/[secure-testing]/data/DSA/list
ViewVC logotype

Diff of /data/DSA/list

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

sarge-checks/DSA/list revision 84 by joeyh, Fri Nov 5 21:17:54 2004 UTC data/DSA/list revision 1446 by jmm-guest, Thu Jul 21 07:13:42 2005 UTC
# Line 1  Line 1 
1    [21 Jul 2005] DSA-764-1 cacti - several
2            {CAN-2005-1524 CAN-2005-1525 CAN-2005-1526 CAN-2005-2148 CAN-2005-2149}
3            - cacti 0.8.6f-1 (high)
4            NOTE: fixed in testing at time of DSA
5            NOTE: DSA information is incorrect, sid fix is 6f, not 6e
6    [20 Jul 2005] DSA-763-1 zlib - buffer overflow
7            {CAN-2005-1849}
8            - zlib 1.2.3-1 (medium)
9            NOTE: not fixed in testing at time of DSA (only 1/2 days old, not built on s390)
10    [19 Jul 2005] DSA-762-1 affix - several
11            {CAN-2005-2250 CAN-2005-2277}
12            - affix 2.1.2-2 (medium)
13            NOTE: not fixed in testing at time of DSA (only 2/2 days old)
14    [19 Jul 2005] DSA-761-1 heartbeat - insecure temporary files
15            {CAN-2005-2231}
16            - heartbeat 1.2.3-12 (medium)
17            NOTE: not fixed in testing at time of DSA (only 0/2 days old)
18    [18 Jul 2005] DSA-760-1 ekg - several
19            {CAN-2005-1850 CAN-2005-1851 CAN-2005-1916}
20            - ekg 1.5+20050712+1.6rc2-1 (low)
21            NOTE: not fixed in testing at time of DSA (waiting on dependencies, not built on five archs)
22    [18 Jul 2005] DSA-759-1 phppgadmin - missing input sanitising
23            {CAN-2005-2256}
24            - phppgadmin 3.5.4-1 (medium)
25            NOTE: not fixed in testing at time of DSA (only 0/10 days old)
26    [18 Jul 2005] DSA-758-1 heimdal - buffer overflow
27            {CAN-2005-2040}
28            - heimdal 0.6.3-11 (medium)
29            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
30    [17 Jul 2005] DSA-757-1 krb5 - buffer overflow, double-free memory
31            {CAN-2005-1689 CAN-2005-1174 CAN-2005-1175}
32            - krb5 1.3.6-4 (medium)
33            NOTE: not fixed in testing at time of DSA (waiting on dependencies, not built on m68k)
34    [14 Jul 2005] DSA-746-1 phpgroupware - remote command execution
35            {CAN-2005-1921}
36            - phpgroupware 0.9.16.006-1 (high)
37            NOTE: fixed in testing at time of DSA
38    [13 Jul 2005] DSA-756-1 squirrelmail - several
39            {CAN-2005-1769 CAN-2005-2095}
40            - squirrelmail 2:1.4.4-6 (medium)
41            NOTE: not fixed in testing at time of DSA (only 0/2 days old)
42    [13 Jul 2005] DSA-755-1 tiff - buffer overflow
43            {CAN-2005-1544}
44            - tiff 3.7.2-3 (medium)
45            NOTE: fixed in testing at time of DSA
46    [13 Jul 2005] DSA-754-1 centericq - insecure temporary file
47            {CAN-2005-1914}
48            - centericq 4.20.0-7 (low)
49            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
50    [12 Jul 2005] DSA-753-1 gedit - format string
51            {CAN-2005-1686}
52            - gedit 2.10.3-1 (low)
53            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
54    [11 Jul 2005] DSA-752-1 gzip - several
55            {CAN-2005-0988 CAN-2005-1228}
56            - gzip 1.3.5-10
57            NOTE: fixed in testing at time of DSA
58    [11 Jul 2005] DSA-751-1 squid - IP spoofind
59            {CAN-2005-1519}
60            - squid 2.5.9-9
61            NOTE: fixed in testing at time of DSA
62    [10 Jul 2005] DSA-748-1 ruby1.8 - bad default value
63            {CAN-2005-1992}
64            - ruby1.8 1.8.2-8 (medium)
65            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
66    [11 Jul 2005] DSA-750-1 dhcpcd - out-of-bound memory access
67            {CAN-2005-1848}
68            - dhcpcd 1.3.22pl4-22
69            NOTE: fixed in testing at time of DSA
70    [10 Jul 2005] DSA-749-1 ettercap - format string error
71            {CAN-2005-1796}
72            - ettercap 0.7.3-1 (medium)
73            NOTE: fixed in testing at time of DSA
74    [10 Jul 2005] DSA-747-1 egroupware - input validation error
75            {CAN-2005-1921}
76            - egroupware 1.0.0.007-3.dfsg-1 (high)
77            NOTE: not fixed in testing at time of DSA (only 1/2 days old)
78    [10 Jul 2005] DSA-745-1 drupal - arbitrary command execution
79            {CAN-2005-1921 CAN-2005-2106 CAN-2005-2116}
80            - drupal 4.5.4-1 (high)
81            NOTE: fixed in testing at time of DSA
82    [08 Jul 2005] DSA-744-1 fuse - programming error
83            {CAN-2005-1858}
84            - fuse 2.3.0-1
85            NOTE: fixed in testing at time of DSA
86    [08 Jul 2005] DSA-743-1 ht - buffer overflows, integer overflows
87            {CAN-2005-1545 CAN-2005-1546}
88            - ht 0.8.0-3
89            NOTE: fixed in testing at time of DSA
90    [09 Jul 2005] DSA-742-1 cvs - buffer overflow
91            {CAN-2005-0753}
92            - cvs 1:1.12.9-13 (high)
93            NOTE: fixed in testing at time of DSA
94    [07 Jul 2005] DSA-741-1 bzip2 - infinite loop
95            {CAN-2005-1260}
96            - bzip2 1.0.2-7 (low)
97            NOTE: fixed in testing at time of DSA
98    [06 Jul 2005] DSA-740-1 zlib - buffer overflow
99            {CAN-2005-2096}
100            - zlib 1.2.2-7 (medium)
101            NOTE: anything statically linking zlib needs rebuild
102            TODO: check rest/coord with Kurt Roeckx
103            - aide (unfixed; bug #317523; medium)
104            NOTE: not fixed in testing at time of DSA (embargoed disclosure)
105    [06 Jul 2005] DSA-739-1 trac - missing input sanitising
106            {CAN-2005-2007}
107            - trac 0.8.4-1 (medium)
108            NOTE: fixed in testing at time of DSA
109    [19 May 2005] DSA-725-2 ppxp - missing privilege release
110            {CAN-2005-0392}
111            - ppxp 0.2001080415-11
112            NOTE: fixed in testing at time of DSA
113    [05 Jul 2005] DSA-738-1 razor - email header parsing error
114            {CAN-2005-2024}
115            - razor 2.720-1 (low)
116            NOTE: not fixed in testing at time of DSA (not built on arm)
117    [05 Jul 2005] DSA-737-1 clamav - various DOS vulnerabilities
118            {CAN-2005-1922 CAN-2005-1923 CAN-2005-2056 CAN-2005-2070}
119            - clamav 0.86.1-1 (medium)
120            NOTE: not fixed in testing at time of DSA (uploaded with low urgency only, one fix missing for sid)
121    [05 Jul 2005] DSA-734-1 gaim - denial of service
122            {CAN-2005-1269 CAN-2005-1934}
123            - gaim 1.3.1-1
124            NOTE: not fixed in testing at time of DSA (not built on sparc)
125    [01 Jul 2005] DSA-736-2 spamassassin - mail header parsing error
126            {CAN-2005-1266}
127            - spamassassin 3.0.4-1 (medium)
128            NOTE: fixed in testing at time of DSA
129    [01 Jul 2005] DSA-736-1 spamassassin - mail header parsing error
130            {CAN-2005-1266}
131            - spamassassin 3.0.4-1 (medium)
132            NOTE: fixed in testing at time of DSA
133    [08 Jul 2005] DSA-735-2 sudo - pathname validation race
134            {CAN-2005-1993}
135            - sudo 1.6.8p9-1 (medium)
136            NOTE: fixed in testing at time of DSA
137    [01 Jul 2005] DSA-735-2 sudo - pathname validation race
138            {CAN-2005-1993}
139            - sudo 1.6.8p9-1 (medium)
140            NOTE: fixed in testing at time of DSA
141    [01 Jul 2005] DSA-735-1 sudo - pathname validation race
142            {CAN-2005-1993}
143            - sudo 1.6.8p9-1 (medium)
144            NOTE: not fixed in testing at time of DSA
145    [30 Jun 2005] DSA-733-1 crip - insecure temporary files
146            {CAN-2005-0393}
147            - crip 3.5-1sarge2 (low)
148            NOTE: not fixed in testing at time of DSA (reserved)
149    [03 Jun 2005] DSA-732-1 mailutils - several
150            {CAN-2005-1520 CAN-2005-1521 CAN-2005-1522 CAN-2005-1523}
151            - mailutils 0.6.1-4
152            NOTE: fixed in testing at time of DSA
153    [02 Jun 2005] DSA-731-1 krb4 - buffer overflows
154            {CAN-2005-0468 CAN-2005-0468}
155            - krb4 1.2.2-11.2
156            NOTE: fixed in testing at time of DSA
157    [27 May 2005] DSA-730-1 bzip2 - race condition
158            {CAN-2005-0953}
159            - bzip2 1.0.2-6
160            NOTE: fixed in testing at time of DSA
161    [26 May 2005] DSA-729-1 php4 - missing input sanitising
162            {CAN-2005-0525}
163            - php4 4.3.10-10
164            NOTE: fixed in testing at time of DSA
165    [25 May 2005] DSA-728-1 qpopper - missing privilege release
166            {CAN-2005-1151 CAN-2005-1152}
167            - qpopper 4.0.5-4sarge1
168            NOTE: fixed in testing at time of DSA by security team
169    [20 May 2005] DSA-727-1 libconvert-uulib-perl - buffer overflow
170            {CAN-2005-1349}
171            - libconvert-uulib-perl 1.0.5.1-1
172            NOTE: fixed in testing at time of DSA
173    [20 May 2005] DSA-726-1 oops - format string vulnerability
174            {CAN-2005-1121}
175            - oops (unfixed; bug #307360)
176            NOTE: not in testing at time of DSA
177    [19 May 2005] DSA-725-1 ppxp - missing privilege release
178            {CAN-2005-0392}
179            - ppxp 0.2001080415-11
180            NOTE: not fixed in testing at time of DSA
181    [18 May 2005] DSA-724-1 phpsysinfo - design flaw
182            {CAN-2005-0870}
183            - phpsysinfo 2.3-3
184            NOTE: fixed in testing at time of DSA
185    [09 May 2005] DSA-723-1 xfree86 - buffer overflow
186            {CAN-2005-0605}
187            - xfree86 4.3.0.dfsg.1-13
188            NOTE: not fixed in testing at time of DSA
189    [09 May 2005] DSA-722-1 smail - buffer overflow
190            {CAN-2005-0892}
191            NOTE: Package not in testing at time of DSA
192    [06 May 2005] DSA-721-1 squid - design flaw
193            {CAN-2005-1345}
194            - squid 2.5.9-7
195            NOTE: not fixed in testing at time of DSA
196    [03 May 2005] DSA-720-1 smartlist - wrong input processing
197            {CAN-2005-0157}
198            - smartlist 3.15-18
199            NOTE: fixed in testing at time of DSA
200    [28 Apr 2005] DSA-719-1 prozilla - format string problems
201            {CAN-2005-0523}
202            - prozilla 1:1.3.7.4-1
203            NOTE: fixed in testing at time of DSA
204    [28 Apr 2005] DSA-718-1 ethereal - buffer overflow
205            {CAN-2005-0739}
206            - ethereal 0.10.10-1
207            NOTE: fixed in testing at time of DSA
208    [27 Apr 2005] DSA-717-1 lsh-utils - buffer overflow, typo
209            {CAN-2003-0826 CAN-2005-0814}
210            - lsh-utils 2.0.1-2
211            NOTE: fixed in testing at time of DSA
212    [27 Apr 2005] DSA-716-1 gaim - denial of service
213            {CAN-2005-0472}
214            - gaim 1.1.3-1
215            NOTE: fixed in testing at time of DSA
216    [27 Apr 2005] DSA-715-1 cvs - several
217            {CAN-2004-1342 CAN-2004-1343}
218            - cvs 1.12.9-12
219            NOTE: not fixed in testing at time of DSA
220    [26 Apr 2005] DSA-714-1 kdelibs - several
221            {CAN-2005-1046}
222            - kdelibs 4:3.3.2-5
223            NOTE: not fixed in testing at time of DSA
224    [21 Apr 2005] DSA-701-2 samba - integer overflows
225            NOTE: only a bug in the backported fix to stable, testing is ok
226    [21 Apr 2005] DSA-713-1 junkbuster - several
227            {CAN-2005-1108 CAN-2005-1109}
228            NOTE: package not in testing/unstable
229    [19 Apr 2005] DSA-712-1 geneweb - insecure file operations
230            {CAN-2005-0391}
231            - geneweb 4.10-7
232            NOTE: fixed in testing at time of DSA
233    [19 Apr 2005] DSA-711-1 info2www - missing input sanitising
234            {CAN-2004-1341}
235            - info2www 1.2.2.9-23
236            NOTE: fixed in testing at time of DSA
237    [18 Apr 2005] DSA-710-1 gtkhtml - null pointer dereference
238            {CAN-2003-0541}
239            - gtkhtml 1.0.4-6.2
240            NOTE: fixed in testing at time of DSA
241    [15 Apr 2005] DSA-709-1 libexif - buffer overflow
242            {CAN-2005-0664}
243            - libexif 0.6.9-5
244    [15 Apr 2005] DSA-708-1 php3 - missing input sanitising
245            {CAN-2005-0525}
246            - php3 3.0.18-31
247    [13 Apr 2005] DSA-707-1 mysql - several
248            {CAN-2004-0957 CAN-2005-0709 CAN-2005-0710 CAN-2005-0711}
249            - mysql-dfsg 4.0.24-5
250            - mysql-dfsg-4.1 4.1.10a-6
251            NOTE: not fixed in testing at time of DSA
252    [13 Apr 2005] DSA-706-1 axel - buffer overflow
253            {CAN-2005-0390}
254            - axel 1.0b-1
255            NOTE: fixed in testing at time of DSA
256    [04 Apr 2005] DSA-705-1 wu-ftpd - missing input sanitising
257            {CAN-2005-0256 CAN-2003-0854}
258            - wu-ftpd 2.6.2-19
259    [04 Apr 2005] DSA-704-1 remstats - tempfile, missing input sanitising
260            {CAN-2005-0387 CAN-2005-0388}
261            - remstats 1.0.13a-5
262            NOTE: not fixed in testing at time of DSA
263    [01 Apr 2005] DSA-703-1 krb5 - buffer overflows
264            {CAN-2005-0468 CAN-2005-0469}
265            - krb5 1.3.6-1
266    [01 Apr 2005] DSA-702-1 imagemagick - several
267            {CAN-2005-0397 CAN-2005-0759 CAN-2005-0760 CAN-2005-0762}
268            - imagemagick 6.0.6.2-2.2
269    [31 Mar 2005] DSA-701-1 samba - integer overflows
270            {CAN-2004-1154}
271            - samba 3.0.10-1
272    [30 Mar 2005] DSA-700-1 mailreader - missing input sanitising
273            {CAN-2005-0386}
274            - mailreader 2.3.29-11
275            NOTE: not fixed in testing at time of DSA
276    [29 Mar 2005] DSA-699-1 netkit-telnet-ssl - buffer overflow
277            {CAN-2005-0469}
278            - netkit-telnet-ssl 0.17.24+0.1-7.1
279            NOTE: not fixed in testing at time of DSA
280    [29 Mar 2005] DSA-698-1 mc - buffer overflow
281            {CAN-2005-0763}
282            NOTE: Not clear which unstable/testing version fixed this,
283            NOTE: but advisory says it's fixed.
284    [29 Mar 2005] DSA-697-1 netkit-telnet - buffer overflow
285            {CAN-2005-0469}
286            - netkit-telnet 0.17-28
287            NOTE: not fixed in testing at time of DSA
288    [22 Mar 2005] DSA-696-1 perl - design flaw
289            {CAN-2005-0448}
290            - perl 5.8.4-8
291            NOTE: fixed in testing at time of DSA
292    [21 Mar 2005] DSA-695-1 xli - buffer overflow, input sanitising, integer overflow
293            {CAN-2001-0775 CAN-2005-0638 CAN-2005-0639}
294            - xli 1.17.0-18
295            NOTE: not fixed in testing at time of DSA
296    [21 Mar 2005] DSA-694-1 xloadimage - missing input sanitising, integer overflow
297            {CAN-2005-0638 CAN-2005-0639}
298            - xloadimage 4.1-14.2
299            NOTE: not fixed in testing at time of DSA
300    [14 Mar 2005] DSA-693-1 luxman - buffer overflow
301            {CAN-2005-0385}
302            NOTE: not fixed in testing at time of DSA
303            NOTE: not in unstable at time of DSA though DSA claimed it was
304            - luxman 0.41-20
305    [14 Mar 2005] DSA-662-2 squirrelmail - several
306            NOTE: only an update to a prior DSA, did not affct sid/sarge.
307    [08 Mar 2005] DSA-692-1 kppp - design flaw
308            {CAN-2005-0205}
309            - kppp 4:3.1.6
310            NOTE: fixed in testing at time of DSA
311    [07 Mar 2005] DSA-691-1 abuse - several
312            {CAN-2005-0098 CAN-2005-0099}
313            NOTE: not in unstable/testing
314    [25 Feb 2005] DSA-690-1 bsmtpd - missing input sanitising
315            {CAN-2005-0107}
316            - bsmtpd 2.3pl8b-16
317            NOTE: not fixed in testing at time of DSA
318    [23 Feb 2005] DSA-689-1 libapache-mod-python - missing input sanitising
319            {CAN-2005-0088}
320            - libapache-mod-python 2.7.10-4
321            NOTE: fixed in testing at time of DSA
322            - libapache2-mod-python 3.1.3-3
323            NOTE: fixed in testing at time of DSA
324    [23 Feb 2005] DSA-688-1 squid - mising input sanitising
325            {CAN-2005-0446}
326            - squid 2.5.8-3
327            NOTE: fixed in testing at time of DSA
328    [21 Feb 2005] DSA-674-3 mailman - cross-site scripting, directory traversal
329            NOTE: only fixed bug in DSA
330    [18 Feb 2005] DSA-687-1 bidwatcher - format string
331            {CAN-2005-0158}
332            - bidwatcher 1.3.17-1
333            NOTE: not fixed in testing at time of DSA
334    [17 Feb 2005] DSA-686-1 gftp - missing input sanitising
335            {CAN-2005-0372}
336            - gftp 2.0.18-1
337            NOTE: not fixed in testing at time of DSA
338    [17 Feb 2005] DSA-685-1 emacs21 - format string
339            {CAN-2005-0100}
340            - emacs21 21.3+1-9
341            NOTE: not fixed in testing at time of DSA
342    [16 Feb 2005] DSA-684-1 typespeed - format string
343            {CAN-2005-0105}
344            - typespeed 0.4.4-8
345            NOTE: not fixed in testing at time of DSA
346    [15 Feb 2005] DSA-683-1 postgresql - buffer overflows
347            {CAN-2005-0245 CAN-2005-0247}
348            - postgresql 7.4.7-2
349            NOTE: fixed in testing at time of DSA
350    [15 Feb 2005] DSA-682-1 awstats - missing input sanitising
351            {CAN-2005-0363}
352            - awstats 6.2-1.2
353            NOTE: not fixed in testing at time of DSA
354    [14 Feb 2005] DSA-681-1 synaesthesia - privilege escalation
355            {CAN-2005-0070}
356            NOTE: does not apply for sarge, program is not setuid anymore
357    [14 Feb 2005] DSA-680-1 htdig - unsanitised input
358            {CAN-2005-0085}
359            - htdig 3.1.6-11
360            NOTE: fixed in testing at time of DSA
361    [14 Feb 2005] DSA-679-1 toolchain-source - insecure temporary files
362            {CAN-2005-0159}
363            - toolchain-source 3.4-5
364            NOTE: not fixed in testing at time of DSA
365    [11 Feb 2005] DSA-678-1 netkit-rwho - missing input validation
366            {CAN-2004-1180}
367            - netkit-rwho 0.17-8
368            NOTE: not fixed in testing at time of DSA
369    [11 Feb 2005] DSA-677-1 sympa - buffer overflow
370            {CAN-2005-0073}
371            - sympa 4.1.2-2.1
372            NOTE: not fixed in testing at time of DSA
373    [11 Feb 2005] DSA-676-1 xpcd - buffer overflow
374            {CAN-2005-0074}
375            - xpcd 2.08-11.1
376            NOTE: not fixed in testing at time of DSA
377    [11 Feb 2005] DSA-674-2 mailman - cross-site scripting, directory traversal
378            NOTE: only fixed bug in DSA
379    [10 Feb 2005] DSA-675-1 hztty - privilege escalation
380            {CAN-2005-0019}
381            - hztty 2.0-6.1
382            NOTE: not fixed in testing at time of DSA
383    [10 Feb 2005] DSA-674-1 mailman - cross-site scripting, directory traversal
384            {CAN-2004-1177}
385            - mailman 2.1.5-5
386            NOTE: fixed in testing at time of DSA
387            {CAN-2005-0202}
388            - mailman 2.1.5-6
389            NOTE: not fixed in testing at time of DSA
390    [10 Feb 2005] DSA-673-1 evolution - integer overflow
391            {CAN-2005-0102}
392            - evolution 2.0.3-1.2
393            NOTE: fixed in testing at time of DSA
394    [09 Feb 2005] DSA-672-1 xview - buffer overflows
395            {CAN-2005-0076}
396            - xview 3.2p1.4-19
397            NOTE: not fixed in testing at time of DSA
398    [08 Feb 2005] DSA-671-1 xemacs21 - format string
399            {CAN-2005-0100}
400            NOTE: not fixed in testing at time of DSA
401            - xemacs21 21.4.16-2
402    [08 Feb 2005] DSA-670-1 emacs20 - format string
403            {CAN-2005-0100}
404            NOTE: also affects emacs21 in unstable, fixed
405    [04 Feb 2005] DSA-689-1 php3 - several
406            {CAN-2004-0594 CAN-2004-0595}
407            - php3 3.0.18-27
408            NOTE: fixed in testing at time of DSA
409    [04 Feb 2005] DSA-668-1 postgresql - privilege escalation
410            {CAN-2005-0227}
411            - postgresql 7.4.7-1
412            NOTE: not fixed in testing at time of DSA
413    [04 Feb 2005] DSA-667-1 squid - several
414            {CAN-2005-0173 CAN-2005-0175 CAN-2005-0194 CAN-2005-0211}
415            - squid 2.5.7-7
416            NOTE: not fixed in testing at time of DSA
417    [04 Feb 2005] DSA-666-1 python2.2 - design flaw
418            {CAN-2005-0089}
419            - python2.2 2.2.3-14
420            - python2.3 2.3.4-20
421            - python2.4 2.4-5
422            NOTE: not fixed in testing at time of DSA
423    [04 Feb 2005] DSA-665-1 ncpfs - missing privilege release
424            {CAN-2005-0013}
425            - ncpfs 2.2.6-1
426            NOTE: not fixed in testing at time of DSA
427    [02 Feb 2005] DSA-664-1 cpio - broken file permissions
428            {CAN-1999-1572}
429            - cpio 2.5-1.2
430            NOTE: not fixed in testing at time of DSA
431    [02 Feb 2005] DSA-663-1 prozilla - buffer overflows
432            {CAN-2004-1120}
433            - prozilla 1.3.7.3-1
434            NOTE: fixed in testing at time of DSA
435    [01 Feb 2005] DSA-662-1 squirrelmail - several
436            {CAN-2005-0104 CAN-2005-0152}
437            NOTE: CAN-2005-0152 only exists in 1.2.6 version
438            - squirrelmail 1.4.4
439            NOTE: fixed in testing at time of DSA
440    [20 Apr 2005] DSA-661-2 f2c - insecure temporary files
441            {CAN-2005-0017 CAN-2005-0018}
442            - f2c 20020621-3.3
443            NOTE: not fixed in testing at time of DSA
444    [26 Jan 2005] DSA-660-1 kdebase - missing return value check
445            {CAN-2005-0078}
446            - kdebase 4:3.0.5
447            NOTE: fixed in testing at time of DSA
448    [26 Jan 2005] DSA-659-1 libpam-radius-auth - information leak, integer underflow
449            {CAN-2004-1340 CAN-2005-0108}
450            - libpam-radius-auth 1.3.16-3
451            NOTE: 1/2 fixed in testing at time of DSA
452    [25 Jan 2005] DSA-658-1 libdbi-perl - insecure temporary file
453            {CAN-2005-0077}
454            - libdbi-perl 1.46-6
455            NOTE: not fixed in testing at time of DSA
456    [25 Jan 2005] DSA-657-1 xine-lib - buffer overflow
457            {CAN-2004-1379}
458            - xine-lib 1-rc6a-1
459            NOTE: fixed in testing at time of DSA
460    [25 Jan 2005] DSA-656-1 vdr - insecure file access
461            {CAN-2005-0071}
462            - vdr 1.2.6-6
463            NOTE: not fixed in testing at time of DSA
464    [25 Jan 2005] DSA-655-1 zhcon - missing privilege release
465            {CAN-2005-0072}
466            - zhcon 1:0.2.3-8.1
467            NOTE: not fixed in testing at time of DSA
468    [21 Jan 2005] DSA-654-1 enscript - several
469            {CAN-2004-1184 CAN-2004-1185 CAN-2004-1186}
470            - enscript 1.6.4-6
471            NOTE: not fixed in testing at time of DSA
472    [21 Jan 2005] DSA-653-1 ethereal - buffer overflow
473            {CAN-2005-0084}
474            - ethereal 0.10.9-1
475            NOTE: not fixed in testing at time of DSA
476    [21 Jan 2005] DSA-652-1 unarj
477            {CAN-2004-0947 CAN-2004-1027}
478            NOTE: not-for-us (unarj)
479    [20 Jan 2005] DSA-651-1 squid - buffer overflow, integer overflow
480            {CAN-2005-0094 CAN-2005-0095}
481            - squid 2.5.7-4
482            NOTE: not fixed in testing at time of DSA
483    [20 Jan 2005] DSA-650-1 sword - missing input sanitising
484            {CAN-2005-0015}
485            - sword 1.5.7-7
486            NOTE: not fixed in testing at time of DSA
487    [20 Jan 2005] DSA-649-1 xtrlock - buffer overflow
488            {CAN-2005-0079}
489            - xtrlock 2.0-9
490            NOTE: fixed in testing at time of DSA
491    [19 Jan 2005] DSA-648-1 xpdf - buffer overflow
492            {CAN-2005-0064}
493            - xpdf 3.00-12
494            NOTE: not fixed in testing at time of DSA
495    [19 Jan 2005] DSA-647-1 mysql - insecure temporary files
496            {CAN-2005-0004}
497            - mysql-dfsg 4.0.23-3
498            - mysql-dfsg-4.1 4.1.8a-6
499            NOTE: not fixed in testing at time of DSA
500    [19 Jan 2005] DSA-646-1 imagemagick - buffer overflow
501            {CAN-2005-0005}
502            - imagemagick 6.0.6.2-2
503            NOTE: not fixed in testing at time of DSA
504    [19 Jan 2005] DSA-645-1 cupsys - buffer overflow
505            {CAN-2005-0064}
506            NOTE: cupsys not affected in sarge, though other programs are vulnerable
507            NOTE: see CAN/list
508            NOTE: not fixed in testing at time of DSA
509    [18 Jan 2005] DSA-644-1 chbg - buffer overflow
510            {CAN-2004-1264}
511            - chbg 1.5-4
512            NOTE: fixed in testing at time of DSA
513    [18 Jan 2005] DSA-643-1 queue - buffer overflows
514            {CAN-2004-0555}
515            - queue 1.30.1-5
516            NOTE: not fixed in testing at time of DSA
517    [17 Jan 2005] DSA-642-1 gallery - several
518            {CAN-2004-1106}
519            - gallery 1.4.4-pl4-1
520            NOTE: fixed in testing at time of DSA
521    [17 Jan 2005] DSA-641-1 playmidi - buffer overflow
522            {CAN-2005-0020}
523            - playmidi 2.4debian-3
524            NOTE: not fixed in testing at time of DSA
525    [17 Jan 2005] DSA-640-1 gatos - buffer overflow
526            {CAN-2005-0016}
527            - gatos 0.0.5-15
528            NOTE: not fixed in testing at time of DSA
529    [14 Jan 2005] DSA-639-1 mc - several
530            {CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176}
531            NOTE: unstable not vulnerable according to DSA
532            NOTE: DSA was wrong..
533            - mc 1:4.6.0-4.6.1-pre3-1
534            NOTE: not fixed in testing at time of DSA
535    [13 Jan 2005] DSA-638-1 gopher - several
536            {CAN-2004-0560 CAN-2004-0561}
537            NOTE: not in sarge
538    [13 Jan 2005] DSA-637-1 exim-tls - buffer overflow
539            {CAN-2005-0021}
540            NOTE: not in sarge
541    [12 Jan 2005] DSA-636-1 glibc - insecure temporary files
542            {CAN-2004-0968}
543            - glibc 2.3.2.ds1-20
544            NOTE: fixed in testing at time of DSA
545    [12 Jan 2005] DSA-635-1 exim - buffer overflow
546            {CAN-2005-0021}
547            - exim4 4.34-10
548            NOTE: fixed in testing at time of DSA
549            - exim 3.36-13
550            NOTE: not fixed in testing at time of DSA
551    [11 Jan 2005] DSA-634-1 hylafax - weak hostname and username validation
552            {CAN-2004-1182}
553            - hylafax 4.2.1-1
554            NOTE: fixed in testing at time of DSA
555    [11 Jan 2005] DSA-633-1 bmv - insecure temporary file
556            {CAN-2003-0014}
557            - bmv 1.2-17
558            NOTE: fixed in testing at time of DSA
559    [10 Jan 2005] DSA-632-1 linpopup - buffer overflow
560            {CAN-2004-1282}
561            - linpopup 1.2.0-7
562            NOTE: fixed in testing at time of DSA
563    [10 Jan 2005] DSA-631-1 kdelibs - unsanitised input
564            {CAN-2004-1165}
565            - kdelibs 4:3.3.2-1
566            NOTE: not fixed in testing at time of DSA
567    [10 Jan 2005] DSA-630-1 lintian - insecure temporary directory
568            {CAN-2004-1000}
569            - lintian 1.23.6
570            NOTE: not fixed in testing at time of DSA
571    [07 Jan 2005] DSA-629-1 krb5 - buffer overflow
572            {CAN-2004-1189}
573            - krb5 1.3.6-1
574            NOTE: not fixed in testing at time of DSA
575    [06 Jan 2005] DSA-628-1 imlib2 - integer overflows
576            {CAN-2004-1026}
577            - imlib2 1.1.2-2.1
578            NOTE: not fixed in testing at time of DSA
579    [06 Jan 2005] DSA-627-1 namazu2 - unsanitised input
580            {CAN-2004-1318}
581            - namazu2 2.0.14-1
582            NOTE: not fixed in testing at time of DSA
583    [06 Jan 2005] DSA-626-1 tiff - unsanitised input
584            {CAN-2004-1183}
585            - libtiff4 3.6.1-5
586            NOTE: not fixed in testing at time of DSA
587    [05 Jan 2005] DSA-625-1 pcal - buffer overflows
588            {CAN-2004-1289}
589            - pcal 4.8.0-1
590            NOTE: not fixed in testing at time of DSA
591    [05 Jan 2005] DSA-624-1 zip - buffer overflow
592            {CAN-2004-1010}
593            - zip 2.30-8
594            NOTE: fixed in testing at time of DSA
595    [04 Jan 2005] DSA-623-1 nasm - buffer overflow
596            {CAN-2004-1287}
597            - nasm 0.98.38-1.1
598    [03 Jan 2005] DSA-622-1 htmlheadline - insecure temporary files
599            {CAN-2004-1181}
600            NOTE: not in unstable
601    [31 Dec 2004] DSA-621-1 cupsys - buffer overflow
602            {CAN-2004-1125}
603            - cupsys 1.1.22-2
604    [30 Dec 2004] DSA-620-1 perl - insecure temporary files / directories
605            {CAN-2004-0452 CAN-2004-0976}
606            - perl 5.8.4-5
607    [30 Dev 2004] DSA-619-1 xpdf - buffer overflow
608            {CAN-2004-1125}
609            - xpdf 3.00-11
610    [24 Dec 2004] DSA-618-1 imlib - buffer overflows, integer overflows
611            {CAN-2004-1025 CAN-2004-1026}
612            - imlib 1.9.14-17.1
613            - imlib-png2 1.9.14-16.1
614    [24 Dec 2004] DSA-617-1 libtiff - insufficient input validation
615            {CAN-2004-1308}
616            - libtiff4 3.6.1-4
617    [23 Dec 2004] DSA-616-1 telnetd-ssl - format string
618            {CAN-2004-0998}
619            - telnetd-ssl 0.17.24+0.1-6
620    [22 Dec 2004] DSA-615-1 debmake - insecure temporary file
621            {CAN-2004-1179}
622            - debmake 3.7.7
623    [21 Dec 2004] DSA-614-1 xzgv - integer overflows
624            {CAN-2004-0994}
625            - xzgv 0.8-3
626    [21 Dec 2004] DSA-613-1 ethereal - inifinite loop
627            {CAN-2004-114}
628            - ethereal 0.10.8-1
629    [21 Dec 2004] DSA-614-1 xzgv - integer overflows
630            {CAN-2004-0994}
631            - xzgv 0.8-3
632    [20 Dec 2004] DSA-612-1 a2ps - unsanitised input
633            {CAN-2004-1170}
634            - a2ps 4.13b-4.2
635    [20 Dec 2004] DSA-611-1 htget - buffer overflow
636            {CAN-2004-0852}
637            NOTE: htget not in sarge or unstable
638    [17 Dec 2004] DSA-610-1 cscope - insecure temporary file
639            {CAN-2004-0996}
640            - cscope 15.5-1
641    [14 Dec 2004] DSA-609-1 atari800 - buffer overflows
642            {CAN-2004-1076}
643            - atari800 1.3.2-1
644    [14 Dec 2004] DSA-608-1 zgv - integer overflows, unsanitised input
645            {CAN-2004-1095 CAN-2004-0999}
646            - zgv 5.7-1.3
647            NOTE: changelog says he only patched 1095, but diff comparison
648            NOTE: shows 0999 was also fixed.
649    [10 Dec 2004] DSA-607-1 xfree86 - several
650            {CAN-2004-0914}
651            - xfree86 4.3.0.dfsg.1-9
652    [08 Dec 2004] DSA-606-1 nfs-utils - wrong signal handler
653            {CAN-2004-1014}
654            - nfs-utils 1:1.0.6-3.1
655    [06 Dec 2004] DSA-605-1 viewcvs - settings not honored
656            {CAN-2004-0915}
657            - viewcvs 0.9.2+cvs.1.0.dev.2004.07.28-1.2
658    [03 Dec 2004] DSA-604-1 hpsockd - missing input sanitising
659            {CAN-2004-0993}
660            - hpsockd 0.14
661    [01 Dec 2004] DSA-603-1 openssl - insecure temporary file
662            {CAN-2004-0975}
663            - openssl 0.9.7e-3
664    [29 Nov 2004] DSA-602-1 libgd2 - integer overlow
665            {CAN-2004-0941 CAN-2004-0990}
666            NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
667            - libgd2 2.0.33-1.1
668    [29 Nov 2004] DSA-601-1 libgd1 - integer overflow
669            {CAN-2004-0941 CAN-2004-0990}
670            NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
671            - libgd 1.8.4-36.1
672    [25 Nov 2004] DSA-599-1 tetex-bin - integer overflows
673            {CAN-2004-0888}
674            - tetex-bin 2.0.2-23
675    [25 Nov 2004] DSA-598-1 yardradius - buffer overflow
676            {CAN-2004-0987}
677            - yardradius 1.0.20-15
678    [25 Nov 2004] DSA-597-1 cyrus-imapd - buffer overflow
679            {CAN-2004-1012 CAN-2004-1013}
680            - cyrus21-imapd 2.1.17-1
681    [24 Nov 2004] DSA-596-2 sudo - missing input sanitising
682            {CAN-2004-1051}
683            - sudo 1.6.8p3-1
684    [24 Nov 2004] DSA-596-1 sudo - missing input sanitising
685            {CAN-2004-1051}
686            - sudo 1.6.8p3-1
687    [24 Nov 2004] DSA-595-1 bnc - buffer overflow
688            {CAN-2004-1052}
689            NOTE: package not in sarge or sid
690    [17 Nov 2004] DSA-594-1 apache - buffer overflows
691            {CAN-2004-0940}
692            - apache 1.3.33-2
693    [16 Nov 2004] DSA-593-1 imagemagick - buffer overflow
694            {CAN-2004-0981}
695            - imagemagick 6:6.0.6.2-1.5
696    [12 Nov 2004] DSA-592-1 ez-ipupdate - format string
697            {CAN-2004-0980}
698            - ez-ipupdate 3.0.11b8-8
699    [09 Nov 2004] DSA-591-1 libgd2 - integer overflows
700            {CAN-2004-0990}
701            - libgd2 2.0.30-1
702    [09 Nov 2004] DSA-590-1 gnats - format string vulnerability
703            {CAN-2004-0623}
704            NOTE: DSA got version of fix for unstable wrong
705            - gnats 4.0-6.1
706    [09 Nov 2004] DSA-589-1 libgd - integer overflows
707            {CAN-2004-0990}
708            - libgd1 1.8.4-36.1
709    [08 Nov 2004] DSA-588-1 gzip - insecure temporary files
710            {CAN-2004-0970}
711            NOTE: dsa says sid not affected
712    [08 Nov 2004] DSA-587-1 freeamp - buffer overflow
713            {CAN-2004-0964}
714            NOTE: DSA says zinf not vulnerable in sarge
715    [08 Nov 2004] DSA-586-1 ruby - infinite loop
716            {CAN-2004-0983}
717            - ruby1.6 1.6.8-12
718            - ruby1.8 1.8.1+1.8.2pre2-4
719  [05 Nov 2004] DSA-585-1 shadow - programming error  [05 Nov 2004] DSA-585-1 shadow - programming error
720          {CAN-2004-1001}          {CAN-2004-1001}
721          - shadow 1:4.0.3-30.3          - shadow 1:4.0.3-30.3
# Line 6  Line 724 
724          - dhcp 2.0pl5-19.1          - dhcp 2.0pl5-19.1
725  [03 Nov 2004] DSA-583-1 lvm10 - insecure temporary directory  [03 Nov 2004] DSA-583-1 lvm10 - insecure temporary directory
726          {CAN-2004-0972}          {CAN-2004-0972}
         TODO: I thought this didn't really matter because the script  
         TODO: was not included in the binary package. Check or fix.  
727  [02 Nov 2004] DSA-582-1 libxml - buffer overflow  [02 Nov 2004] DSA-582-1 libxml - buffer overflow
728          {CAN-2004-0989}          {CAN-2004-0989}
729          - libxml 1.8.17-9          - libxml 1.8.17-9
# Line 40  Line 756 
756          {CAN-2004-0888}          {CAN-2004-0888}
757          - cupsys 1.1.20final+rc1-10          - cupsys 1.1.20final+rc1-10
758          {CAN-2004-0889}          {CAN-2004-0889}
759          - xpdf 3.00-9          - xpdf 3.00-10
760          - kpdf (unfixed; bug #278173)          NOTE: kpdf and kfax are fixed in sarge, bug #278173 and #280373 for reference
761            - kpdf 4:3.3.1-1
762          - gpdf 2.8.0-1          - gpdf 2.8.0-1
763            - kfax 4:3.3.1-1
764  [21 Oct 2004] DSA-572-1 ecartis - multiple  [21 Oct 2004] DSA-572-1 ecartis - multiple
765          {CAN-2004-0913}          {CAN-2004-0913}
766          - ecartis 1.0.0+cvs.20030911-8          - ecartis 1.0.0+cvs.20030911-8
# Line 125  Line 843 
843  [16 Sep 2004] DSA-548-1 imlib - unsanitised input  [16 Sep 2004] DSA-548-1 imlib - unsanitised input
844          {CAN-2004-0817}          {CAN-2004-0817}
845          - imlib 1.9.14-17          - imlib 1.9.14-17
846          - imlib+png2 1.9.14-16          - imlib+png2 1.9.14-16.2
847  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows
848          {CAN-2004-0827}          {CAN-2004-0827}
849          - imagemagic 6.0.6.2-1          - imagemagic 6.0.6.2-1
# Line 159  Line 877 
877          - kdelibs 4:3.2.3-3.sarge.1          - kdelibs 4:3.2.3-3.sarge.1
878  [17 Aug 2004] DSA-538 rsync - unauthorised directory traversal and file access  [17 Aug 2004] DSA-538 rsync - unauthorised directory traversal and file access
879          - rsync 2.6.2-3          - rsync 2.6.2-3
880  [16 Aug 2004] DSA-537 ruby -- insecure file permissions  [16 Aug 2004] DSA-537 ruby - insecure file permissions
881          {CAN-2004-0755}          {CAN-2004-0755}
882          - ruby1.8 1.8.1+1.8.2pre1-4          - ruby1.8 1.8.1+1.8.2pre1-4
883          HELP: is ruby1.6 vulnerable?          HELP: is ruby1.6 vulnerable?
# Line 244  Line 962 
962          {CAN-2004-0522}          {CAN-2004-0522}
963          - gallery 1.4.3-pl2-1          - gallery 1.4.3-pl2-1
964  [30 May 2004] DSA-511 ethereal - buffer overflows  [30 May 2004] DSA-511 ethereal - buffer overflows
965          {CAN-2004-0176          {CAN-2004-0176}
966          - ethereal 0.10.3-1          - ethereal 0.10.3-1
967  [29 May 2004] DSA-510 jftpgw - format string  [29 May 2004] DSA-510 jftpgw - format string
968          {CAN-2004-0448}          {CAN-2004-0448}
# Line 391  Line 1109 
1109          NOTE: CAN-2004-0081 only affects 0.9.6.          NOTE: CAN-2004-0081 only affects 0.9.6.
1110          NOTE: 0.9.7d also fixes CAN-2004-0112          NOTE: 0.9.7d also fixes CAN-2004-0112
1111          - openssl 0.9.6l          - openssl 0.9.6l
1112            - openssl096 0.9.6m-1
1113  [16 Mar 2004] DSA-464 gdk-pixbuf - broken image handling  [16 Mar 2004] DSA-464 gdk-pixbuf - broken image handling
1114          {CAN-2004-0111}          {CAN-2004-0111}
1115          - gdk-pixbuf 0.22.0-3          - gdk-pixbuf 0.22.0-3
# Line 413  Line 1132 
1132          {CAN-2004-0150}          {CAN-2004-0150}
1133          NOTE: not affected according to DSA          NOTE: not affected according to DSA
1134  [08 Mar 2004] DSA-457 wu-ftpd - several vulnerabilities  [08 Mar 2004] DSA-457 wu-ftpd - several vulnerabilities
1135          CAN-2004-0148 CAN-2004-0185}          {CAN-2004-0148 CAN-2004-0185}
1136          - wu-ftpd 2.6.2-17.1          - wu-ftpd 2.6.2-17.1
1137  [06 Mar 2004] DSA-456 linux-kernel-2.2.19-arm - failing function and TLB flush  [06 Mar 2004] DSA-456 linux-kernel-2.2.19-arm - failing function and TLB flush
1138          {CAN-2004-0077}          {CAN-2004-0077}
# Line 522  Line 1241 
1241          HELP: No idea if this is fixed, we have a new upstream version          HELP: No idea if this is fixed, we have a new upstream version
1242          HELP: that came out after these advisories, but neither the debian nor          HELP: that came out after these advisories, but neither the debian nor
1243          HELP: the upstream changelog seem to mention them.          HELP: the upstream changelog seem to mention them.
1244          NOTE: Mailed maintainr.          NOTE: Mailed maintainer.
1245  [16 Jan 2004] DSA-424 mc - buffer overflow  [16 Jan 2004] DSA-424 mc - buffer overflow
1246          {CAN-2003-1023}          {CAN-2003-1023}
1247          - mc 1:4.6.0-4.6.1-pre1-1          - mc 1:4.6.0-4.6.1-pre1-1
# Line 547  Line 1266 
1266          {CAN-2003-0961 CAN-2003-0985}          {CAN-2003-0961 CAN-2003-0985}
1267          NOTE: 2.4.18 not present. Did not check newer kernels.          NOTE: 2.4.18 not present. Did not check newer kernels.
1268  [06 Jan 2004] DSA-416 fsp - buffer overflow, directory traversal  [06 Jan 2004] DSA-416 fsp - buffer overflow, directory traversal
1269          {CAN-2003-1022, CAN-2004-0011}          {CAN-2003-1022 CAN-2004-0011}
1270          - fsp 2.81.b18-1          - fsp 2.81.b18-1
1271  [06 Jan 2004] DSA-415 zebra - denial of service  [06 Jan 2004] DSA-415 zebra - denial of service
1272          {CAN-2003-0795 CAN-2003-0858}          {CAN-2003-0795 CAN-2003-0858}
# Line 741  Line 1460 
1460          {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}          {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}
1461          NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.          NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.
1462  [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit  [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit
1463            {CAN-2003-0466}
1464          - wu-ftpd 2.6.2-12          - wu-ftpd 2.6.2-12
1465  [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows  [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows
1466          {CAN-2003-0611}          {CAN-2003-0611}
# Line 1325  Line 2045 
2045          {CAN-2002-0838}          {CAN-2002-0838}
2046          - gnome-gv 1.99.7-9          - gnome-gv 1.99.7-9
2047  [17 Oct 2002] DSA-178 heimdal - remote command execution  [17 Oct 2002] DSA-178 heimdal - remote command execution
2048          {CAN-2002-1225, CAN-2002-1226}          {CAN-2002-1225 CAN-2002-1226}
2049          - heimdal 0.4e-21          - heimdal 0.4e-21
2050  [17 Oct 2002] DSA-177 pam - serious security violation  [17 Oct 2002] DSA-177 pam - serious security violation
2051          {CAN-2002-1227}          {CAN-2002-1227}
# Line 1346  Line 2066 
2066          {CAN-2002-1193}          {CAN-2002-1193}
2067          NOTE: not in testing nor unstable (was fixed in 4.0beta9-9)          NOTE: not in testing nor unstable (was fixed in 4.0beta9-9)
2068  [07 Oct 2002] DSA-171 fetchmail - buffer overflows  [07 Oct 2002] DSA-171 fetchmail - buffer overflows
2069          {CAN-2002-1175, CAN-2002-1174}          {CAN-2002-1175 CAN-2002-1174}
2070          - fetchmail 6.1.0-1          - fetchmail 6.1.0-1
2071          NOTE: fetchmail-ssl not in testing, fixed in unstable (fetchmail-ssl 6.1.0-1)          NOTE: fetchmail-ssl not in testing, fixed in unstable (fetchmail-ssl 6.1.0-1)
2072  [04 Oct 2002] DSA-170 tomcat4 - source code disclosure  [04 Oct 2002] DSA-170 tomcat4 - source code disclosure

Legend:
Removed from v.84  
changed lines
  Added in v.1446

  ViewVC Help
Powered by ViewVC 1.1.5