - buffer overflow
345            {CAN-2005-0605}
346            - xfree86 4.3.0.dfsg.1-13
347            NOTE: not fixed in testing at time of DSA
348    [09 May 2005] DSA-722-1 smail - buffer overflow
349            {CAN-2005-0892}
350            NOTE: Package not in testing at time of DSA
351    [06 May 2005] DSA-721-1 squid - design flaw
352            {CAN-2005-1345}
353            - squid 2.5.9-7
354            NOTE: not fixed in testing at time of DSA
355    [03 May 2005] DSA-720-1 smartlist - wrong input processing
356            {CAN-2005-0157}
357            - smartlist 3.15-18
358            NOTE: fixed in testing at time of DSA
359    [28 Apr 2005] DSA-719-1 prozilla - format string problems
360            {CAN-2005-0523}
361            - prozilla 1:1.3.7.4-1
362            NOTE: fixed in testing at time of DSA
363    [28 Apr 2005] DSA-718-1 ethereal - buffer overflow
364            {CAN-2005-0739}
365            - ethereal 0.10.10-1
366            NOTE: fixed in testing at time of DSA
367    [27 Apr 2005] DSA-717-1 lsh-utils - buffer overflow, typo
368            {CAN-2003-0826 CAN-2005-0814}
369            - lsh-utils 2.0.1-2
370            NOTE: fixed in testing at time of DSA
371    [27 Apr 2005] DSA-716-1 gaim - denial of service
372            {CAN-2005-0472}
373            - gaim 1.1.3-1
374            NOTE: fixed in testing at time of DSA
375    [27 Apr 2005] DSA-715-1 cvs - several
376            {CAN-2004-1342 CAN-2004-1343}
377            - cvs 1.12.9-12
378            NOTE: not fixed in testing at time of DSA
379    [26 Apr 2005] DSA-714-1 kdelibs - several
380            {CAN-2005-1046}
381            - kdelibs 4:3.3.2-5
382            NOTE: not fixed in testing at time of DSA
383    [21 Apr 2005] DSA-701-2 samba - integer overflows
384            NOTE: only a bug in the backported fix to stable, testing is ok
385    [21 Apr 2005] DSA-713-1 junkbuster - several
386            {CAN-2005-1108 CAN-2005-1109}
387            NOTE: package not in testing/unstable
388    [19 Apr 2005] DSA-712-1 geneweb - insecure file operations
389            {CAN-2005-0391}
390            - geneweb 4.10-7
391            NOTE: fixed in testing at time of DSA
392    [19 Apr 2005] DSA-711-1 info2www - missing input sanitising
393            {CAN-2004-1341}
394            - info2www 1.2.2.9-23
395            NOTE: fixed in testing at time of DSA
396    [18 Apr 2005] DSA-710-1 gtkhtml - null pointer dereference
397            {CAN-2003-0541}
398            - gtkhtml 1.0.4-6.2
399            NOTE: fixed in testing at time of DSA
400    [15 Apr 2005] DSA-709-1 libexif - buffer overflow
401            {CAN-2005-0664}
402            - libexif 0.6.9-5
403    [15 Apr 2005] DSA-708-1 php3 - missing input sanitising
404            {CAN-2005-0525}
405            - php3 3.0.18-31
406    [13 Apr 2005] DSA-707-1 mysql - several
407            {CAN-2004-0957 CAN-2005-0709 CAN-2005-0710 CAN-2005-0711}
408            - mysql-dfsg 4.0.24-5
409            - mysql-dfsg-4.1 4.1.10a-6
410            NOTE: not fixed in testing at time of DSA
411    [13 Apr 2005] DSA-706-1 axel - buffer overflow
412            {CAN-2005-0390}
413            - axel 1.0b-1
414            NOTE: fixed in testing at time of DSA
415    [04 Apr 2005] DSA-705-1 wu-ftpd - missing input sanitising
416            {CAN-2005-0256 CAN-2003-0854}
417            - wu-ftpd 2.6.2-19
418    [04 Apr 2005] DSA-704-1 remstats - tempfile, missing input sanitising
419            {CAN-2005-0387 CAN-2005-0388}
420            - remstats 1.0.13a-5
421            NOTE: not fixed in testing at time of DSA
422    [01 Apr 2005] DSA-703-1 krb5 - buffer overflows
423            {CAN-2005-0468 CAN-2005-0469}
424            - krb5 1.3.6-1
425    [01 Apr 2005] DSA-702-1 imagemagick - several
426            {CAN-2005-0397 CAN-2005-0759 CAN-2005-0760 CAN-2005-0762}
427            - imagemagick 6.0.6.2-2.2
428    [31 Mar 2005] DSA-701-1 samba - integer overflows
429            {CAN-2004-1154}
430            - samba 3.0.10-1
431    [30 Mar 2005] DSA-700-1 mailreader - missing input sanitising
432            {CAN-2005-0386}
433            - mailreader 2.3.29-11
434            NOTE: not fixed in testing at time of DSA
435    [29 Mar 2005] DSA-699-1 netkit-telnet-ssl - buffer overflow
436            {CAN-2005-0469}
437            - netkit-telnet-ssl 0.17.24+0.1-7.1
438            NOTE: not fixed in testing at time of DSA
439    [29 Mar 2005] DSA-698-1 mc - buffer overflow
440            {CAN-2005-0763}
441            NOTE: Not clear which unstable/testing version fixed this,
442            NOTE: but advisory says it's fixed.
443    [29 Mar 2005] DSA-697-1 netkit-telnet - buffer overflow
444            {CAN-2005-0469}
445            - netkit-telnet 0.17-28
446            NOTE: not fixed in testing at time of DSA
447    [22 Mar 2005] DSA-696-1 perl - design flaw
448            {CAN-2005-0448}
449            - perl 5.8.4-8
450            NOTE: fixed in testing at time of DSA
451    [21 Mar 2005] DSA-695-1 xli - buffer overflow, input sanitising, integer overflow
452            {CAN-2001-0775 CAN-2005-0638 CAN-2005-0639}
453            - xli 1.17.0-18
454            NOTE: not fixed in testing at time of DSA
455    [21 Mar 2005] DSA-694-1 xloadimage - missing input sanitising, integer overflow
456            {CAN-2005-0638 CAN-2005-0639}
457            - xloadimage 4.1-14.2
458            NOTE: not fixed in testing at time of DSA
459    [14 Mar 2005] DSA-693-1 luxman - buffer overflow
460            {CAN-2005-0385}
461            NOTE: not fixed in testing at time of DSA
462            NOTE: not in unstable at time of DSA though DSA claimed it was
463            - luxman 0.41-20
464    [14 Mar 2005] DSA-662-2 squirrelmail - several
465            NOTE: only an update to a prior DSA, did not affct sid/sarge.
466    [08 Mar 2005] DSA-692-1 kppp - design flaw
467            {CAN-2005-0205}
468            - kppp 4:3.1.6
469            NOTE: fixed in testing at time of DSA
470    [07 Mar 2005] DSA-691-1 abuse - several
471            {CAN-2005-0098 CAN-2005-0099}
472            NOTE: not in unstable/testing
473    [25 Feb 2005] DSA-690-1 bsmtpd - missing input sanitising
474            {CAN-2005-0107}
475            - bsmtpd 2.3pl8b-16
476            NOTE: not fixed in testing at time of DSA
477    [23 Feb 2005] DSA-689-1 libapache-mod-python - missing input sanitising
478            {CAN-2005-0088}
479            - libapache-mod-python 2.7.10-4
480            NOTE: fixed in testing at time of DSA
481            - libapache2-mod-python 3.1.3-3
482            NOTE: fixed in testing at time of DSA
483    [23 Feb 2005] DSA-688-1 squid - mising input sanitising
484            {CAN-2005-0446}
485            - squid 2.5.8-3
486            NOTE: fixed in testing at time of DSA
487    [21 Feb 2005] DSA-674-3 mailman - cross-site scripting, directory traversal
488            NOTE: only fixed bug in DSA
489    [18 Feb 2005] DSA-687-1 bidwatcher - format string
490            {CAN-2005-0158}
491            - bidwatcher 1.3.17-1
492            NOTE: not fixed in testing at time of DSA
493    [17 Feb 2005] DSA-686-1 gftp - missing input sanitising
494            {CAN-2005-0372}
495            - gftp 2.0.18-1
496            NOTE: not fixed in testing at time of DSA
497    [17 Feb 2005] DSA-685-1 emacs21 - format string
498            {CAN-2005-0100}
499            - emacs21 21.3+1-9
500            NOTE: not fixed in testing at time of DSA
501    [16 Feb 2005] DSA-684-1 typespeed - format string
502            {CAN-2005-0105}
503            - typespeed 0.4.4-8
504            NOTE: not fixed in testing at time of DSA
505    [15 Feb 2005] DSA-683-1 postgresql - buffer overflows
506            {CAN-2005-0245 CAN-2005-0247}
507            - postgresql 7.4.7-2
508            NOTE: fixed in testing at time of DSA
509    [15 Feb 2005] DSA-682-1 awstats - missing input sanitising
510            {CAN-2005-0363}
511            - awstats 6.2-1.2
512            NOTE: not fixed in testing at time of DSA
513    [14 Feb 2005] DSA-681-1 synaesthesia - privilege escalation
514            {CAN-2005-0070}
515            NOTE: does not apply for sarge, program is not setuid anymore
516    [14 Feb 2005] DSA-680-1 htdig - unsanitised input
517            {CAN-2005-0085}
518            - htdig 3.1.6-11
519            NOTE: fixed in testing at time of DSA
520    [14 Feb 2005] DSA-679-1 toolchain-source - insecure temporary files
521            {CAN-2005-0159}
522            - toolchain-source 3.4-5
523            NOTE: not fixed in testing at time of DSA
524    [11 Feb 2005] DSA-678-1 netkit-rwho - missing input validation
525            {CAN-2004-1180}
526            - netkit-rwho 0.17-8
527            NOTE: not fixed in testing at time of DSA
528    [11 Feb 2005] DSA-677-1 sympa - buffer overflow
529            {CAN-2005-0073}
530            - sympa 4.1.2-2.1
531            NOTE: not fixed in testing at time of DSA
532    [11 Feb 2005] DSA-676-1 xpcd - buffer overflow
533            {CAN-2005-0074}
534            - xpcd 2.08-11.1
535            NOTE: not fixed in testing at time of DSA
536    [11 Feb 2005] DSA-674-2 mailman - cross-site scripting, directory traversal
537            NOTE: only fixed bug in DSA
538    [10 Feb 2005] DSA-675-1 hztty - privilege escalation
539            {CAN-2005-0019}
540            - hztty 2.0-6.1
541            NOTE: not fixed in testing at time of DSA
542    [10 Feb 2005] DSA-674-1 mailman - cross-site scripting, directory traversal
543            {CAN-2004-1177}
544            - mailman 2.1.5-5
545            NOTE: fixed in testing at time of DSA
546            {CAN-2005-0202}
547            - mailman 2.1.5-6
548            NOTE: not fixed in testing at time of DSA
549    [10 Feb 2005] DSA-673-1 evolution - integer overflow
550            {CAN-2005-0102}
551            - evolution 2.0.3-1.2
552            NOTE: fixed in testing at time of DSA
553    [09 Feb 2005] DSA-672-1 xview - buffer overflows
554            {CAN-2005-0076}
555            - xview 3.2p1.4-19
556            NOTE: not fixed in testing at time of DSA
557    [08 Feb 2005] DSA-671-1 xemacs21 - format string
558            {CAN-2005-0100}
559            NOTE: not fixed in testing at time of DSA
560            - xemacs21 21.4.16-2
561    [08 Feb 2005] DSA-670-1 emacs20 - format string
562            {CAN-2005-0100}
563            NOTE: also affects emacs21 in unstable, fixed
564    [04 Feb 2005] DSA-689-1 php3 - several
565            {CAN-2004-0594 CAN-2004-0595}
566            - php3 3.0.18-27
567            NOTE: fixed in testing at time of DSA
568    [04 Feb 2005] DSA-668-1 postgresql - privilege escalation
569            {CAN-2005-0227}
570            - postgresql 7.4.7-1
571            NOTE: not fixed in testing at time of DSA
572    [04 Feb 2005] DSA-667-1 squid - several
573            {CAN-2005-0173 CAN-2005-0175 CAN-2005-0194 CAN-2005-0211}
574            - squid 2.5.7-7
575            NOTE: not fixed in testing at time of DSA
576    [04 Feb 2005] DSA-666-1 python2.2 - design flaw
577            {CAN-2005-0089}
578            - python2.2 2.2.3-14
579            - python2.3 2.3.4-20
580            - python2.4 2.4-5
581            NOTE: not fixed in testing at time of DSA
582    [04 Feb 2005] DSA-665-1 ncpfs - missing privilege release
583            {CAN-2005-0013}
584            - ncpfs 2.2.6-1
585            NOTE: not fixed in testing at time of DSA
586    [02 Feb 2005] DSA-664-1 cpio - broken file permissions
587            {CAN-1999-1572}
588            - cpio 2.5-1.2
589            NOTE: not fixed in testing at time of DSA
590    [02 Feb 2005] DSA-663-1 prozilla - buffer overflows
591            {CAN-2004-1120}
592            - prozilla 1.3.7.3-1
593            NOTE: fixed in testing at time of DSA
594    [01 Feb 2005] DSA-662-1 squirrelmail - several
595            {CAN-2005-0104 CAN-2005-0152}
596            NOTE: CAN-2005-0152 only exists in 1.2.6 version
597            - squirrelmail 1.4.4
598            NOTE: fixed in testing at time of DSA
599    [20 Apr 2005] DSA-661-2 f2c - insecure temporary files
600            {CAN-2005-0017 CAN-2005-0018}
601            - f2c 20020621-3.3
602            NOTE: not fixed in testing at time of DSA
603    [26 Jan 2005] DSA-660-1 kdebase - missing return value check
604            {CAN-2005-0078}
605            - kdebase 4:3.0.5
606            NOTE: fixed in testing at time of DSA
607    [26 Jan 2005] DSA-659-1 libpam-radius-auth - information leak, integer underflow
608            {CAN-2004-1340 CAN-2005-0108}
609            - libpam-radius-auth 1.3.16-3
610            NOTE: 1/2 fixed in testing at time of DSA
611    [25 Jan 2005] DSA-658-1 libdbi-perl - insecure temporary file
612            {CAN-2005-0077}
613            - libdbi-perl 1.46-6
614            NOTE: not fixed in testing at time of DSA
615    [25 Jan 2005] DSA-657-1 xine-lib - buffer overflow
616            {CAN-2004-1379}
617            - xine-lib 1-rc6a-1
618            NOTE: fixed in testing at time of DSA
619    [25 Jan 2005] DSA-656-1 vdr - insecure file access
620            {CAN-2005-0071}
621            - vdr 1.2.6-6
622            NOTE: not fixed in testing at time of DSA
623    [25 Jan 2005] DSA-655-1 zhcon - missing privilege release
624            {CAN-2005-0072}
625            - zhcon 1:0.2.3-8.1
626            NOTE: not fixed in testing at time of DSA
627    [21 Jan 2005] DSA-654-1 enscript - several
628            {CAN-2004-1184 CAN-2004-1185 CAN-2004-1186}
629            - enscript 1.6.4-6
630            NOTE: not fixed in testing at time of DSA
631    [21 Jan 2005] DSA-653-1 ethereal - buffer overflow
632            {CAN-2005-0084}
633            - ethereal 0.10.9-1
634            NOTE: not fixed in testing at time of DSA
635    [21 Jan 2005] DSA-652-1 unarj
636            {CAN-2004-0947 CAN-2004-1027}
637            NOTE: not-for-us (unarj)
638    [20 Jan 2005] DSA-651-1 squid - buffer overflow, integer overflow
639            {CAN-2005-0094 CAN-2005-0095}
640            - squid 2.5.7-4
641            NOTE: not fixed in testing at time of DSA
642    [20 Jan 2005] DSA-650-1 sword - missing input sanitising
643            {CAN-2005-0015}
644            - sword 1.5.7-7
645            NOTE: not fixed in testing at time of DSA
646    [20 Jan 2005] DSA-649-1 xtrlock - buffer overflow
647            {CAN-2005-0079}
648            - xtrlock 2.0-9
649            NOTE: fixed in testing at time of DSA
650    [19 Jan 2005] DSA-648-1 xpdf - buffer overflow
651            {CAN-2005-0064}
652            - xpdf 3.00-12
653            NOTE: not fixed in testing at time of DSA
654    [19 Jan 2005] DSA-647-1 mysql - insecure temporary files
655            {CAN-2005-0004}
656            - mysql-dfsg 4.0.23-3
657            - mysql-dfsg-4.1 4.1.8a-6
658            NOTE: not fixed in testing at time of DSA
659    [19 Jan 2005] DSA-646-1 imagemagick - buffer overflow
660            {CAN-2005-0005}
661            - imagemagick 6.0.6.2-2
662            NOTE: not fixed in testing at time of DSA
663    [19 Jan 2005] DSA-645-1 cupsys - buffer overflow
664            {CAN-2005-0064}
665            NOTE: cupsys not affected in sarge, though other programs are vulnerable
666            NOTE: see CAN/list
667            NOTE: not fixed in testing at time of DSA
668    [18 Jan 2005] DSA-644-1 chbg - buffer overflow
669            {CAN-2004-1264}
670            - chbg 1.5-4
671            NOTE: fixed in testing at time of DSA
672    [18 Jan 2005] DSA-643-1 queue - buffer overflows
673            {CAN-2004-0555}
674            - queue 1.30.1-5
675            NOTE: not fixed in testing at time of DSA
676    [17 Jan 2005] DSA-642-1 gallery - several
677            {CAN-2004-1106}
678            - gallery 1.4.4-pl4-1
679            NOTE: fixed in testing at time of DSA
680    [17 Jan 2005] DSA-641-1 playmidi - buffer overflow
681            {CAN-2005-0020}
682            - playmidi 2.4debian-3
683            NOTE: not fixed in testing at time of DSA
684    [17 Jan 2005] DSA-640-1 gatos - buffer overflow
685            {CAN-2005-0016}
686            - gatos 0.0.5-15
687            NOTE: not fixed in testing at time of DSA
688    [14 Jan 2005] DSA-639-1 mc - several
689            {CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176}
690            NOTE: unstable not vulnerable according to DSA
691            NOTE: DSA was wrong..
692            - mc 1:4.6.0-4.6.1-pre3-1
693            NOTE: not fixed in testing at time of DSA
694    [13 Jan 2005] DSA-638-1 gopher - several
695            {CAN-2004-0560 CAN-2004-0561}
696            NOTE: not in sarge
697    [13 Jan 2005] DSA-637-1 exim-tls - buffer overflow
698            {CAN-2005-0021}
699            NOTE: not in sarge
700    [12 Jan 2005] DSA-636-1 glibc - insecure temporary files
701            {CAN-2004-0968}
702            - glibc 2.3.2.ds1-20
703            NOTE: fixed in testing at time of DSA
704    [12 Jan 2005] DSA-635-1 exim - buffer overflow
705            {CAN-2005-0021}
706            - exim4 4.34-10
707            NOTE: fixed in testing at time of DSA
708            - exim 3.36-13
709            NOTE: not fixed in testing at time of DSA
710    [11 Jan 2005] DSA-634-1 hylafax - weak hostname and username validation
711            {CAN-2004-1182}
712            - hylafax 4.2.1-1
713            NOTE: fixed in testing at time of DSA
714    [11 Jan 2005] DSA-633-1 bmv - insecure temporary file
715            {CAN-2003-0014}
716            - bmv 1.2-17
717            NOTE: fixed in testing at time of DSA
718    [10 Jan 2005] DSA-632-1 linpopup - buffer overflow
719            {CAN-2004-1282}
720            - linpopup 1.2.0-7
721            NOTE: fixed in testing at time of DSA
722    [10 Jan 2005] DSA-631-1 kdelibs - unsanitised input
723            {CAN-2004-1165}
724            - kdelibs 4:3.3.2-1
725            NOTE: not fixed in testing at time of DSA
726    [10 Jan 2005] DSA-630-1 lintian - insecure temporary directory
727            {CAN-2004-1000}
728            - lintian 1.23.6
729            NOTE: not fixed in testing at time of DSA
730    [07 Jan 2005] DSA-629-1 krb5 - buffer overflow
731            {CAN-2004-1189}
732            - krb5 1.3.6-1
733            NOTE: not fixed in testing at time of DSA
734    [06 Jan 2005] DSA-628-1 imlib2 - integer overflows
735            {CAN-2004-1026}
736            - imlib2 1.1.2-2.1
737            NOTE: not fixed in testing at time of DSA
738    [06 Jan 2005] DSA-627-1 namazu2 - unsanitised input
739            {CAN-2004-1318}
740            - namazu2 2.0.14-1
741            NOTE: not fixed in testing at time of DSA
742    [06 Jan 2005] DSA-626-1 tiff - unsanitised input
743            {CAN-2004-1183}
744            - libtiff4 3.6.1-5
745            NOTE: not fixed in testing at time of DSA
746    [05 Jan 2005] DSA-625-1 pcal - buffer overflows
747            {CAN-2004-1289}
748            - pcal 4.8.0-1
749            NOTE: not fixed in testing at time of DSA
750    [05 Jan 2005] DSA-624-1 zip - buffer overflow
751            {CAN-2004-1010}
752            - zip 2.30-8
753            NOTE: fixed in testing at time of DSA
754    [04 Jan 2005] DSA-623-1 nasm - buffer overflow
755            {CAN-2004-1287}
756            - nasm 0.98.38-1.1
757    [03 Jan 2005] DSA-622-1 htmlheadline - insecure temporary files
758            {CAN-2004-1181}
759            NOTE: not in unstable
760    [31 Dec 2004] DSA-621-1 cupsys - buffer overflow
761            {CAN-2004-1125}
762            - cupsys 1.1.22-2
763    [30 Dec 2004] DSA-620-1 perl - insecure temporary files / directories
764            {CAN-2004-0452 CAN-2004-0976}
765            - perl 5.8.4-5
766    [30 Dev 2004] DSA-619-1 xpdf - buffer overflow
767            {CAN-2004-1125}
768            - xpdf 3.00-11
769    [24 Dec 2004] DSA-618-1 imlib - buffer overflows, integer overflows
770            {CAN-2004-1025 CAN-2004-1026}
771            - imlib 1.9.14-17.1
772            - imlib-png2 1.9.14-16.1
773    [24 Dec 2004] DSA-617-1 libtiff - insufficient input validation
774            {CAN-2004-1308}
775            - libtiff4 3.6.1-4
776    [23 Dec 2004] DSA-616-1 telnetd-ssl - format string
777            {CAN-2004-0998}
778            - telnetd-ssl 0.17.24+0.1-6
779    [22 Dec 2004] DSA-615-1 debmake - insecure temporary file
780            {CAN-2004-1179}
781            - debmake 3.7.7
782    [21 Dec 2004] DSA-614-1 xzgv - integer overflows
783            {CAN-2004-0994}
784            - xzgv 0.8-3
785    [21 Dec 2004] DSA-613-1 ethereal - inifinite loop
786            {CAN-2004-114}
787            - ethereal 0.10.8-1
788    [21 Dec 2004] DSA-614-1 xzgv - integer overflows
789            {CAN-2004-0994}
790            - xzgv 0.8-3
791    [20 Dec 2004] DSA-612-1 a2ps - unsanitised input
792            {CAN-2004-1170}
793            - a2ps 4.13b-4.2
794    [20 Dec 2004] DSA-611-1 htget - buffer overflow
795            {CAN-2004-0852}
796            NOTE: htget not in sarge or unstable
797    [17 Dec 2004] DSA-610-1 cscope - insecure temporary file
798            {CAN-2004-0996}
799            - cscope 15.5-1
800    [14 Dec 2004] DSA-609-1 atari800 - buffer overflows
801            {CAN-2004-1076}
802            - atari800 1.3.2-1
803    [14 Dec 2004] DSA-608-1 zgv - integer overflows, unsanitised input
804            {CAN-2004-1095 CAN-2004-0999}
805            - zgv 5.7-1.3
806            NOTE: changelog says he only patched 1095, but diff comparison
807            NOTE: shows 0999 was also fixed.
808    [10 Dec 2004] DSA-607-1 xfree86 - several
809            {CAN-2004-0914}
810            - xfree86 4.3.0.dfsg.1-9
811    [08 Dec 2004] DSA-606-1 nfs-utils - wrong signal handler
812            {CAN-2004-1014}
813            - nfs-utils 1:1.0.6-3.1
814    [06 Dec 2004] DSA-605-1 viewcvs - settings not honored
815            {CAN-2004-0915}
816            - viewcvs 0.9.2+cvs.1.0.dev.2004.07.28-1.2
817  [03 Dec 2004] DSA-604-1 hpsockd - missing input sanitising  [03 Dec 2004] DSA-604-1 hpsockd - missing input sanitising
818          {CAN-2004-0993}          {CAN-2004-0993}
819          - hpsockd 0.14          - hpsockd 0.14
820  [01 Dec 2004] DSA-603-1 openssl - insecure temporary file  [01 Dec 2004] DSA-603-1 openssl - insecure temporary file
821          {CAN-2004-0975}          {CAN-2004-0975}
822          - openssl 0.9.7e-1          - openssl 0.9.7e-3
823  [29 Nov 2004] DSA-602-1 libgd2 - integer overlow  [29 Nov 2004] DSA-602-1 libgd2 - integer overlow
824          {CAN-2004-0941 CAN-2004-0990}          {CAN-2004-0941 CAN-2004-0990}
825          NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new          NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
# Line 20  Line 836 
836          - yardradius 1.0.20-15          - yardradius 1.0.20-15
837  [25 Nov 2004] DSA-597-1 cyrus-imapd - buffer overflow  [25 Nov 2004] DSA-597-1 cyrus-imapd - buffer overflow
838          {CAN-2004-1012 CAN-2004-1013}          {CAN-2004-1012 CAN-2004-1013}
839          - cyrus-imapd 2.1.17-1          - cyrus21-imapd 2.1.17-1
840  [24 Nov 2004] DSA-596-2 sudo - missing input sanitising  [24 Nov 2004] DSA-596-2 sudo - missing input sanitising
841          {CAN-2004-1051}          {CAN-2004-1051}
842          - sudo 1.6.8p3-1          - sudo 1.6.8p3-1
# Line 48  Line 864 
864          - gnats 4.0-6.1          - gnats 4.0-6.1
865  [09 Nov 2004] DSA-589-1 libgd - integer overflows  [09 Nov 2004] DSA-589-1 libgd - integer overflows
866          {CAN-2004-0990}          {CAN-2004-0990}
867          - libgd1 (unfixed; bug #280134)          - libgd1 1.8.4-36.1
868  [08 Nov 2004] DSA-588-1 gzip - insecure temporary files  [08 Nov 2004] DSA-588-1 gzip - insecure temporary files
869          {CAN-2004-0970}          {CAN-2004-0970}
870          NOTE: dsa says sid not affected          NOTE: dsa says sid not affected
# Line 100  Line 916 
916          - cupsys 1.1.20final+rc1-10          - cupsys 1.1.20final+rc1-10
917          {CAN-2004-0889}          {CAN-2004-0889}
918          - xpdf 3.00-10          - xpdf 3.00-10
919          TODO: kpdf and kfax not fixed in sarge, bug #278173 has a backported patch for the kpdf hole          NOTE: kpdf and kfax are fixed in sarge, bug #278173 and #280373 for reference
920          - kpdf 4:3.3.1-1          - kpdf 4:3.3.1-1
921          - gpdf 2.8.0-1          - gpdf 2.8.0-1
922          - kfax 4:3.3.1-1          - kfax 4:3.3.1-1
# Line 186  Line 1002 
1002  [16 Sep 2004] DSA-548-1 imlib - unsanitised input  [16 Sep 2004] DSA-548-1 imlib - unsanitised input
1003          {CAN-2004-0817}          {CAN-2004-0817}
1004          - imlib 1.9.14-17          - imlib 1.9.14-17
1005          - imlib+png2 1.9.14-16          - imlib+png2 1.9.14-16.2
1006  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows
1007          {CAN-2004-0827}          {CAN-2004-0827}
1008          - imagemagic 6.0.6.2-1          - imagemagic 6.0.6.2-1
# Line 305  Line 1121 
1121          {CAN-2004-0522}          {CAN-2004-0522}
1122          - gallery 1.4.3-pl2-1          - gallery 1.4.3-pl2-1
1123  [30 May 2004] DSA-511 ethereal - buffer overflows  [30 May 2004] DSA-511 ethereal - buffer overflows
1124          {CAN-2004-0176          {CAN-2004-0176}
1125          - ethereal 0.10.3-1          - ethereal 0.10.3-1
1126  [29 May 2004] DSA-510 jftpgw - format string  [29 May 2004] DSA-510 jftpgw - format string
1127          {CAN-2004-0448}          {CAN-2004-0448}
# Line 803  Line 1619 
1619          {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}          {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}
1620          NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.          NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.
1621  [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit  [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit
1622            {CAN-2003-0466}
1623          - wu-ftpd 2.6.2-12          - wu-ftpd 2.6.2-12
1624  [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows  [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows
1625          {CAN-2003-0611}          {CAN-2003-0611}

Legend:
Removed from v.172  
changed lines
  Added in v.1822

  ViewVC Help
Powered by ViewVC 1.1.5