/[secure-testing]/data/DSA/list
ViewVC logotype

Diff of /data/DSA/list

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

sarge-checks/DSA/list revision 84 by joeyh, Fri Nov 5 21:17:54 2004 UTC data/DSA/list revision 1922 by jmm-guest, Mon Sep 12 09:07:20 2005 UTC
# Line 1  Line 1 
1    [09 Sep 2005] DSA-806-1 gcvs - insecure temporary files
2            {CAN-2005-2693}
3            - gcvs 1.0final-7 (low)
4            NOTE: fixed in testing at time of DSA
5    [08 Sep 2005] DSA-805-1 apache2 - several
6            {CAN-2005-1268 CAN-2005-2088 CAN-2005-2700 CAN-2005-2728}
7            - apache2 2.0.54-5 (medium)
8            NOTE: not fixed in testing at time of DSA (too young)
9    [08 Sep 2005] DSA-804-1 kdelibs - insecure permissions
10            {CAN-2005-1920}
11            - kdebase 4:3.4.2-1 (medium)
12            NOTE: not fixed in testing at time of DSA (kde transition)
13    [07 Sep 2005] DSA-803-1 apache - programming error
14            {CAN-2005-2088}
15            - apache 1.3.33-8 (medium)
16            NOTE: not fixed in testing at time of DSA (too young)
17    [07 Sep 2005] DSA-802-1 cvs - insecure temporary files
18            {CAN-2005-2693}
19            - cvs 1:1.11.5-4 (low)
20            NOTE: fixed in testing at time of DSA
21    [05 Sep 2005] DSA-801-1 ntp - programming error
22            {CAN-2005-2496}
23            - ntp 1:4.2.0a+stable-4 (medium)
24            NOTE: not fixed in testing at time of DSA (RC bugs)
25    [02 Sep 2005] DSA-800-1 pcre3 - integer overflow
26            {CAN-2005-2491}
27            - pcre3 6.3-0.1etch1 (high)
28            NOTE: not fixed in testing at time of DSA (glibc transition)
29            NOTE: however, fixed in secure-testing archive
30    [02 Sep 2005] DSA-799-1 webcalendar - input validation
31            {CAN-2005-2717}
32            - webcalendar (unfixed; bug #326223; high)
33            NOTE: not fixed in testing at time of DSA (coordinated disclosure)
34    [02 Sep 2005] DSA-798-1 phpgroupware - several
35            {CAN-2005-2498 CAN-2005-2600 CAN-2005-2761}
36            - phpgroupware 0.9.16.008-1 (high)
37            NOTE: not fixed in testing at time of DSA (too young)
38    [01 Sep 2005] DSA-797-1 zsync - buffer overflow
39            {CAN-2005-1849 CAN-2005-2096}
40            - zsync 0.4.0-2 (medium)
41            NOTE: fixed in testing at time of DSA
42    [01 Sep 2005] DSA-796-1 affix - unsafe use of popen
43            {CAN-2005-2716}
44            - affix 2.1.2-3 (medium)
45            NOTE: not fixed in testing at time of DSA (glibc transition, builds)
46    [01 Sep 2005] DSA-795-2 proftpd - format string error
47            {CAN-2005-2390}
48            - proftpd 1.2.10-20 (medium)
49            NOTE: fixed in testing at time of DSA
50            NOTE: Initial -1 release had a build problem
51    [01 Sep 2005] DSA-794-1 polygen - programming error
52            {CAN-2005-2656}
53            - polygen 1.0.6-9 (low)
54            NOTE: not fixed in testing at time of DSA (too young)
55    [21 Aug 2005] DSA-779-2 mozilla-firefox - several
56            NOTE: Essentially 1.0.6 with rolled-back version number, backported version had regressions
57            {CAN-2005-2260 CAN-2005-2261 CAN-2005-2262 CAN-2005-2263 CAN-2005-2264 CAN-2005-2265 CAN-2005-2266 CAN-2005-2267 CAN-2005-2268 CAN-2005-2269 CAN-2005-2270}
58            - mozilla-firefox 1.0.6-1 (medium)
59            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
60            NOTE: Fixed in DTSA, which will have the same regressions, should be checked/reverted
61    [01 Sep 2005] DSA-793-1 courier - missing input sanitising
62            {CAN-2005-2724}
63            - courier 0.47-8 (medium)
64            NOTE: not fixed in testing at time of DSA (glibc transition, too young)
65    [31 Aug 2005] DSA-792-1 pstotext - missing input sanitising
66            {CAN-2005-2536}
67            - pstotext 1.9-2 (medium)
68            NOTE: not fixed in testing at time of DSA (glibc transition, builds)
69    [30 Aug 2005] DSA-791-1 maildrop - missing privilege release
70            {CAN-2005-2655}
71            - maildrop 1.5.3-1.1etch1 (medium)
72            NOTE: not fixed in testing at time of DSA (glibc transition)
73            NOTE: but fixed in secure-testing repo
74    [30 Aug 2005] DSA-790-1 phpldapadmin - programming error
75            {CAN-2005-2654}
76            - phpldapadmin 0.9.6c-5 (medium)
77            NOTE: fixed in testing at time of DSA
78    [29 Aug 2005] DSA-789-1 php4 - several
79            {CAN-2005-1751 CAN-2005-1921 CAN-2005-2498}
80            - php4 4:4.4.0-2 (high)
81            NOTE: not fixed in testing at time of DSA (not uploaded yet)
82    [29 Aug 2005] DSA-788-1 kismet - several
83            {CAN-2005-2626 CAN-2005-2627}
84            - kismet 2005.08.R1-1 (medium)
85            NOTE: not fixed in testing at time of DSA (glibc transition)
86            NOTE: but fixed in secure-testing repo
87    [26 Aug 2005] DSA-787-1 backup-manager - insecure permissions and tempfile
88            {CAN-2005-1855 CAN-2005-1856}
89            - backup-manager 0.5.8-2 (medium)
90            NOTE: fixed in testing at time of DSA
91    [26 Aug 2005] DSA-786-1 simpleproxy - format string vulnerability
92            {CAN-2005-1857}
93            - simpleproxy 3.2-4 (medium)
94            NOTE: not fixed in testing at time of DSA (embargoed disclosure)
95    [25 Aug 2005] DSA-785-1 libpam-ldap - authentication bypass
96            {CAN-2005-2641}
97            - libpam-ldap 178-1sarge1 (medium)
98            NOTE: not fixed in testing at time of DSA (embargoed disclosure)
99    [25 Aug 2005] DSA-784-1 courier - programming error
100            {CAN-2005-2151}
101            - courier 0.47-6 (low)
102            NOTE: not fixed in testing at time of DSA (glibc transition)
103    [24 Aug 2005] DSA-783-1 mysql-dfsg-4.1 - insecure temporary file
104            {CAN-2005-1636}
105            - mysql-dfsg-4.1 4.1.12 (medium)
106            NOTE: not fixed in testing at time of DSA (glibc transition)
107            - mysql-dfsg-5.0 5.0.11beta-3 (medium)
108            NOTE: not fixed in testing at time of DSA (glibc transition)
109    [23 Aug 2005] DSA-782-1 bluez-utils - missing input sanitising
110            {CAN-2005-2547}
111            - bluez-utils 2.19-1 (high)
112            NOTE: not fixed in testing at time of DSA (missing builds)
113    [23 Aug 2005] DSA-781-1 mozilla-thunderbird - several
114            {CAN-2005-0989 CAN-2005-1159 CAN-2005-1160 CAN-2005-1532 CAN-2005-2261 CAN-2005-2265 CAN-2005-2266 CAN-2005-2269 CAN-2005-2270}
115            - mozilla-thunderbird 1.0.6-1 (medium)
116            NOTE: not fixed in testing at time of DSA (missing builds)
117    [22 Aug 2005] DSA-780-1 kdegraphics - wrong input sanitising
118            {CAN-2005-2097}
119            - kdegraphics 4:3.4.2-1 (bug #322458; low)
120            NOTE: not fixed in testing at time of DSA (nor in unstable; C++ ABI transition)
121    [21 Aug 2005] DSA-779-1 mozilla-firefox - several
122            {CAN-2005-2260 CAN-2005-2261 CAN-2005-2262 CAN-2005-2263 CAN-2005-2264 CAN-2005-2265 CAN-2005-2266 CAN-2005-2267 CAN-2005-2268 CAN-2005-2269 CAN-2005-2270}
123            - mozilla-firefox 1.0.6-1 (medium)
124            NOTE: not fixed in testing at time of DSA (build and deps)
125    [19 Aug 2005] DSA-778-1 mantis - missing input sanitising
126            {CAN-2005-2556 CAN-2005-2557}
127            - mantis 0.19.2-4 (medium)
128            NOTE: not fixed in testing at time of DSA (nor unstable)
129    [17 Aug 2005] DSA-777-1 mozilla - frame injection spoofing
130            {CAN-2004-0718 CAN-2005-1937}
131            - mozilla-browser 1.7.10-1 (medium)
132            NOTE: not fixed in testing at time of DSA (waiting on builds)
133    [16 Aug 2005] DSA-776-1 clamav - integer overflows, infinite loop
134            {CAN-2005-2450}
135            - clamav 0.86.2-1 (medium)
136            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
137    [12 Aug 2005] DSA-775-1 mozilla-firefox - frame injection spoofing
138            {CAN-2004-0718 CAN-2005-1937}
139            - mozilla-firefox 1.0.4-3 (medium)
140            NOTE: IMO the information about the sid fix in the DSA is wrong, pinged security@
141            NOTE: fixed in testing at time of DSA
142    [12 Aug 2005] DSA-774-1 fetchmail - buffer overflow
143            {CAN-2005-2335}
144            - fetchmail 6.2.5-16 (medium)
145            NOTE: fixed in testing at time of DSA
146    [11 Aug 2005] DSA-773-1 New amd64 packages fix several bugs
147            NOTE: amd64 catch-up DSA, no new holes
148    [03 Aug 2005] DSA-772-1 apt-cacher - missing input sanitising
149            {CAN-2005-1854}
150            - apt-cacher 0.9.10 (high)
151            NOTE: not fixed in testing at time of DSA (not uploaded to unstable yet)
152    [01 Aug 2005] DSA-771-1 pdns - several
153            {CAN-2005-2301 CAN-2005-2302}
154            - pdns 2.9.18-1 (medium)
155            NOTE: not fixed in testing at time of DSA (too young)
156    [29 Jul 2005] DSA-770-1 gopher - insecure tmpfile handling
157            {CAN-2005-1853}
158            - gopher 3.0.10
159            NOTE: not fixed in testing at time of DSA (Debian server outage)
160    [29 Jul 2005] DSA-769-1 gaim - memory alignment bug
161            {CAN-2005-2370}
162            - gaim 1:1.4.0-5 (high)
163            NOTE: not fixed in testing at time of DSA (?)
164    [27 Jul 2005] DSA-768-1 phpbb2 - missing input validation
165            {CAN-2005-2161}
166            - phpbb2 2.0.13-6sarge1
167            NOTE: not fixed in testing at time of DSA (Debian server outage)
168    [27 Jul 2005] DSA-767-1 ekg - integer overflows
169            {CAN-2005-1852}
170            - ekg 1.5+20050718+1.6rc3-1 (medium)
171            NOTE: not fixed in testing at time of DSA (Debian server outage)
172    [26 Jul 2005] DSA-766-1 webcalendar - authorisation failure
173            {CAN-2005-2320}
174            - webcalendar (unfixed; bug #315671; medium)
175            NOTE: not fixed in testing at time of DSA (Debian server outage)
176    [22 Jul 2005] DSA-765-1 heimdal - buffer overflow
177            {CAN-2005-0469}
178            - heimdal 0.6.3-10 (medium)
179            NOTE: fixed in testing at time of DSA
180    [21 Jul 2005] DSA-764-1 cacti - several
181            {CAN-2005-1524 CAN-2005-1525 CAN-2005-1526 CAN-2005-2148 CAN-2005-2149}
182            - cacti 0.8.6f-1 (high)
183            NOTE: fixed in testing at time of DSA
184            NOTE: DSA information is incorrect, sid fix is 6f, not 6e
185    [20 Jul 2005] DSA-763-1 zlib - buffer overflow
186            {CAN-2005-1849}
187            - zlib 1.2.3-1 (medium)
188            NOTE: not fixed in testing at time of DSA (only 1/2 days old, not built on s390)
189    [19 Jul 2005] DSA-762-1 affix - several
190            {CAN-2005-2250 CAN-2005-2277}
191            - affix 2.1.2-2 (medium)
192            NOTE: not fixed in testing at time of DSA (only 2/2 days old)
193    [19 Jul 2005] DSA-761-2 heartbeat - insecure temporary files
194            {CAN-2005-2231}
195            - heartbeat 1.2.3-12 (medium)
196            NOTE: not fixed in testing at time of DSA (only 0/2 days old)
197    [18 Jul 2005] DSA-760-1 ekg - several
198            {CAN-2005-1850 CAN-2005-1851 CAN-2005-1916}
199            - ekg 1.5+20050712+1.6rc2-1 (low)
200            NOTE: not fixed in testing at time of DSA (waiting on dependencies, not built on five archs)
201    [18 Jul 2005] DSA-759-1 phppgadmin - missing input sanitising
202            {CAN-2005-2256}
203            - phppgadmin 3.5.4-1 (medium)
204            NOTE: not fixed in testing at time of DSA (only 0/10 days old)
205    [18 Jul 2005] DSA-758-1 heimdal - buffer overflow
206            {CAN-2005-2040}
207            - heimdal 0.6.3-11 (medium)
208            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
209    [17 Jul 2005] DSA-757-1 krb5 - buffer overflow, double-free memory
210            {CAN-2005-1689 CAN-2005-1174 CAN-2005-1175}
211            - krb5 1.3.6-4 (medium)
212            NOTE: not fixed in testing at time of DSA (waiting on dependencies, not built on m68k)
213    [14 Jul 2005] DSA-746-1 phpgroupware - remote command execution
214            {CAN-2005-1921}
215            - phpgroupware 0.9.16.006-1 (high)
216            NOTE: fixed in testing at time of DSA
217    [13 Jul 2005] DSA-756-1 squirrelmail - several
218            {CAN-2005-1769 CAN-2005-2095}
219            - squirrelmail 2:1.4.4-6 (medium)
220            NOTE: not fixed in testing at time of DSA (only 0/2 days old)
221    [13 Jul 2005] DSA-755-1 tiff - buffer overflow
222            {CAN-2005-1544}
223            - tiff 3.7.2-3 (medium)
224            NOTE: fixed in testing at time of DSA
225    [13 Jul 2005] DSA-754-1 centericq - insecure temporary file
226            {CAN-2005-1914}
227            - centericq 4.20.0-7 (low)
228            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
229    [12 Jul 2005] DSA-753-1 gedit - format string
230            {CAN-2005-1686}
231            - gedit 2.10.3-1 (low)
232            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
233    [11 Jul 2005] DSA-752-1 gzip - several
234            {CAN-2005-0988 CAN-2005-1228}
235            - gzip 1.3.5-10
236            NOTE: fixed in testing at time of DSA
237    [11 Jul 2005] DSA-751-1 squid - IP spoofind
238            {CAN-2005-1519}
239            - squid 2.5.9-9
240            NOTE: fixed in testing at time of DSA
241    [10 Jul 2005] DSA-748-1 ruby1.8 - bad default value
242            {CAN-2005-1992}
243            - ruby1.8 1.8.2-8 (medium)
244            NOTE: not fixed in testing at time of DSA (waiting on dependencies)
245    [11 Jul 2005] DSA-750-1 dhcpcd - out-of-bound memory access
246            {CAN-2005-1848}
247            - dhcpcd 1.3.22pl4-22
248            NOTE: fixed in testing at time of DSA
249    [10 Jul 2005] DSA-749-1 ettercap - format string error
250            {CAN-2005-1796}
251            - ettercap 0.7.3-1 (medium)
252            NOTE: fixed in testing at time of DSA
253    [10 Jul 2005] DSA-747-1 egroupware - input validation error
254            {CAN-2005-1921}
255            - egroupware 1.0.0.007-3.dfsg-1 (high)
256            NOTE: not fixed in testing at time of DSA (only 1/2 days old)
257    [10 Jul 2005] DSA-745-1 drupal - arbitrary command execution
258            {CAN-2005-1921 CAN-2005-2106 CAN-2005-2116}
259            - drupal 4.5.4-1 (high)
260            NOTE: fixed in testing at time of DSA
261    [08 Jul 2005] DSA-744-1 fuse - programming error
262            {CAN-2005-1858}
263            - fuse 2.3.0-1
264            NOTE: fixed in testing at time of DSA
265    [08 Jul 2005] DSA-743-1 ht - buffer overflows, integer overflows
266            {CAN-2005-1545 CAN-2005-1546}
267            - ht 0.8.0-3
268            NOTE: fixed in testing at time of DSA
269    [09 Jul 2005] DSA-742-1 cvs - buffer overflow
270            {CAN-2005-0753}
271            - cvs 1:1.12.9-13 (high)
272            NOTE: fixed in testing at time of DSA
273    [07 Jul 2005] DSA-741-1 bzip2 - infinite loop
274            {CAN-2005-1260}
275            - bzip2 1.0.2-7 (low)
276            NOTE: fixed in testing at time of DSA
277    [06 Jul 2005] DSA-740-1 zlib - buffer overflow
278            {CAN-2005-2096}
279            - zlib 1.2.2-7 (medium)
280            NOTE: anything statically linking zlib needs rebuild
281            NOTE: not fixed in testing at time of DSA (embargoed disclosure)
282    [06 Jul 2005] DSA-739-1 trac - missing input sanitising
283            {CAN-2005-2007}
284            - trac 0.8.4-1 (medium)
285            NOTE: fixed in testing at time of DSA
286    [19 May 2005] DSA-725-2 ppxp - missing privilege release
287            {CAN-2005-0392}
288            - ppxp 0.2001080415-11
289            NOTE: fixed in testing at time of DSA
290    [05 Jul 2005] DSA-738-1 razor - email header parsing error
291            {CAN-2005-2024}
292            - razor 2.720-1 (low)
293            NOTE: not fixed in testing at time of DSA (not built on arm)
294    [05 Jul 2005] DSA-737-1 clamav - various DOS vulnerabilities
295            {CAN-2005-1922 CAN-2005-1923 CAN-2005-2056 CAN-2005-2070}
296            - clamav 0.86.1-1 (medium)
297            NOTE: not fixed in testing at time of DSA (uploaded with low urgency only, one fix missing for sid)
298    [05 Jul 2005] DSA-734-1 gaim - denial of service
299            {CAN-2005-1269 CAN-2005-1934}
300            - gaim 1.3.1-1
301            NOTE: not fixed in testing at time of DSA (not built on sparc)
302    [01 Jul 2005] DSA-736-2 spamassassin - mail header parsing error
303            {CAN-2005-1266}
304            - spamassassin 3.0.4-1 (medium)
305            NOTE: fixed in testing at time of DSA
306    [01 Jul 2005] DSA-736-1 spamassassin - mail header parsing error
307            {CAN-2005-1266}
308            - spamassassin 3.0.4-1 (medium)
309            NOTE: fixed in testing at time of DSA
310    [08 Jul 2005] DSA-735-2 sudo - pathname validation race
311            {CAN-2005-1993}
312            - sudo 1.6.8p9-1 (medium)
313            NOTE: fixed in testing at time of DSA
314    [01 Jul 2005] DSA-735-2 sudo - pathname validation race
315            {CAN-2005-1993}
316            - sudo 1.6.8p9-1 (medium)
317            NOTE: fixed in testing at time of DSA
318    [01 Jul 2005] DSA-735-1 sudo - pathname validation race
319            {CAN-2005-1993}
320            - sudo 1.6.8p9-1 (medium)
321            NOTE: not fixed in testing at time of DSA
322    [30 Jun 2005] DSA-733-1 crip - insecure temporary files
323            {CAN-2005-0393}
324            - crip 3.5-1sarge2 (low)
325            NOTE: not fixed in testing at time of DSA (reserved)
326    [03 Jun 2005] DSA-732-1 mailutils - several
327            {CAN-2005-1520 CAN-2005-1521 CAN-2005-1522 CAN-2005-1523}
328            - mailutils 0.6.1-4
329            NOTE: fixed in testing at time of DSA
330    [02 Jun 2005] DSA-731-1 krb4 - buffer overflows
331            {CAN-2005-0468 CAN-2005-0468}
332            - krb4 1.2.2-11.2
333            NOTE: fixed in testing at time of DSA
334    [27 May 2005] DSA-730-1 bzip2 - race condition
335            {CAN-2005-0953}
336            - bzip2 1.0.2-6
337            NOTE: fixed in testing at time of DSA
338    [26 May 2005] DSA-729-1 php4 - missing input sanitising
339            {CAN-2005-0525}
340            - php4 4.3.10-10
341            NOTE: fixed in testing at time of DSA
342    [25 May 2005] DSA-728-1 qpopper - missing privilege release
343            {CAN-2005-1151 CAN-2005-1152}
344            - qpopper 4.0.5-4sarge1
345            NOTE: fixed in testing at time of DSA by security team
346    [20 May 2005] DSA-727-1 libconvert-uulib-perl - buffer overflow
347            {CAN-2005-1349}
348            - libconvert-uulib-perl 1.0.5.1-1
349            NOTE: fixed in testing at time of DSA
350    [20 May 2005] DSA-726-1 oops - format string vulnerability
351            {CAN-2005-1121}
352            - oops (unfixed; bug #307360)
353            NOTE: not in testing at time of DSA
354    [19 May 2005] DSA-725-1 ppxp - missing privilege release
355            {CAN-2005-0392}
356            - ppxp 0.2001080415-11
357            NOTE: not fixed in testing at time of DSA
358    [18 May 2005] DSA-724-1 phpsysinfo - design flaw
359            {CAN-2005-0870}
360            - phpsysinfo 2.3-3
361            NOTE: fixed in testing at time of DSA
362    [09 May 2005] DSA-723-1 xfree86 - buffer overflow
363            {CAN-2005-0605}
364            - xfree86 4.3.0.dfsg.1-13
365            NOTE: not fixed in testing at time of DSA
366    [09 May 2005] DSA-722-1 smail - buffer overflow
367            {CAN-2005-0892}
368            NOTE: Package not in testing at time of DSA
369    [06 May 2005] DSA-721-1 squid - design flaw
370            {CAN-2005-1345}
371            - squid 2.5.9-7
372            NOTE: not fixed in testing at time of DSA
373    [03 May 2005] DSA-720-1 smartlist - wrong input processing
374            {CAN-2005-0157}
375            - smartlist 3.15-18
376            NOTE: fixed in testing at time of DSA
377    [28 Apr 2005] DSA-719-1 prozilla - format string problems
378            {CAN-2005-0523}
379            - prozilla 1:1.3.7.4-1
380            NOTE: fixed in testing at time of DSA
381    [28 Apr 2005] DSA-718-1 ethereal - buffer overflow
382            {CAN-2005-0739}
383            - ethereal 0.10.10-1
384            NOTE: fixed in testing at time of DSA
385    [27 Apr 2005] DSA-717-1 lsh-utils - buffer overflow, typo
386            {CAN-2003-0826 CAN-2005-0814}
387            - lsh-utils 2.0.1-2
388            NOTE: fixed in testing at time of DSA
389    [27 Apr 2005] DSA-716-1 gaim - denial of service
390            {CAN-2005-0472}
391            - gaim 1.1.3-1
392            NOTE: fixed in testing at time of DSA
393    [27 Apr 2005] DSA-715-1 cvs - several
394            {CAN-2004-1342 CAN-2004-1343}
395            - cvs 1.12.9-12
396            NOTE: not fixed in testing at time of DSA
397    [26 Apr 2005] DSA-714-1 kdelibs - several
398            {CAN-2005-1046}
399            - kdelibs 4:3.3.2-5
400            NOTE: not fixed in testing at time of DSA
401    [21 Apr 2005] DSA-701-2 samba - integer overflows
402            NOTE: only a bug in the backported fix to stable, testing is ok
403    [21 Apr 2005] DSA-713-1 junkbuster - several
404            {CAN-2005-1108 CAN-2005-1109}
405            NOTE: package not in testing/unstable
406    [19 Apr 2005] DSA-712-1 geneweb - insecure file operations
407            {CAN-2005-0391}
408            - geneweb 4.10-7
409            NOTE: fixed in testing at time of DSA
410    [19 Apr 2005] DSA-711-1 info2www - missing input sanitising
411            {CAN-2004-1341}
412            - info2www 1.2.2.9-23
413            NOTE: fixed in testing at time of DSA
414    [18 Apr 2005] DSA-710-1 gtkhtml - null pointer dereference
415            {CAN-2003-0541}
416            - gtkhtml 1.0.4-6.2
417            NOTE: fixed in testing at time of DSA
418    [15 Apr 2005] DSA-709-1 libexif - buffer overflow
419            {CAN-2005-0664}
420            - libexif 0.6.9-5
421    [15 Apr 2005] DSA-708-1 php3 - missing input sanitising
422            {CAN-2005-0525}
423            - php3 3.0.18-31
424    [13 Apr 2005] DSA-707-1 mysql - several
425            {CAN-2004-0957 CAN-2005-0709 CAN-2005-0710 CAN-2005-0711}
426            - mysql-dfsg 4.0.24-5
427            - mysql-dfsg-4.1 4.1.10a-6
428            NOTE: not fixed in testing at time of DSA
429    [13 Apr 2005] DSA-706-1 axel - buffer overflow
430            {CAN-2005-0390}
431            - axel 1.0b-1
432            NOTE: fixed in testing at time of DSA
433    [04 Apr 2005] DSA-705-1 wu-ftpd - missing input sanitising
434            {CAN-2005-0256 CAN-2003-0854}
435            - wu-ftpd 2.6.2-19
436    [04 Apr 2005] DSA-704-1 remstats - tempfile, missing input sanitising
437            {CAN-2005-0387 CAN-2005-0388}
438            - remstats 1.0.13a-5
439            NOTE: not fixed in testing at time of DSA
440    [01 Apr 2005] DSA-703-1 krb5 - buffer overflows
441            {CAN-2005-0468 CAN-2005-0469}
442            - krb5 1.3.6-1
443    [01 Apr 2005] DSA-702-1 imagemagick - several
444            {CAN-2005-0397 CAN-2005-0759 CAN-2005-0760 CAN-2005-0762}
445            - imagemagick 6.0.6.2-2.2
446    [31 Mar 2005] DSA-701-1 samba - integer overflows
447            {CAN-2004-1154}
448            - samba 3.0.10-1
449    [30 Mar 2005] DSA-700-1 mailreader - missing input sanitising
450            {CAN-2005-0386}
451            - mailreader 2.3.29-11
452            NOTE: not fixed in testing at time of DSA
453    [29 Mar 2005] DSA-699-1 netkit-telnet-ssl - buffer overflow
454            {CAN-2005-0469}
455            - netkit-telnet-ssl 0.17.24+0.1-7.1
456            NOTE: not fixed in testing at time of DSA
457    [29 Mar 2005] DSA-698-1 mc - buffer overflow
458            {CAN-2005-0763}
459            NOTE: Not clear which unstable/testing version fixed this,
460            NOTE: but advisory says it's fixed.
461    [29 Mar 2005] DSA-697-1 netkit-telnet - buffer overflow
462            {CAN-2005-0469}
463            - netkit-telnet 0.17-28
464            NOTE: not fixed in testing at time of DSA
465    [22 Mar 2005] DSA-696-1 perl - design flaw
466            {CAN-2005-0448}
467            - perl 5.8.4-8
468            NOTE: fixed in testing at time of DSA
469    [21 Mar 2005] DSA-695-1 xli - buffer overflow, input sanitising, integer overflow
470            {CAN-2001-0775 CAN-2005-0638 CAN-2005-0639}
471            - xli 1.17.0-18
472            NOTE: not fixed in testing at time of DSA
473    [21 Mar 2005] DSA-694-1 xloadimage - missing input sanitising, integer overflow
474            {CAN-2005-0638 CAN-2005-0639}
475            - xloadimage 4.1-14.2
476            NOTE: not fixed in testing at time of DSA
477    [14 Mar 2005] DSA-693-1 luxman - buffer overflow
478            {CAN-2005-0385}
479            NOTE: not fixed in testing at time of DSA
480            NOTE: not in unstable at time of DSA though DSA claimed it was
481            - luxman 0.41-20
482    [14 Mar 2005] DSA-662-2 squirrelmail - several
483            NOTE: only an update to a prior DSA, did not affct sid/sarge.
484    [08 Mar 2005] DSA-692-1 kppp - design flaw
485            {CAN-2005-0205}
486            - kppp 4:3.1.6
487            NOTE: fixed in testing at time of DSA
488    [07 Mar 2005] DSA-691-1 abuse - several
489            {CAN-2005-0098 CAN-2005-0099}
490            NOTE: not in unstable/testing
491    [25 Feb 2005] DSA-690-1 bsmtpd - missing input sanitising
492            {CAN-2005-0107}
493            - bsmtpd 2.3pl8b-16
494            NOTE: not fixed in testing at time of DSA
495    [23 Feb 2005] DSA-689-1 libapache-mod-python - missing input sanitising
496            {CAN-2005-0088}
497            - libapache-mod-python 2.7.10-4
498            NOTE: fixed in testing at time of DSA
499            - libapache2-mod-python 3.1.3-3
500            NOTE: fixed in testing at time of DSA
501    [23 Feb 2005] DSA-688-1 squid - mising input sanitising
502            {CAN-2005-0446}
503            - squid 2.5.8-3
504            NOTE: fixed in testing at time of DSA
505    [21 Feb 2005] DSA-674-3 mailman - cross-site scripting, directory traversal
506            NOTE: only fixed bug in DSA
507    [18 Feb 2005] DSA-687-1 bidwatcher - format string
508            {CAN-2005-0158}
509            - bidwatcher 1.3.17-1
510            NOTE: not fixed in testing at time of DSA
511    [17 Feb 2005] DSA-686-1 gftp - missing input sanitising
512            {CAN-2005-0372}
513            - gftp 2.0.18-1
514            NOTE: not fixed in testing at time of DSA
515    [17 Feb 2005] DSA-685-1 emacs21 - format string
516            {CAN-2005-0100}
517            - emacs21 21.3+1-9
518            NOTE: not fixed in testing at time of DSA
519    [16 Feb 2005] DSA-684-1 typespeed - format string
520            {CAN-2005-0105}
521            - typespeed 0.4.4-8
522            NOTE: not fixed in testing at time of DSA
523    [15 Feb 2005] DSA-683-1 postgresql - buffer overflows
524            {CAN-2005-0245 CAN-2005-0247}
525            - postgresql 7.4.7-2
526            NOTE: fixed in testing at time of DSA
527    [15 Feb 2005] DSA-682-1 awstats - missing input sanitising
528            {CAN-2005-0363}
529            - awstats 6.2-1.2
530            NOTE: not fixed in testing at time of DSA
531    [14 Feb 2005] DSA-681-1 synaesthesia - privilege escalation
532            {CAN-2005-0070}
533            NOTE: does not apply for sarge, program is not setuid anymore
534    [14 Feb 2005] DSA-680-1 htdig - unsanitised input
535            {CAN-2005-0085}
536            - htdig 3.1.6-11
537            NOTE: fixed in testing at time of DSA
538    [14 Feb 2005] DSA-679-1 toolchain-source - insecure temporary files
539            {CAN-2005-0159}
540            - toolchain-source 3.4-5
541            NOTE: not fixed in testing at time of DSA
542    [11 Feb 2005] DSA-678-1 netkit-rwho - missing input validation
543            {CAN-2004-1180}
544            - netkit-rwho 0.17-8
545            NOTE: not fixed in testing at time of DSA
546    [11 Feb 2005] DSA-677-1 sympa - buffer overflow
547            {CAN-2005-0073}
548            - sympa 4.1.2-2.1
549            NOTE: not fixed in testing at time of DSA
550    [11 Feb 2005] DSA-676-1 xpcd - buffer overflow
551            {CAN-2005-0074}
552            - xpcd 2.08-11.1
553            NOTE: not fixed in testing at time of DSA
554    [11 Feb 2005] DSA-674-2 mailman - cross-site scripting, directory traversal
555            NOTE: only fixed bug in DSA
556    [10 Feb 2005] DSA-675-1 hztty - privilege escalation
557            {CAN-2005-0019}
558            - hztty 2.0-6.1
559            NOTE: not fixed in testing at time of DSA
560    [10 Feb 2005] DSA-674-1 mailman - cross-site scripting, directory traversal
561            {CAN-2004-1177}
562            - mailman 2.1.5-5
563            NOTE: fixed in testing at time of DSA
564            {CAN-2005-0202}
565            - mailman 2.1.5-6
566            NOTE: not fixed in testing at time of DSA
567    [10 Feb 2005] DSA-673-1 evolution - integer overflow
568            {CAN-2005-0102}
569            - evolution 2.0.3-1.2
570            NOTE: fixed in testing at time of DSA
571    [09 Feb 2005] DSA-672-1 xview - buffer overflows
572            {CAN-2005-0076}
573            - xview 3.2p1.4-19
574            NOTE: not fixed in testing at time of DSA
575    [08 Feb 2005] DSA-671-1 xemacs21 - format string
576            {CAN-2005-0100}
577            NOTE: not fixed in testing at time of DSA
578            - xemacs21 21.4.16-2
579    [08 Feb 2005] DSA-670-1 emacs20 - format string
580            {CAN-2005-0100}
581            NOTE: also affects emacs21 in unstable, fixed
582    [04 Feb 2005] DSA-689-1 php3 - several
583            {CAN-2004-0594 CAN-2004-0595}
584            - php3 3.0.18-27
585            NOTE: fixed in testing at time of DSA
586    [04 Feb 2005] DSA-668-1 postgresql - privilege escalation
587            {CAN-2005-0227}
588            - postgresql 7.4.7-1
589            NOTE: not fixed in testing at time of DSA
590    [04 Feb 2005] DSA-667-1 squid - several
591            {CAN-2005-0173 CAN-2005-0175 CAN-2005-0194 CAN-2005-0211}
592            - squid 2.5.7-7
593            NOTE: not fixed in testing at time of DSA
594    [04 Feb 2005] DSA-666-1 python2.2 - design flaw
595            {CAN-2005-0089}
596            - python2.2 2.2.3-14
597            - python2.3 2.3.4-20
598            - python2.4 2.4-5
599            NOTE: not fixed in testing at time of DSA
600    [04 Feb 2005] DSA-665-1 ncpfs - missing privilege release
601            {CAN-2005-0013}
602            - ncpfs 2.2.6-1
603            NOTE: not fixed in testing at time of DSA
604    [02 Feb 2005] DSA-664-1 cpio - broken file permissions
605            {CAN-1999-1572}
606            - cpio 2.5-1.2
607            NOTE: not fixed in testing at time of DSA
608    [02 Feb 2005] DSA-663-1 prozilla - buffer overflows
609            {CAN-2004-1120}
610            - prozilla 1.3.7.3-1
611            NOTE: fixed in testing at time of DSA
612    [01 Feb 2005] DSA-662-1 squirrelmail - several
613            {CAN-2005-0104 CAN-2005-0152}
614            NOTE: CAN-2005-0152 only exists in 1.2.6 version
615            - squirrelmail 1.4.4
616            NOTE: fixed in testing at time of DSA
617    [20 Apr 2005] DSA-661-2 f2c - insecure temporary files
618            {CAN-2005-0017 CAN-2005-0018}
619            - f2c 20020621-3.3
620            NOTE: not fixed in testing at time of DSA
621    [26 Jan 2005] DSA-660-1 kdebase - missing return value check
622            {CAN-2005-0078}
623            - kdebase 4:3.0.5
624            NOTE: fixed in testing at time of DSA
625    [26 Jan 2005] DSA-659-1 libpam-radius-auth - information leak, integer underflow
626            {CAN-2004-1340 CAN-2005-0108}
627            - libpam-radius-auth 1.3.16-3
628            NOTE: 1/2 fixed in testing at time of DSA
629    [25 Jan 2005] DSA-658-1 libdbi-perl - insecure temporary file
630            {CAN-2005-0077}
631            - libdbi-perl 1.46-6
632            NOTE: not fixed in testing at time of DSA
633    [25 Jan 2005] DSA-657-1 xine-lib - buffer overflow
634            {CAN-2004-1379}
635            - xine-lib 1-rc6a-1
636            NOTE: fixed in testing at time of DSA
637    [25 Jan 2005] DSA-656-1 vdr - insecure file access
638            {CAN-2005-0071}
639            - vdr 1.2.6-6
640            NOTE: not fixed in testing at time of DSA
641    [25 Jan 2005] DSA-655-1 zhcon - missing privilege release
642            {CAN-2005-0072}
643            - zhcon 1:0.2.3-8.1
644            NOTE: not fixed in testing at time of DSA
645    [21 Jan 2005] DSA-654-1 enscript - several
646            {CAN-2004-1184 CAN-2004-1185 CAN-2004-1186}
647            - enscript 1.6.4-6
648            NOTE: not fixed in testing at time of DSA
649    [21 Jan 2005] DSA-653-1 ethereal - buffer overflow
650            {CAN-2005-0084}
651            - ethereal 0.10.9-1
652            NOTE: not fixed in testing at time of DSA
653    [21 Jan 2005] DSA-652-1 unarj
654            {CAN-2004-0947 CAN-2004-1027}
655            NOTE: not-for-us (unarj)
656    [20 Jan 2005] DSA-651-1 squid - buffer overflow, integer overflow
657            {CAN-2005-0094 CAN-2005-0095}
658            - squid 2.5.7-4
659            NOTE: not fixed in testing at time of DSA
660    [20 Jan 2005] DSA-650-1 sword - missing input sanitising
661            {CAN-2005-0015}
662            - sword 1.5.7-7
663            NOTE: not fixed in testing at time of DSA
664    [20 Jan 2005] DSA-649-1 xtrlock - buffer overflow
665            {CAN-2005-0079}
666            - xtrlock 2.0-9
667            NOTE: fixed in testing at time of DSA
668    [19 Jan 2005] DSA-648-1 xpdf - buffer overflow
669            {CAN-2005-0064}
670            - xpdf 3.00-12
671            NOTE: not fixed in testing at time of DSA
672    [19 Jan 2005] DSA-647-1 mysql - insecure temporary files
673            {CAN-2005-0004}
674            - mysql-dfsg 4.0.23-3
675            - mysql-dfsg-4.1 4.1.8a-6
676            NOTE: not fixed in testing at time of DSA
677    [19 Jan 2005] DSA-646-1 imagemagick - buffer overflow
678            {CAN-2005-0005}
679            - imagemagick 6.0.6.2-2
680            NOTE: not fixed in testing at time of DSA
681    [19 Jan 2005] DSA-645-1 cupsys - buffer overflow
682            {CAN-2005-0064}
683            NOTE: cupsys not affected in sarge, though other programs are vulnerable
684            NOTE: see CAN/list
685            NOTE: not fixed in testing at time of DSA
686    [18 Jan 2005] DSA-644-1 chbg - buffer overflow
687            {CAN-2004-1264}
688            - chbg 1.5-4
689            NOTE: fixed in testing at time of DSA
690    [18 Jan 2005] DSA-643-1 queue - buffer overflows
691            {CAN-2004-0555}
692            - queue 1.30.1-5
693            NOTE: not fixed in testing at time of DSA
694    [17 Jan 2005] DSA-642-1 gallery - several
695            {CAN-2004-1106}
696            - gallery 1.4.4-pl4-1
697            NOTE: fixed in testing at time of DSA
698    [17 Jan 2005] DSA-641-1 playmidi - buffer overflow
699            {CAN-2005-0020}
700            - playmidi 2.4debian-3
701            NOTE: not fixed in testing at time of DSA
702    [17 Jan 2005] DSA-640-1 gatos - buffer overflow
703            {CAN-2005-0016}
704            - gatos 0.0.5-15
705            NOTE: not fixed in testing at time of DSA
706    [14 Jan 2005] DSA-639-1 mc - several
707            {CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176}
708            NOTE: unstable not vulnerable according to DSA
709            NOTE: DSA was wrong..
710            - mc 1:4.6.0-4.6.1-pre3-1
711            NOTE: not fixed in testing at time of DSA
712    [13 Jan 2005] DSA-638-1 gopher - several
713            {CAN-2004-0560 CAN-2004-0561}
714            NOTE: not in sarge
715    [13 Jan 2005] DSA-637-1 exim-tls - buffer overflow
716            {CAN-2005-0021}
717            NOTE: not in sarge
718    [12 Jan 2005] DSA-636-1 glibc - insecure temporary files
719            {CAN-2004-0968}
720            - glibc 2.3.2.ds1-20
721            NOTE: fixed in testing at time of DSA
722    [12 Jan 2005] DSA-635-1 exim - buffer overflow
723            {CAN-2005-0021}
724            - exim4 4.34-10
725            NOTE: fixed in testing at time of DSA
726            - exim 3.36-13
727            NOTE: not fixed in testing at time of DSA
728    [11 Jan 2005] DSA-634-1 hylafax - weak hostname and username validation
729            {CAN-2004-1182}
730            - hylafax 4.2.1-1
731            NOTE: fixed in testing at time of DSA
732    [11 Jan 2005] DSA-633-1 bmv - insecure temporary file
733            {CAN-2003-0014}
734            - bmv 1.2-17
735            NOTE: fixed in testing at time of DSA
736    [10 Jan 2005] DSA-632-1 linpopup - buffer overflow
737            {CAN-2004-1282}
738            - linpopup 1.2.0-7
739            NOTE: fixed in testing at time of DSA
740    [10 Jan 2005] DSA-631-1 kdelibs - unsanitised input
741            {CAN-2004-1165}
742            - kdelibs 4:3.3.2-1
743            NOTE: not fixed in testing at time of DSA
744    [10 Jan 2005] DSA-630-1 lintian - insecure temporary directory
745            {CAN-2004-1000}
746            - lintian 1.23.6
747            NOTE: not fixed in testing at time of DSA
748    [07 Jan 2005] DSA-629-1 krb5 - buffer overflow
749            {CAN-2004-1189}
750            - krb5 1.3.6-1
751            NOTE: not fixed in testing at time of DSA
752    [06 Jan 2005] DSA-628-1 imlib2 - integer overflows
753            {CAN-2004-1026}
754            - imlib2 1.1.2-2.1
755            NOTE: not fixed in testing at time of DSA
756    [06 Jan 2005] DSA-627-1 namazu2 - unsanitised input
757            {CAN-2004-1318}
758            - namazu2 2.0.14-1
759            NOTE: not fixed in testing at time of DSA
760    [06 Jan 2005] DSA-626-1 tiff - unsanitised input
761            {CAN-2004-1183}
762            - libtiff4 3.6.1-5
763            NOTE: not fixed in testing at time of DSA
764    [05 Jan 2005] DSA-625-1 pcal - buffer overflows
765            {CAN-2004-1289}
766            - pcal 4.8.0-1
767            NOTE: not fixed in testing at time of DSA
768    [05 Jan 2005] DSA-624-1 zip - buffer overflow
769            {CAN-2004-1010}
770            - zip 2.30-8
771            NOTE: fixed in testing at time of DSA
772    [04 Jan 2005] DSA-623-1 nasm - buffer overflow
773            {CAN-2004-1287}
774            - nasm 0.98.38-1.1
775    [03 Jan 2005] DSA-622-1 htmlheadline - insecure temporary files
776            {CAN-2004-1181}
777            NOTE: not in unstable
778    [31 Dec 2004] DSA-621-1 cupsys - buffer overflow
779            {CAN-2004-1125}
780            - cupsys 1.1.22-2
781    [30 Dec 2004] DSA-620-1 perl - insecure temporary files / directories
782            {CAN-2004-0452 CAN-2004-0976}
783            - perl 5.8.4-5
784    [30 Dev 2004] DSA-619-1 xpdf - buffer overflow
785            {CAN-2004-1125}
786            - xpdf 3.00-11
787    [24 Dec 2004] DSA-618-1 imlib - buffer overflows, integer overflows
788            {CAN-2004-1025 CAN-2004-1026}
789            - imlib 1.9.14-17.1
790            - imlib-png2 1.9.14-16.1
791    [24 Dec 2004] DSA-617-1 libtiff - insufficient input validation
792            {CAN-2004-1308}
793            - libtiff4 3.6.1-4
794    [23 Dec 2004] DSA-616-1 telnetd-ssl - format string
795            {CAN-2004-0998}
796            - telnetd-ssl 0.17.24+0.1-6
797    [22 Dec 2004] DSA-615-1 debmake - insecure temporary file
798            {CAN-2004-1179}
799            - debmake 3.7.7
800    [21 Dec 2004] DSA-614-1 xzgv - integer overflows
801            {CAN-2004-0994}
802            - xzgv 0.8-3
803    [21 Dec 2004] DSA-613-1 ethereal - inifinite loop
804            {CAN-2004-114}
805            - ethereal 0.10.8-1
806    [21 Dec 2004] DSA-614-1 xzgv - integer overflows
807            {CAN-2004-0994}
808            - xzgv 0.8-3
809    [20 Dec 2004] DSA-612-1 a2ps - unsanitised input
810            {CAN-2004-1170}
811            - a2ps 4.13b-4.2
812    [20 Dec 2004] DSA-611-1 htget - buffer overflow
813            {CAN-2004-0852}
814            NOTE: htget not in sarge or unstable
815    [17 Dec 2004] DSA-610-1 cscope - insecure temporary file
816            {CAN-2004-0996}
817            - cscope 15.5-1
818    [14 Dec 2004] DSA-609-1 atari800 - buffer overflows
819            {CAN-2004-1076}
820            - atari800 1.3.2-1
821    [14 Dec 2004] DSA-608-1 zgv - integer overflows, unsanitised input
822            {CAN-2004-1095 CAN-2004-0999}
823            - zgv 5.7-1.3
824            NOTE: changelog says he only patched 1095, but diff comparison
825            NOTE: shows 0999 was also fixed.
826    [10 Dec 2004] DSA-607-1 xfree86 - several
827            {CAN-2004-0914}
828            - xfree86 4.3.0.dfsg.1-9
829    [08 Dec 2004] DSA-606-1 nfs-utils - wrong signal handler
830            {CAN-2004-1014}
831            - nfs-utils 1:1.0.6-3.1
832    [06 Dec 2004] DSA-605-1 viewcvs - settings not honored
833            {CAN-2004-0915}
834            - viewcvs 0.9.2+cvs.1.0.dev.2004.07.28-1.2
835    [03 Dec 2004] DSA-604-1 hpsockd - missing input sanitising
836            {CAN-2004-0993}
837            - hpsockd 0.14
838    [01 Dec 2004] DSA-603-1 openssl - insecure temporary file
839            {CAN-2004-0975}
840            - openssl 0.9.7e-3
841    [29 Nov 2004] DSA-602-1 libgd2 - integer overlow
842            {CAN-2004-0941 CAN-2004-0990}
843            NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
844            - libgd2 2.0.33-1.1
845    [29 Nov 2004] DSA-601-1 libgd1 - integer overflow
846            {CAN-2004-0941 CAN-2004-0990}
847            NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
848            - libgd 1.8.4-36.1
849    [25 Nov 2004] DSA-599-1 tetex-bin - integer overflows
850            {CAN-2004-0888}
851            - tetex-bin 2.0.2-23
852    [25 Nov 2004] DSA-598-1 yardradius - buffer overflow
853            {CAN-2004-0987}
854            - yardradius 1.0.20-15
855    [25 Nov 2004] DSA-597-1 cyrus-imapd - buffer overflow
856            {CAN-2004-1012 CAN-2004-1013}
857            - cyrus21-imapd 2.1.17-1
858    [24 Nov 2004] DSA-596-2 sudo - missing input sanitising
859            {CAN-2004-1051}
860            - sudo 1.6.8p3-1
861    [24 Nov 2004] DSA-596-1 sudo - missing input sanitising
862            {CAN-2004-1051}
863            - sudo 1.6.8p3-1
864    [24 Nov 2004] DSA-595-1 bnc - buffer overflow
865            {CAN-2004-1052}
866            NOTE: package not in sarge or sid
867    [17 Nov 2004] DSA-594-1 apache - buffer overflows
868            {CAN-2004-0940}
869            - apache 1.3.33-2
870    [16 Nov 2004] DSA-593-1 imagemagick - buffer overflow
871            {CAN-2004-0981}
872            - imagemagick 6:6.0.6.2-1.5
873    [12 Nov 2004] DSA-592-1 ez-ipupdate - format string
874            {CAN-2004-0980}
875            - ez-ipupdate 3.0.11b8-8
876    [09 Nov 2004] DSA-591-1 libgd2 - integer overflows
877            {CAN-2004-0990}
878            - libgd2 2.0.30-1
879    [09 Nov 2004] DSA-590-1 gnats - format string vulnerability
880            {CAN-2004-0623}
881            NOTE: DSA got version of fix for unstable wrong
882            - gnats 4.0-6.1
883    [09 Nov 2004] DSA-589-1 libgd - integer overflows
884            {CAN-2004-0990}
885            - libgd1 1.8.4-36.1
886    [08 Nov 2004] DSA-588-1 gzip - insecure temporary files
887            {CAN-2004-0970}
888            NOTE: dsa says sid not affected
889    [08 Nov 2004] DSA-587-1 freeamp - buffer overflow
890            {CAN-2004-0964}
891            NOTE: DSA says zinf not vulnerable in sarge
892    [08 Nov 2004] DSA-586-1 ruby - infinite loop
893            {CAN-2004-0983}
894            - ruby1.6 1.6.8-12
895            - ruby1.8 1.8.1+1.8.2pre2-4
896  [05 Nov 2004] DSA-585-1 shadow - programming error  [05 Nov 2004] DSA-585-1 shadow - programming error
897          {CAN-2004-1001}          {CAN-2004-1001}
898          - shadow 1:4.0.3-30.3          - shadow 1:4.0.3-30.3
# Line 6  Line 901 
901          - dhcp 2.0pl5-19.1          - dhcp 2.0pl5-19.1
902  [03 Nov 2004] DSA-583-1 lvm10 - insecure temporary directory  [03 Nov 2004] DSA-583-1 lvm10 - insecure temporary directory
903          {CAN-2004-0972}          {CAN-2004-0972}
         TODO: I thought this didn't really matter because the script  
         TODO: was not included in the binary package. Check or fix.  
904  [02 Nov 2004] DSA-582-1 libxml - buffer overflow  [02 Nov 2004] DSA-582-1 libxml - buffer overflow
905          {CAN-2004-0989}          {CAN-2004-0989}
906          - libxml 1.8.17-9          - libxml 1.8.17-9
# Line 40  Line 933 
933          {CAN-2004-0888}          {CAN-2004-0888}
934          - cupsys 1.1.20final+rc1-10          - cupsys 1.1.20final+rc1-10
935          {CAN-2004-0889}          {CAN-2004-0889}
936          - xpdf 3.00-9          - xpdf 3.00-10
937          - kpdf (unfixed; bug #278173)          NOTE: kpdf and kfax are fixed in sarge, bug #278173 and #280373 for reference
938            - kpdf 4:3.3.1-1
939          - gpdf 2.8.0-1          - gpdf 2.8.0-1
940            - kfax 4:3.3.1-1
941  [21 Oct 2004] DSA-572-1 ecartis - multiple  [21 Oct 2004] DSA-572-1 ecartis - multiple
942          {CAN-2004-0913}          {CAN-2004-0913}
943          - ecartis 1.0.0+cvs.20030911-8          - ecartis 1.0.0+cvs.20030911-8
# Line 57  Line 952 
952          - netkit-telnet-ssl 0.17.24+0.1-4          - netkit-telnet-ssl 0.17.24+0.1-4
953  [16 Oct 2004] DSA-568-1 cyrus-sasl-mit - unsanitised input  [16 Oct 2004] DSA-568-1 cyrus-sasl-mit - unsanitised input
954          {CAN-2004-0884}          {CAN-2004-0884}
955          NOTE removed from testing          NOTE: removed from testing
956          NOTE maintainer reports hole not in cyrus-sasl2-mit          NOTE: maintainer reports hole not in cyrus-sasl2-mit
957  [15 Oct 2004] DSA-567-1 tiff - heap overflows  [15 Oct 2004] DSA-567-1 tiff - heap overflows
958          {CAN-2004-0803 CAN-2004-0804 CAN-2004-0886}          {CAN-2004-0803 CAN-2004-0804 CAN-2004-0886}
959          - tiff 3.6.1-2          - tiff 3.6.1-2
# Line 125  Line 1020 
1020  [16 Sep 2004] DSA-548-1 imlib - unsanitised input  [16 Sep 2004] DSA-548-1 imlib - unsanitised input
1021          {CAN-2004-0817}          {CAN-2004-0817}
1022          - imlib 1.9.14-17          - imlib 1.9.14-17
1023          - imlib+png2 1.9.14-16          - imlib+png2 1.9.14-16.2
1024  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows
1025          {CAN-2004-0827}          {CAN-2004-0827}
1026          - imagemagic 6.0.6.2-1          - imagemagic 6.0.6.2-1
# Line 159  Line 1054 
1054          - kdelibs 4:3.2.3-3.sarge.1          - kdelibs 4:3.2.3-3.sarge.1
1055  [17 Aug 2004] DSA-538 rsync - unauthorised directory traversal and file access  [17 Aug 2004] DSA-538 rsync - unauthorised directory traversal and file access
1056          - rsync 2.6.2-3          - rsync 2.6.2-3
1057  [16 Aug 2004] DSA-537 ruby -- insecure file permissions  [16 Aug 2004] DSA-537 ruby - insecure file permissions
1058          {CAN-2004-0755}          {CAN-2004-0755}
1059          - ruby1.8 1.8.1+1.8.2pre1-4          - ruby1.8 1.8.1+1.8.2pre1-4
1060          HELP: is ruby1.6 vulnerable?          TODO: is ruby1.6 vulnerable?
1061  [04 Aug 2004] DSA-536 libpng - several vulnerabilities  [04 Aug 2004] DSA-536 libpng - several vulnerabilities
1062          {CAN-2004-0597 CAN-2004-0598 CAN-2004-0599 CAN-2004-0768}          {CAN-2004-0597 CAN-2004-0598 CAN-2004-0599 CAN-2004-0768}
1063          - libpng 1.0.15-6          - libpng 1.0.15-6
# Line 223  Line 1118 
1118          {CAN-2004-0411}          {CAN-2004-0411}
1119          - kdelibs 3.2.3          - kdelibs 3.2.3
1120  [10 Jun 2004] DSA-517 cvs - buffer overflow  [10 Jun 2004] DSA-517 cvs - buffer overflow
1121          {CAN-2004-0414]          {CAN-2004-0414}
1122          - cvs 1.12.9-1          - cvs 1.12.9-1
1123  [07 Jun 2004] DSA-516 postgresql - buffer overflow  [07 Jun 2004] DSA-516 postgresql - buffer overflow
1124          {CAN-2004-0547}          {CAN-2004-0547}
# Line 232  Line 1127 
1127          {CAN-2004-0234 CAN-2004-0235}          {CAN-2004-0234 CAN-2004-0235}
1128          ! lha 1.14i-8          ! lha 1.14i-8
1129          NOTE: If 1.14i-8 cannot get into testing, the fix for 1.14i-2.0.1          NOTE: If 1.14i-8 cannot get into testing, the fix for 1.14i-2.0.1
1130          from the DSA could to updated via t-p-u.          NOTE: from the DSA could to updated via t-p-u.
1131  [04 Jun 2004] DSA-514 kernel-image-sparc-2.2 - failing function and TLB flush  [04 Jun 2004] DSA-514 kernel-image-sparc-2.2 - failing function and TLB flush
1132          {CAN-2004-0077}          {CAN-2004-0077}
1133          - kernel-image-sparc-2.2 9.1          - kernel-image-sparc-2.2 9.1
# Line 244  Line 1139 
1139          {CAN-2004-0522}          {CAN-2004-0522}
1140          - gallery 1.4.3-pl2-1          - gallery 1.4.3-pl2-1
1141  [30 May 2004] DSA-511 ethereal - buffer overflows  [30 May 2004] DSA-511 ethereal - buffer overflows
1142          {CAN-2004-0176          {CAN-2004-0176}
1143          - ethereal 0.10.3-1          - ethereal 0.10.3-1
1144  [29 May 2004] DSA-510 jftpgw - format string  [29 May 2004] DSA-510 jftpgw - format string
1145          {CAN-2004-0448}          {CAN-2004-0448}
# Line 333  Line 1228 
1228          {CAN-2004-0381}          {CAN-2004-0381}
1229          - mysql-dfsg 4.0.18-4          - mysql-dfsg 4.0.18-4
1230          {CAN-2004-0388}          {CAN-2004-0388}
1231          ! mysql-dfsg 4.0.18-6          - mysql-dfsg 4.0.18-6
1232  [14 Apr 2004] DSA-482 linux-kernel-2.4.17-apus+s390 - several vulnerabilities  [14 Apr 2004] DSA-482 linux-kernel-2.4.17-apus+s390 - several vulnerabilities
1233          {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}          {CAN-2004-0003 CAN-2004-0010 CAN-2004-0109 CAN-2004-0177 CAN-2004-0178}
1234          NOTE: 2.4.17 not present. Did not check newer kernels.          NOTE: 2.4.17 not present. Did not check newer kernels.
# Line 391  Line 1286 
1286          NOTE: CAN-2004-0081 only affects 0.9.6.          NOTE: CAN-2004-0081 only affects 0.9.6.
1287          NOTE: 0.9.7d also fixes CAN-2004-0112          NOTE: 0.9.7d also fixes CAN-2004-0112
1288          - openssl 0.9.6l          - openssl 0.9.6l
1289            - openssl096 0.9.6m-1
1290  [16 Mar 2004] DSA-464 gdk-pixbuf - broken image handling  [16 Mar 2004] DSA-464 gdk-pixbuf - broken image handling
1291          {CAN-2004-0111}          {CAN-2004-0111}
1292          - gdk-pixbuf 0.22.0-3          - gdk-pixbuf 0.22.0-3
# Line 413  Line 1309 
1309          {CAN-2004-0150}          {CAN-2004-0150}
1310          NOTE: not affected according to DSA          NOTE: not affected according to DSA
1311  [08 Mar 2004] DSA-457 wu-ftpd - several vulnerabilities  [08 Mar 2004] DSA-457 wu-ftpd - several vulnerabilities
1312          CAN-2004-0148 CAN-2004-0185}          {CAN-2004-0148 CAN-2004-0185}
1313          - wu-ftpd 2.6.2-17.1          - wu-ftpd 2.6.2-17.1
1314  [06 Mar 2004] DSA-456 linux-kernel-2.2.19-arm - failing function and TLB flush  [06 Mar 2004] DSA-456 linux-kernel-2.2.19-arm - failing function and TLB flush
1315          {CAN-2004-0077}          {CAN-2004-0077}
# Line 448  Line 1344 
1344          ! hsftp 1.15-1          ! hsftp 1.15-1
1345  [21 Feb 2004] DSA-446 synaesthesia - insecure file creation  [21 Feb 2004] DSA-446 synaesthesia - insecure file creation
1346          {CAN-2004-0160}          {CAN-2004-0160}
1347          DSA notes not setuid anymore so ok          NOTE: DSA notes not setuid anymore so ok
1348  [21 Feb 2004] DSA-445 lbreakout2 - buffer overflow  [21 Feb 2004] DSA-445 lbreakout2 - buffer overflow
1349          {CAN-2004-0158}          {CAN-2004-0158}
1350          - lbreakout2 2.4          - lbreakout2 2.4
# Line 519  Line 1415 
1415          - netpbm-free 2:9.25-9          - netpbm-free 2:9.25-9
1416  [16 Jan 2004] DSA-425 tcpdump - multiple vulnerabilities  [16 Jan 2004] DSA-425 tcpdump - multiple vulnerabilities
1417          {CAN-2003-1029 CAN-2003-0989 CAN-2004-0055 CAN-2004-0057}          {CAN-2003-1029 CAN-2003-0989 CAN-2004-0055 CAN-2004-0057}
1418          HELP: No idea if this is fixed, we have a new upstream version          TODO: No idea if this is fixed, we have a new upstream version
1419          HELP: that came out after these advisories, but neither the debian nor          TODO: that came out after these advisories, but neither the debian nor
1420          HELP: the upstream changelog seem to mention them.          TODO: the upstream changelog seem to mention them.
1421          NOTE: Mailed maintainr.          NOTE: Mailed maintainer.
1422  [16 Jan 2004] DSA-424 mc - buffer overflow  [16 Jan 2004] DSA-424 mc - buffer overflow
1423          {CAN-2003-1023}          {CAN-2003-1023}
1424          - mc 1:4.6.0-4.6.1-pre1-1          - mc 1:4.6.0-4.6.1-pre1-1
# Line 547  Line 1443 
1443          {CAN-2003-0961 CAN-2003-0985}          {CAN-2003-0961 CAN-2003-0985}
1444          NOTE: 2.4.18 not present. Did not check newer kernels.          NOTE: 2.4.18 not present. Did not check newer kernels.
1445  [06 Jan 2004] DSA-416 fsp - buffer overflow, directory traversal  [06 Jan 2004] DSA-416 fsp - buffer overflow, directory traversal
1446          {CAN-2003-1022, CAN-2004-0011}          {CAN-2003-1022 CAN-2004-0011}
1447          - fsp 2.81.b18-1          - fsp 2.81.b18-1
1448  [06 Jan 2004] DSA-415 zebra - denial of service  [06 Jan 2004] DSA-415 zebra - denial of service
1449          {CAN-2003-0795 CAN-2003-0858}          {CAN-2003-0795 CAN-2003-0858}
# Line 574  Line 1470 
1470          {CAN-2003-0972}          {CAN-2003-0972}
1471          - screen 4.0.2-0.1          - screen 4.0.2-0.1
1472  [05 Jan 2004] DSA-407 ethereal - buffer overflows  [05 Jan 2004] DSA-407 ethereal - buffer overflows
1473          {CAN-2003-0925 CAN-2003-0926 CAN-2003-0927 CAN-2003-1012 CAN-2003-1013          {CAN-2003-0925 CAN-2003-0926 CAN-2003-0927 CAN-2003-1012 CAN-2003-1013}
1474          - ethereal 0.10.0-1          - ethereal 0.10.0-1
1475  [05 Jan 2004] DSA-406 lftp - buffer overflow  [05 Jan 2004] DSA-406 lftp - buffer overflow
1476          - lftp 2.6.10-1          - lftp 2.6.10-1
# Line 611  Line 1507 
1507  [15 Oct 2003] DSA-395 tomcat4 - incorrect input handling  [15 Oct 2003] DSA-395 tomcat4 - incorrect input handling
1508          {CAN-2003-0866}          {CAN-2003-0866}
1509          ! tomcat4 4.1.24-2          ! tomcat4 4.1.24-2
1510          NOTE another RC (unreproducible?) bug and missing deps (#263201)          NOTE: another RC (unreproducible?) bug and missing deps (#263201)
1511          NOTE are keeping the fix out of testing          NOTE: are keeping the fix out of testing
1512  [11 Oct 2003] DSA-394 openssl095 - ASN.1 parsing vulnerability  [11 Oct 2003] DSA-394 openssl095 - ASN.1 parsing vulnerability
1513          {CAN-2003-0543 CAN-2003-0544 CAN-2003-0545}          {CAN-2003-0543 CAN-2003-0544 CAN-2003-0545}
1514          - openssl 0.9.7c          - openssl 0.9.7c
# Line 629  Line 1525 
1525          - freesweep 0.88-4.1          - freesweep 0.88-4.1
1526  [26 Sep 2003] DSA-390 marbles - buffer overflow  [26 Sep 2003] DSA-390 marbles - buffer overflow
1527          {CAN-2003-0830}          {CAN-2003-0830}
1528          NOTE not present in sid, sarge          NOTE: not present in sid, sarge
1529  [20 Sep 2003] DSA-389 ipmasq - insecure packet filtering rules  [20 Sep 2003] DSA-389 ipmasq - insecure packet filtering rules
1530          {CAN-2003-0785}          {CAN-2003-0785}
1531          - ipmasq 3.5.12          - ipmasq 3.5.12
# Line 652  Line 1548 
1548          {CAN-2003-0693}          {CAN-2003-0693}
1549          {CAN-2003-0695}          {CAN-2003-0695}
1550          {CAN-2003-0682}          {CAN-2003-0682}
1551          HELP: Screwy changelog does not make sense. Filed bug.          TODO: Screwy changelog does not make sense. Filed bug.
1552  [16 Sep 2003] DSA-382 ssh - possible remote vulnerability  [16 Sep 2003] DSA-382 ssh - possible remote vulnerability
1553          {CAN-2003-0693}          {CAN-2003-0693}
1554          - openssh 1:3.6.1p2-6.0          - openssh 1:3.6.1p2-6.0
# Line 716  Line 1612 
1612          - eroaster 2.2.0-0.5-1          - eroaster 2.2.0-0.5-1
1613  [05 Aug 2003] DSA-365 phpgroupware - several vulnerabilities  [05 Aug 2003] DSA-365 phpgroupware - several vulnerabilities
1614          {CAN-2003-0504 CAN-2003-0599 CAN-2003-0657}          {CAN-2003-0504 CAN-2003-0599 CAN-2003-0657}
1615          - phpgroupware 0.9.14.007-1)          - phpgroupware 0.9.14.007-1
1616  [04 Aug 2003] DSA-364 man-db - buffer overflows, arbitrary command execution  [04 Aug 2003] DSA-364 man-db - buffer overflows, arbitrary command execution
1617          {CAN-2003-0620 CAN-2003-0645}          {CAN-2003-0620 CAN-2003-0645}
1618          - man-db 2.4.1-13          - man-db 2.4.1-13
# Line 741  Line 1637 
1637          {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}          {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}
1638          NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.          NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.
1639  [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit  [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit
1640            {CAN-2003-0466}
1641          - wu-ftpd 2.6.2-12          - wu-ftpd 2.6.2-12
1642  [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows  [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows
1643          {CAN-2003-0611}          {CAN-2003-0611}
# Line 873  Line 1770 
1770          NOTE: DSA contains some strange non-nethack version numbers          NOTE: DSA contains some strange non-nethack version numbers
1771  [11 Jun 2003] DSA-315 gnocatan - buffer overflows, denial of service  [11 Jun 2003] DSA-315 gnocatan - buffer overflows, denial of service
1772          {CAN-2003-0433}          {CAN-2003-0433}
1773          HELP: no mention of any security fixes in debian changelog,          TODO: no mention of any security fixes in debian changelog,
1774          HELP: upstream changelog. Mailed maintainer.          TODO: upstream changelog. Mailed maintainer.
1775  [11 Jun 2003] DSA-314 atftp - buffer overflow  [11 Jun 2003] DSA-314 atftp - buffer overflow
1776          {CAN-2003-0380}          {CAN-2003-0380}
1777          - atftp 0.6.2          - atftp 0.6.2
# Line 912  Line 1809 
1809          {CAN-2003-0073}          {CAN-2003-0073}
1810          - mysql-dfsg 4.0.12-2          - mysql-dfsg 4.0.12-2
1811          {CAN-2003-0150}          {CAN-2003-0150}
1812          HELP: not sure if this is fixed          TODO: not sure if this is fixed
1813  [07 May 2003] DSA-302 fuzz - privilege escalation  [07 May 2003] DSA-302 fuzz - privilege escalation
1814          {CAN-2003-0261}          {CAN-2003-0261}
1815          - fuzz 0.6-7.1          - fuzz 0.6-7.1
# Line 1164  Line 2061 
2061  [09 Jan 2003] DSA-225 tomcat4 - source disclosure  [09 Jan 2003] DSA-225 tomcat4 - source disclosure
2062          {CAN-2002-1394}          {CAN-2002-1394}
2063          ! tomcat4 4.1.16-1          ! tomcat4 4.1.16-1
2064          NOTE another RC (unreproducible?) bug and missing deps (#263201)          NOTE: another RC (unreproducible?) bug and missing deps (#263201)
2065          NOTE are keeping the fix out of testing          NOTE: are keeping the fix out of testing
2066          NOTE this is the second unfixed security hole in tomcat4 in testing..          NOTE: this is the second unfixed security hole in tomcat4 in testing..
2067  [08 Jan 2003] DSA-224 canna - buffer overflow and more  [08 Jan 2003] DSA-224 canna - buffer overflow and more
2068          {CAN-2002-1158 CAN-2002-1159}          {CAN-2002-1158 CAN-2002-1159}
2069          - canna 3.6p1-1          - canna 3.6p1-1
# Line 1285  Line 2182 
2182          - apache 1.3.27-0.1          - apache 1.3.27-0.1
2183          {CAN-2001-0131 CAN-2002-1233}          {CAN-2001-0131 CAN-2002-1233}
2184          - apache 1.3.27-1          - apache 1.3.27-1
2185          HELP: note sure about this          TODO: note sure about this
2186          NOTE: I have mailed maintainers          NOTE: I have mailed maintainers
2187          {NO-CAN Several buffer overflows in ApacheBench}          {NO-CAN Several buffer overflows in ApacheBench}
2188          HELP: I don't know about this          TODO: I don't know about this
2189          NOTE: I have mailed maintainers          NOTE: I have mailed maintainers
2190  [04 Nov 2002] DSA-187 apache - several vulnerabilities  [04 Nov 2002] DSA-187 apache - several vulnerabilities
2191          {CAN-2002-0839 CAN-2002-0840 CAN-2002-0843}          {CAN-2002-0839 CAN-2002-0840 CAN-2002-0843}
2192          - apache 1.3.27-0.1          - apache 1.3.27-0.1
2193          {CAN-2001-0131 CAN-2002-1233}          {CAN-2001-0131 CAN-2002-1233}
2194          - apache 1.3.27-1          - apache 1.3.27-1
2195          HELP: note sure about this          TODO: note sure about this
2196          NOTE: I have mailed maintainers          NOTE: I have mailed maintainers
2197          {NO-CAN Several buffer overflows in ApacheBench}          {NO-CAN Several buffer overflows in ApacheBench}
2198          HELP: I don't know about this          TODO: I don't know about this
2199          NOTE: I have mailed maintainers          NOTE: I have mailed maintainers
2200  [01 Nov 2002] DSA-186 log2mail - buffer overflow  [01 Nov 2002] DSA-186 log2mail - buffer overflow
2201          {CAN-2002-1251}          {CAN-2002-1251}
# Line 1325  Line 2222 
2222          {CAN-2002-0838}          {CAN-2002-0838}
2223          - gnome-gv 1.99.7-9          - gnome-gv 1.99.7-9
2224  [17 Oct 2002] DSA-178 heimdal - remote command execution  [17 Oct 2002] DSA-178 heimdal - remote command execution
2225          {CAN-2002-1225, CAN-2002-1226}          {CAN-2002-1225 CAN-2002-1226}
2226          - heimdal 0.4e-21          - heimdal 0.4e-21
2227  [17 Oct 2002] DSA-177 pam - serious security violation  [17 Oct 2002] DSA-177 pam - serious security violation
2228          {CAN-2002-1227}          {CAN-2002-1227}
# Line 1346  Line 2243 
2243          {CAN-2002-1193}          {CAN-2002-1193}
2244          NOTE: not in testing nor unstable (was fixed in 4.0beta9-9)          NOTE: not in testing nor unstable (was fixed in 4.0beta9-9)
2245  [07 Oct 2002] DSA-171 fetchmail - buffer overflows  [07 Oct 2002] DSA-171 fetchmail - buffer overflows
2246          {CAN-2002-1175, CAN-2002-1174}          {CAN-2002-1175 CAN-2002-1174}
2247          - fetchmail 6.1.0-1          - fetchmail 6.1.0-1
2248          NOTE: fetchmail-ssl not in testing, fixed in unstable (fetchmail-ssl 6.1.0-1)          NOTE: fetchmail-ssl not in testing, fixed in unstable (fetchmail-ssl 6.1.0-1)
2249  [04 Oct 2002] DSA-170 tomcat4 - source code disclosure  [04 Oct 2002] DSA-170 tomcat4 - source code disclosure

Legend:
Removed from v.84  
changed lines
  Added in v.1922

  ViewVC Help
Powered by ViewVC 1.1.5