/[secure-testing]/data/DSA/list
ViewVC logotype

Diff of /data/DSA/list

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 84 by joeyh, Fri Nov 5 21:17:54 2004 UTC revision 828 by dom-guest, Fri Apr 15 11:06:36 2005 UTC
# Line 1  Line 1 
1    [15 Apr 2005] DSA-708-1 php3 - missing input sanitising
2        {CAN-2005-0525}
3        - php3 3.0.18-31
4    [13 Apr 2005] DSA-707-1 mysql - several
5            {CAN-2004-0957 CAN-2005-0709 CAN-2005-0710 CAN-2005-0711}
6            - mysql-dfsg 4.0.24-5
7            - mysql-dfsg-4.1 4.1.10a-6
8            NOTE: not fixed in testing at time of DSA
9    [13 Apr 2005] DSA-706-1 axel - buffer overflow
10            {CAN-2005-0390}
11            - axel 1.0b-1
12    [04 Apr 2005] DSA-705-1 wu-ftpd - missing input sanitising
13            {CAN-2005-0256 CAN-2003-0854}
14            - wu-ftpd 2.6.2-19
15    [04 Apr 2005] DSA-704-1 remstats - tempfile, missing input sanitising
16            {CAN-2005-0387 CAN-2005-0388}
17            - remstats 1.0.13a-5
18            NOTE: not fixed in testing at time of DSA
19    [01 Apr 2005] DSA-703-1 krb5 - buffer overflows
20            {CAN-2005-0468 CAN-2005-0469}
21            - krb5 1.3.6-1
22    [01 Apr 2005] DSA-702-1 imagemagick - several
23            {CAN-2005-0397 CAN-2005-0759 CAN-2005-0760 CAN-2005-0762}
24            - imagemagick 6.0.6.2-2.2
25    [31 Mar 2005] DSA-701-1 samba - integer overflows
26            {CAN-2004-1154}
27            - samba 3.0.10-1
28    [30 Mar 2005] DSA-700-1 mailreader - missing input sanitising
29            {CAN-2005-0386}
30            - mailreader 2.3.29-11
31            NOTE: not fixed in testing at time of DSA
32    [29 Mar 2005] DSA-699-1 netkit-telnet-ssl - buffer overflow
33            {CAN-2005-0469}
34            - netkit-telnet-ssl 0.17.24+0.1-7.1
35            NOTE: not fixed in testing at time of DSA
36    [29 Mar 2005] DSA-698-1 mc - buffer overflow
37            {CAN-2005-0763}
38            NOTE: Not clear which unstable/testing version fixed this,
39            NOTE: but advisory says it's fixed.
40    [29 Mar 2005] DSA-697-1 netkit-telnet - buffer overflow
41            {CAN-2005-0469}
42            - netkit-telnet 0.17-28
43            NOTE: not fixed in testing at time of DSA
44    [22 Mar 2005] DSA-696-1 perl - design flaw
45            {CAN-2005-0448}
46            - perl 5.8.4-8
47            NOTE: fixed in testing at time of DSA
48    [21 Mar 2005] DSA-695-1 xli - buffer overflow, input sanitising, integer overflow
49            {CAN-2001-0775 CAN-2005-0638 CAN-2005-0639}
50            - xli 1.17.0-18
51            NOTE: not fixed in testing at time of DSA
52    [21 Mar 2005] DSA-694-1 xloadimage - missing input sanitising, integer overflow
53            {CAN-2005-0638 CAN-2005-0639}
54            - xloadimage 4.1-14.2
55            NOTE: not fixed in testing at time of DSA
56    [14 Mar 2005] DSA-693-1 luxman - buffer overflow
57            {CAN-2005-0385}
58            NOTE: not fixed in testing at time of DSA
59            NOTE: not in unstable at time of DSA though DSA claimed it was
60            - luxman 0.41-20
61    [14 Mar 2005] DSA-662-2 squirrelmail - several
62            NOTE: only an update to a prior DSA, did not affct sid/sarge.
63    [08 Mar 2005] DSA-692-1 kppp - design flaw
64            {CAN-2005-0205}
65            - kppp 4:3.1.6
66            NOTE: fixed in testing at time of DSA
67    [07 Mar 2005] DSA-691-1 abuse - several
68            {CAN-2005-0098 CAN-2005-0099}
69            NOTE: not in unstable/testing
70    [25 Feb 2005] DSA-690-1 bsmtpd - missing input sanitising
71            {CAN-2005-0107}
72            - bsmtpd 2.3pl8b-16
73            NOTE: not fixed in testing at time of DSA
74    [23 Feb 2005] DSA-689-1 libapache-mod-python - missing input sanitising
75            {CAN-2005-0088}
76            - libapache-mod-python 2.7.10-4
77            NOTE: fixed in testing at time of DSA
78            - libapache2-mod-python 3.1.3-3
79            NOTE: fixed in testing at time of DSA
80    [23 Feb 2005] DSA-688-1 squid - mising input sanitising
81            {CAN-2005-0446}
82            - squid 2.5.8-3
83            NOTE: fixed in testing at time of DSA
84    [21 Feb 2005] DSA-674-3 mailman - cross-site scripting, directory traversal
85            NOTE: only fixed bug in DSA
86    [18 Feb 2005] DSA-687-1 bidwatcher - format string
87            {CAN-2005-0158}
88            - bidwatcher 1.3.17-1
89            NOTE: not fixed in testing at time of DSA
90    [17 Feb 2005] DSA-686-1 gftp - missing input sanitising
91            {CAN-2005-0372}
92            - gftp 2.0.18-1
93            NOTE: not fixed in testing at time of DSA
94    [17 Feb 2005] DSA-685-1 emacs21 - format string
95            {CAN-2005-0100}
96            - emacs21 21.3+1-9
97            NOTE: not fixed in testing at time of DSA
98    [16 Feb 2005] DSA-684-1 typespeed - format string
99            {CAN-2005-0105}
100            - typespeed 0.4.4-8
101            NOTE: not fixed in testing at time of DSA
102    [15 Feb 2005] DSA-683-1 postgresql - buffer overflows
103            {CAN-2005-0245 CAN-2005-0247}
104            - postgresql 7.4.7-2
105            NOTE: fixed in testing at time of DSA
106    [15 Feb 2005] DSA-682-1 awstats - missing input sanitising
107            {CAN-2005-0363}
108            - awstats 6.2-1.2
109            NOTE: not fixed in testing at time of DSA
110    [14 Feb 2005] DSA-681-1 synaesthesia - privilege escalation
111            {CAN-2005-0070}
112            NOTE: does not apply for sarge, program is not setuid anymore
113    [14 Feb 2005] DSA-680-1 htdig - unsanitised input
114            {CAN-2005-0085}
115            - htdig 3.1.6-11
116            NOTE: fixed in testing at time of DSA
117    [14 Feb 2005] DSA-679-1 toolchain-source - insecure temporary files
118            {CAN-2005-0159}
119            - toolchain-source 3.4-5
120            NOTE: not fixed in testing at time of DSA
121    [11 Feb 2005] DSA-678-1 netkit-rwho - missing input validation
122            {CAN-2004-1180}
123            - netkit-rwho 0.17-8
124            NOTE: not fixed in testing at time of DSA
125    [11 Feb 2005] DSA-677-1 sympa - buffer overflow
126            {CAN-2005-0073}
127            - sympa 4.1.2-2.1
128            NOTE: not fixed in testing at time of DSA
129    [11 Feb 2005] DSA-676-1 xpcd - buffer overflow
130            {CAN-2005-0074}
131            - xpcd 2.08-11.1
132            NOTE: not fixed in testing at time of DSA
133    [11 Feb 2005] DSA-674-2 mailman - cross-site scripting, directory traversal
134            NOTE: only fixed bug in DSA
135    [10 Feb 2005] DSA-675-1 hztty - privilege escalation
136            {CAN-2005-0019}
137            - hztty 2.0-6.1
138            NOTE: not fixed in testing at time of DSA
139    [10 Feb 2005] DSA-674-1 mailman - cross-site scripting, directory traversal
140            {CAN-2004-1177}
141            - mailman 2.1.5-5
142            NOTE: fixed in testing at time of DSA
143            {CAN-2005-0202}
144            - mailman 2.1.5-6
145            NOTE: not fixed in testing at time of DSA
146    [10 Feb 2005] DSA-673-1 evolution - integer overflow
147            {CAN-2005-0102}
148            - evolution 2.0.3-1.2
149            NOTE: fixed in testing at time of DSA
150    [09 Feb 2005] DSA-672-1 xview - buffer overflows
151            {CAN-2005-0076}
152            - xview 3.2p1.4-19
153            NOTE: not fixed in testing at time of DSA
154    [08 Feb 2005] DSA-671-1 xemacs21 - format string
155            {CAN-2005-0100}
156            NOTE: not fixed in testing at time of DSA
157            - xemacs21 21.4.16-2
158    [08 Feb 2005] DSA-670-1 emacs20 - format string
159            {CAN-2005-0100}
160            NOTE: also affects emacs21 in unstable, fixed
161    [04 Feb 2005] DSA-689-1 php3 - several
162            {CAN-2004-0594 CAN-2004-0595}
163            - php3 3.0.18-27
164            NOTE: fixed in testing at time of DSA
165    [04 Feb 2005] DSA-668-1 postgresql - privilege escalation
166            {CAN-2005-0227}
167            - postgresql 7.4.7-1
168            NOTE: not fixed in testing at time of DSA
169    [04 Feb 2005] DSA-667-1 squid - several
170            {CAN-2005-0173 CAN-2005-0175 CAN-2005-0194 CAN-2005-0211}
171            - squid 2.5.7-7
172            NOTE: not fixed in testing at time of DSA
173    [04 Feb 2005] DSA-666-1 python2.2 - design flaw
174            {CAN-2005-0089}
175            - python2.2 2.2.3-14
176            - python2.3 2.3.4-20
177            - python2.4 2.4-5
178            NOTE: not fixed in testing at time of DSA
179    [04 Feb 2005] DSA-665-1 ncpfs - missing privilege release
180            {CAN-2005-0013}
181            - ncpfs 2.2.6-1
182            NOTE: not fixed in testing at time of DSA
183    [02 Feb 2005] DSA-664-1 cpio - broken file permissions
184            {CAN-1999-1572}
185            - cpio 2.5-1.2
186            NOTE: not fixed in testing at time of DSA
187    [02 Feb 2005] DSA-663-1 prozilla - buffer overflows
188            {CAN-2004-1120}
189            - prozilla 1.3.7.3-1
190            NOTE: fixed in testing at time of DSA
191    [01 Feb 2005] DSA-662-1 squirrelmail - several
192            {CAN-2005-0104 CAN-2005-0152}
193            NOTE: CAN-2005-0152 only exists in 1.2.6 version
194            - squirrelmail 1.4.4
195            NOTE: fixed in testing at time of DSA
196    [27 Jan 2005] DSA-661-1 f2c - insecure temporary files
197            {CAN-2005-0017 CAN-2005-0018}
198            - f2c 20020621-3.1
199            NOTE: not fixed in testing at time of DSA
200    [26 Jan 2005] DSA-660-1 kdebase - missing return value check
201            {CAN-2005-0078}
202            - kdebase 4:3.0.5
203            NOTE: fixed in testing at time of DSA
204    [26 Jan 2005] DSA-659-1 libpam-radius-auth - information leak, integer underflow
205            {CAN-2004-1340 CAN-2005-0108}
206            - libpam-radius-auth 1.3.16-3
207            NOTE: 1/2 fixed in testing at time of DSA
208    [25 Jan 2005] DSA-658-1 libdbi-perl - insecure temporary file
209            {CAN-2005-0077}
210            - libdbi-perl 1.46-6
211            NOTE: not fixed in testing at time of DSA
212    [25 Jan 2005] DSA-657-1 xine-lib - buffer overflow
213            {CAN-2004-1379}
214            - xine-lib 1-rc6a-1
215            NOTE: fixed in testing at time of DSA
216    [25 Jan 2005] DSA-656-1 vdr - insecure file access
217            {CAN-2005-0071}
218            - vdr 1.2.6-6
219            NOTE: not fixed in testing at time of DSA
220    [25 Jan 2005] DSA-655-1 zhcon - missing privilege release
221            {CAN-2005-0072}
222            - zhcon 1:0.2.3-8.1
223            NOTE: not fixed in testing at time of DSA
224    [21 Jan 2005] DSA-654-1 enscript - several
225            {CAN-2004-1184 CAN-2004-1185 CAN-2004-1186}
226            - enscript 1.6.4-6
227            NOTE: not fixed in testing at time of DSA
228    [21 Jan 2005] DSA-653-1 ethereal - buffer overflow
229            {CAN-2005-0084}
230            - ethereal 0.10.9-1
231            NOTE: not fixed in testing at time of DSA
232    [21 Jan 2005] DSA-652-1 unarj
233            {CAN-2004-0947 CAN-2004-1027}
234            NOTE: not-for-us (unarj)
235    [20 Jan 2005] DSA-651-1 squid - buffer overflow, integer overflow
236            {CAN-2005-0094 CAN-2005-0095}
237            - squid 2.5.7-4
238            NOTE: not fixed in testing at time of DSA
239    [20 Jan 2005] DSA-650-1 sword - missing input sanitising
240            {CAN-2005-0015}
241            - sword 1.5.7-7
242            NOTE: not fixed in testing at time of DSA
243    [20 Jan 2005] DSA-649-1 xtrlock - buffer overflow
244            {CAN-2005-0079}
245            - xtrlock 2.0-9
246            NOTE: fixed in testing at time of DSA
247    [19 Jan 2005] DSA-648-1 xpdf - buffer overflow
248            {CAN-2005-0064}
249            - xpdf 3.00-12
250            NOTE: not fixed in testing at time of DSA
251    [19 Jan 2005] DSA-647-1 mysql - insecure temporary files
252            {CAN-2005-0004}
253            - mysql-dfsg 4.0.23-3
254            - mysql-dfsg-4.1 4.1.8a-6
255            NOTE: not fixed in testing at time of DSA
256    [19 Jan 2005] DSA-646-1 imagemagick - buffer overflow
257            {CAN-2005-0005}
258            - imagemagick 6.0.6.2-2
259            NOTE: not fixed in testing at time of DSA
260    [19 Jan 2005] DSA-645-1 cupsys - buffer overflow
261            {CAN-2005-0064}
262            NOTE: cupsys not affected in sarge, though other programs are vulnerable
263            NOTE: see CAN/list
264            NOTE: not fixed in testing at time of DSA
265    [18 Jan 2005] DSA-644-1 chbg - buffer overflow
266            {CAN-2004-1264}
267            - chbg 1.5-4
268            NOTE: fixed in testing at time of DSA
269    [18 Jan 2005] DSA-643-1 queue - buffer overflows
270            {CAN-2004-0555}
271            - queue 1.30.1-5
272            NOTE: not fixed in testing at time of DSA
273    [17 Jan 2005] DSA-642-1 gallery - several
274            {CAN-2004-1106}
275            - gallery 1.4.4-pl4-1
276            NOTE: fixed in testing at time of DSA
277    [17 Jan 2005] DSA-641-1 playmidi - buffer overflow
278            {CAN-2005-0020}
279            - playmidi 2.4debian-3
280            NOTE: not fixed in testing at time of DSA
281    [17 Jan 2005] DSA-640-1 gatos - buffer overflow
282            {CAN-2005-0016}
283            - gatos 0.0.5-15
284            NOTE: not fixed in testing at time of DSA
285    [14 Jan 2005] DSA-639-1 mc - several
286            {CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176}
287            NOTE: unstable not vulnerable according to DSA
288            NOTE: DSA was wrong..
289            - mc 1:4.6.0-4.6.1-pre3-1
290            NOTE: not fixed in testing at time of DSA
291    [13 Jan 2005] DSA-638-1 gopher - several
292            {CAN-2004-0560 CAN-2004-0561}
293            NOTE: not in sarge
294    [13 Jan 2005] DSA-637-1 exim-tls - buffer overflow
295            {CAN-2005-0021}
296            NOTE: not in sarge
297    [12 Jan 2005] DSA-636-1 glibc - insecure temporary files
298            {CAN-2004-0968}
299            - glibc 2.3.2.ds1-20
300            NOTE: fixed in testing at time of DSA
301    [12 Jan 2005] DSA-635-1 exim - buffer overflow
302            {CAN-2005-0021}
303            - exim4 4.34-10
304            NOTE: fixed in testing at time of DSA
305            - exim 3.36-13
306            NOTE: not fixed in testing at time of DSA
307    [11 Jan 2005] DSA-634-1 hylafax - weak hostname and username validation
308            {CAN-2004-1182}
309            - hylafax 4.2.1-1
310            NOTE: fixed in testing at time of DSA
311    [11 Jan 2005] DSA-633-1 bmv - insecure temporary file
312            {CAN-2003-0014}
313            - bmv 1.2-17
314            NOTE: fixed in testing at time of DSA
315    [10 Jan 2005] DSA-632-1 linpopup - buffer overflow
316            {CAN-2004-1282}
317            - linpopup 1.2.0-7
318            NOTE: fixed in testing at time of DSA
319    [10 Jan 2005] DSA-631-1 kdelibs - unsanitised input
320            {CAN-2004-1165}
321            - kdelibs 4:3.3.2-1
322            NOTE: not fixed in testing at time of DSA
323    [10 Jan 2005] DSA-630-1 lintian - insecure temporary directory
324            {CAN-2004-1000}
325            - lintian 1.23.6
326            NOTE: not fixed in testing at time of DSA
327    [07 Jan 2005] DSA-629-1 krb5 - buffer overflow
328            {CAN-2004-1189}
329            - krb5 1.3.6-1
330            NOTE: not fixed in testing at time of DSA
331    [06 Jan 2005] DSA-628-1 imlib2 - integer overflows
332            {CAN-2004-1026}
333            - imlib2 1.1.2-2.1
334            NOTE: not fixed in testing at time of DSA
335    [06 Jan 2005] DSA-627-1 namazu2 - unsanitised input
336            {CAN-2004-1318}
337            - namazu2 2.0.14-1
338            NOTE: not fixed in testing at time of DSA
339    [06 Jan 2005] DSA-626-1 tiff - unsanitised input
340            {CAN-2004-1183}
341            - libtiff4 3.6.1-5
342            NOTE: not fixed in testing at time of DSA
343    [05 Jan 2005] DSA-625-1 pcal - buffer overflows
344            {CAN-2004-1289}
345            - pcal 4.8.0-1
346            NOTE: not fixed in testing at time of DSA
347    [05 Jan 2005] DSA-624-1 zip - buffer overflow
348            {CAN-2004-1010}
349            - zip 2.30-8
350            NOTE: fixed in testing at time of DSA
351    [04 Jan 2005] DSA-623-1 nasm - buffer overflow
352            {CAN-2004-1287}
353            - nasm 0.98.38-1.1
354    [03 Jan 2005] DSA-622-1 htmlheadline - insecure temporary files
355            {CAN-2004-1181}
356            NOTE: not in unstable
357    [31 Dec 2004] DSA-621-1 cupsys - buffer overflow
358            {CAN-2004-1125}
359            - cupsys 1.1.22-2
360    [30 Dec 2004] DSA-620-1 perl - insecure temporary files / directories
361            {CAN-2004-0452 CAN-2004-0976}
362            - perl 5.8.4-5
363    [30 Dev 2004] DSA-619-1 xpdf - buffer overflow
364            {CAN-2004-1125}
365            - xpdf 3.00-11
366    [24 Dec 2004] DSA-618-1 imlib - buffer overflows, integer overflows
367            {CAN-2004-1025 CAN-2004-1026}
368            - imlib 1.9.14-17.1
369            - imlib-png2 1.9.14-16.1
370    [24 Dec 2004] DSA-617-1 libtiff - insufficient input validation
371            {CAN-2004-1308}
372            - libtiff4 3.6.1-4
373    [23 Dec 2004] DSA-616-1 telnetd-ssl - format string
374            {CAN-2004-0998}
375            - telnetd-ssl 0.17.24+0.1-6
376    [22 Dec 2004] DSA-615-1 debmake - insecure temporary file
377            {CAN-2004-1179}
378            - debmake 3.7.7
379    [21 Dec 2004] DSA-614-1 xzgv - integer overflows
380            {CAN-2004-0994}
381            - xzgv 0.8-3
382    [21 Dec 2004] DSA-613-1 ethereal - inifinite loop
383            {CAN-2004-114}
384            - ethereal 0.10.8-1
385    [21 Dec 2004] DSA-614-1 xzgv - integer overflows
386            {CAN-2004-0994}
387            - xzgv 0.8-3
388    [20 Dec 2004] DSA-612-1 a2ps - unsanitised input
389            {CAN-2004-1170}
390            - a2ps 4.13b-4.2
391    [20 Dec 2004] DSA-611-1 htget - buffer overflow
392            {CAN-2004-0852}
393            NOTE: htget not in sarge or unstable
394    [17 Dec 2004] DSA-610-1 cscope - insecure temporary file
395            {CAN-2004-0996}
396            - cscope 15.5-1
397    [14 Dec 2004] DSA-609-1 atari800 - buffer overflows
398            {CAN-2004-1076}
399            - atari800 1.3.2-1
400    [14 Dec 2004] DSA-608-1 zgv - integer overflows, unsanitised input
401            {CAN-2004-1095 CAN-2004-0999}
402            - zgv 5.7-1.3
403            NOTE: changelog says he only patched 1095, but diff comparison
404            NOTE: shows 0999 was also fixed.
405    [10 Dec 2004] DSA-607-1 xfree86 - several
406            {CAN-2004-0914}
407            - xfree86 4.3.0.dfsg.1-9
408    [08 Dec 2004] DSA-606-1 nfs-utils - wrong signal handler
409            {CAN-2004-1014}
410            - nfs-utils 1:1.0.6-3.1
411    [06 Dec 2004] DSA-605-1 viewcvs - settings not honored
412            {CAN-2004-0915}
413            - viewcvs 0.9.2+cvs.1.0.dev.2004.07.28-1.2
414    [03 Dec 2004] DSA-604-1 hpsockd - missing input sanitising
415            {CAN-2004-0993}
416            - hpsockd 0.14
417    [01 Dec 2004] DSA-603-1 openssl - insecure temporary file
418            {CAN-2004-0975}
419            - openssl 0.9.7e-3
420    [29 Nov 2004] DSA-602-1 libgd2 - integer overlow
421            {CAN-2004-0941 CAN-2004-0990}
422            NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
423            - libgd2 2.0.33-1.1
424    [29 Nov 2004] DSA-601-1 libgd1 - integer overflow
425            {CAN-2004-0941 CAN-2004-0990}
426            NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
427            - libgd 1.8.4-36.1
428    [25 Nov 2004] DSA-599-1 tetex-bin - integer overflows
429            {CAN-2004-0888}
430            - tetex-bin 2.0.2-23
431    [25 Nov 2004] DSA-598-1 yardradius - buffer overflow
432            {CAN-2004-0987}
433            - yardradius 1.0.20-15
434    [25 Nov 2004] DSA-597-1 cyrus-imapd - buffer overflow
435            {CAN-2004-1012 CAN-2004-1013}
436            - cyrus21-imapd 2.1.17-1
437    [24 Nov 2004] DSA-596-2 sudo - missing input sanitising
438            {CAN-2004-1051}
439            - sudo 1.6.8p3-1
440    [24 Nov 2004] DSA-596-1 sudo - missing input sanitising
441            {CAN-2004-1051}
442            - sudo 1.6.8p3-1
443    [24 Nov 2004] DSA-595-1 bnc - buffer overflow
444            {CAN-2004-1052}
445            NOTE: package not in sarge or sid
446    [17 Nov 2004] DSA-594-1 apache - buffer overflows
447            {CAN-2004-0940}
448            - apache 1.3.33-2
449    [16 Nov 2004] DSA-593-1 imagemagick - buffer overflow
450            {CAN-2004-0981}
451            - imagemagick 6:6.0.6.2-1.5
452    [12 Nov 2004] DSA-592-1 ez-ipupdate - format string
453            {CAN-2004-0980}
454            - ez-ipupdate 3.0.11b8-8
455    [09 Nov 2004] DSA-591-1 libgd2 - integer overflows
456            {CAN-2004-0990}
457            - libgd2 2.0.30-1
458    [09 Nov 2004] DSA-590-1 gnats - format string vulnerability
459            {CAN-2004-0623}
460            NOTE: DSA got version of fix for unstable wrong
461            - gnats 4.0-6.1
462    [09 Nov 2004] DSA-589-1 libgd - integer overflows
463            {CAN-2004-0990}
464            - libgd1 1.8.4-36.1
465    [08 Nov 2004] DSA-588-1 gzip - insecure temporary files
466            {CAN-2004-0970}
467            NOTE: dsa says sid not affected
468    [08 Nov 2004] DSA-587-1 freeamp - buffer overflow
469            {CAN-2004-0964}
470            NOTE: DSA says zinf not vulnerable in sarge
471    [08 Nov 2004] DSA-586-1 ruby - infinite loop
472            {CAN-2004-0983}
473            - ruby1.6 1.6.8-12
474            - ruby1.8 1.8.1+1.8.2pre2-4
475  [05 Nov 2004] DSA-585-1 shadow - programming error  [05 Nov 2004] DSA-585-1 shadow - programming error
476          {CAN-2004-1001}          {CAN-2004-1001}
477          - shadow 1:4.0.3-30.3          - shadow 1:4.0.3-30.3
# Line 6  Line 480 
480          - dhcp 2.0pl5-19.1          - dhcp 2.0pl5-19.1
481  [03 Nov 2004] DSA-583-1 lvm10 - insecure temporary directory  [03 Nov 2004] DSA-583-1 lvm10 - insecure temporary directory
482          {CAN-2004-0972}          {CAN-2004-0972}
         TODO: I thought this didn't really matter because the script  
         TODO: was not included in the binary package. Check or fix.  
483  [02 Nov 2004] DSA-582-1 libxml - buffer overflow  [02 Nov 2004] DSA-582-1 libxml - buffer overflow
484          {CAN-2004-0989}          {CAN-2004-0989}
485          - libxml 1.8.17-9          - libxml 1.8.17-9
# Line 40  Line 512 
512          {CAN-2004-0888}          {CAN-2004-0888}
513          - cupsys 1.1.20final+rc1-10          - cupsys 1.1.20final+rc1-10
514          {CAN-2004-0889}          {CAN-2004-0889}
515          - xpdf 3.00-9          - xpdf 3.00-10
516          - kpdf (unfixed; bug #278173)          NOTE: kpdf and kfax are fixed in sarge, bug #278173 and #280373 for reference
517            - kpdf 4:3.3.1-1
518          - gpdf 2.8.0-1          - gpdf 2.8.0-1
519            - kfax 4:3.3.1-1
520  [21 Oct 2004] DSA-572-1 ecartis - multiple  [21 Oct 2004] DSA-572-1 ecartis - multiple
521          {CAN-2004-0913}          {CAN-2004-0913}
522          - ecartis 1.0.0+cvs.20030911-8          - ecartis 1.0.0+cvs.20030911-8
# Line 125  Line 599 
599  [16 Sep 2004] DSA-548-1 imlib - unsanitised input  [16 Sep 2004] DSA-548-1 imlib - unsanitised input
600          {CAN-2004-0817}          {CAN-2004-0817}
601          - imlib 1.9.14-17          - imlib 1.9.14-17
602          - imlib+png2 1.9.14-16          - imlib+png2 1.9.14-16.2
603  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows  [16 Sep 2004] DSA-547-1 imagemagic - buffer overflows
604          {CAN-2004-0827}          {CAN-2004-0827}
605          - imagemagic 6.0.6.2-1          - imagemagic 6.0.6.2-1
# Line 159  Line 633 
633          - kdelibs 4:3.2.3-3.sarge.1          - kdelibs 4:3.2.3-3.sarge.1
634  [17 Aug 2004] DSA-538 rsync - unauthorised directory traversal and file access  [17 Aug 2004] DSA-538 rsync - unauthorised directory traversal and file access
635          - rsync 2.6.2-3          - rsync 2.6.2-3
636  [16 Aug 2004] DSA-537 ruby -- insecure file permissions  [16 Aug 2004] DSA-537 ruby - insecure file permissions
637          {CAN-2004-0755}          {CAN-2004-0755}
638          - ruby1.8 1.8.1+1.8.2pre1-4          - ruby1.8 1.8.1+1.8.2pre1-4
639          HELP: is ruby1.6 vulnerable?          HELP: is ruby1.6 vulnerable?
# Line 244  Line 718 
718          {CAN-2004-0522}          {CAN-2004-0522}
719          - gallery 1.4.3-pl2-1          - gallery 1.4.3-pl2-1
720  [30 May 2004] DSA-511 ethereal - buffer overflows  [30 May 2004] DSA-511 ethereal - buffer overflows
721          {CAN-2004-0176          {CAN-2004-0176}
722          - ethereal 0.10.3-1          - ethereal 0.10.3-1
723  [29 May 2004] DSA-510 jftpgw - format string  [29 May 2004] DSA-510 jftpgw - format string
724          {CAN-2004-0448}          {CAN-2004-0448}
# Line 391  Line 865 
865          NOTE: CAN-2004-0081 only affects 0.9.6.          NOTE: CAN-2004-0081 only affects 0.9.6.
866          NOTE: 0.9.7d also fixes CAN-2004-0112          NOTE: 0.9.7d also fixes CAN-2004-0112
867          - openssl 0.9.6l          - openssl 0.9.6l
868            - openssl096 0.9.6m-1
869  [16 Mar 2004] DSA-464 gdk-pixbuf - broken image handling  [16 Mar 2004] DSA-464 gdk-pixbuf - broken image handling
870          {CAN-2004-0111}          {CAN-2004-0111}
871          - gdk-pixbuf 0.22.0-3          - gdk-pixbuf 0.22.0-3
# Line 413  Line 888 
888          {CAN-2004-0150}          {CAN-2004-0150}
889          NOTE: not affected according to DSA          NOTE: not affected according to DSA
890  [08 Mar 2004] DSA-457 wu-ftpd - several vulnerabilities  [08 Mar 2004] DSA-457 wu-ftpd - several vulnerabilities
891          CAN-2004-0148 CAN-2004-0185}          {CAN-2004-0148 CAN-2004-0185}
892          - wu-ftpd 2.6.2-17.1          - wu-ftpd 2.6.2-17.1
893  [06 Mar 2004] DSA-456 linux-kernel-2.2.19-arm - failing function and TLB flush  [06 Mar 2004] DSA-456 linux-kernel-2.2.19-arm - failing function and TLB flush
894          {CAN-2004-0077}          {CAN-2004-0077}
# Line 522  Line 997 
997          HELP: No idea if this is fixed, we have a new upstream version          HELP: No idea if this is fixed, we have a new upstream version
998          HELP: that came out after these advisories, but neither the debian nor          HELP: that came out after these advisories, but neither the debian nor
999          HELP: the upstream changelog seem to mention them.          HELP: the upstream changelog seem to mention them.
1000          NOTE: Mailed maintainr.          NOTE: Mailed maintainer.
1001  [16 Jan 2004] DSA-424 mc - buffer overflow  [16 Jan 2004] DSA-424 mc - buffer overflow
1002          {CAN-2003-1023}          {CAN-2003-1023}
1003          - mc 1:4.6.0-4.6.1-pre1-1          - mc 1:4.6.0-4.6.1-pre1-1
# Line 547  Line 1022 
1022          {CAN-2003-0961 CAN-2003-0985}          {CAN-2003-0961 CAN-2003-0985}
1023          NOTE: 2.4.18 not present. Did not check newer kernels.          NOTE: 2.4.18 not present. Did not check newer kernels.
1024  [06 Jan 2004] DSA-416 fsp - buffer overflow, directory traversal  [06 Jan 2004] DSA-416 fsp - buffer overflow, directory traversal
1025          {CAN-2003-1022, CAN-2004-0011}          {CAN-2003-1022 CAN-2004-0011}
1026          - fsp 2.81.b18-1          - fsp 2.81.b18-1
1027  [06 Jan 2004] DSA-415 zebra - denial of service  [06 Jan 2004] DSA-415 zebra - denial of service
1028          {CAN-2003-0795 CAN-2003-0858}          {CAN-2003-0795 CAN-2003-0858}
# Line 741  Line 1216 
1216          {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}          {CAN-2003-0461 CAN-2003-0462 CAN-2003-0476 CAN-2003-0501 CAN-2003-0550 CAN-2003-0551 CAN-2003-0552 CAN-2003-0018 CAN-2003-0619 CAN-2003-0643}
1217          NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.          NOTE: 2.4.18/2.4.20 not in unstable/testing. Did not check newer ones.
1218  [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit  [31 Jul 2003] DSA-357 wu-ftpd - remote root exploit
1219            {CAN-2003-0466}
1220          - wu-ftpd 2.6.2-12          - wu-ftpd 2.6.2-12
1221  [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows  [30 Jul 2003] DSA-356 xtokkaetama - buffer overflows
1222          {CAN-2003-0611}          {CAN-2003-0611}
# Line 1325  Line 1801 
1801          {CAN-2002-0838}          {CAN-2002-0838}
1802          - gnome-gv 1.99.7-9          - gnome-gv 1.99.7-9
1803  [17 Oct 2002] DSA-178 heimdal - remote command execution  [17 Oct 2002] DSA-178 heimdal - remote command execution
1804          {CAN-2002-1225, CAN-2002-1226}          {CAN-2002-1225 CAN-2002-1226}
1805          - heimdal 0.4e-21          - heimdal 0.4e-21
1806  [17 Oct 2002] DSA-177 pam - serious security violation  [17 Oct 2002] DSA-177 pam - serious security violation
1807          {CAN-2002-1227}          {CAN-2002-1227}
# Line 1346  Line 1822 
1822          {CAN-2002-1193}          {CAN-2002-1193}
1823          NOTE: not in testing nor unstable (was fixed in 4.0beta9-9)          NOTE: not in testing nor unstable (was fixed in 4.0beta9-9)
1824  [07 Oct 2002] DSA-171 fetchmail - buffer overflows  [07 Oct 2002] DSA-171 fetchmail - buffer overflows
1825          {CAN-2002-1175, CAN-2002-1174}          {CAN-2002-1175 CAN-2002-1174}
1826          - fetchmail 6.1.0-1          - fetchmail 6.1.0-1
1827          NOTE: fetchmail-ssl not in testing, fixed in unstable (fetchmail-ssl 6.1.0-1)          NOTE: fetchmail-ssl not in testing, fixed in unstable (fetchmail-ssl 6.1.0-1)
1828  [04 Oct 2002] DSA-170 tomcat4 - source code disclosure  [04 Oct 2002] DSA-170 tomcat4 - source code disclosure

Legend:
Removed from v.84  
changed lines
  Added in v.828

  ViewVC Help
Powered by ViewVC 1.1.5