| 1 |
|
[19 Apr 2005] DSA-711-1 info2www - missing input sanitising |
| 2 |
|
{CAN-2004-1341} |
| 3 |
|
- info2www 1.2.2.9-23 |
| 4 |
|
NOTE: fixed in testing in time of DSA |
| 5 |
|
[18 Apr 2005] DSA-710-1 gtkhtml - null pointer dereference |
| 6 |
|
{CAN-2003-0541} |
| 7 |
|
- gtkhtml 1.0.4-6.2 |
| 8 |
|
NOTE: fixed in testing at time of DSA |
| 9 |
|
[15 Apr 2005] DSA-709-1 libexif - buffer overflow |
| 10 |
|
{CAN-2005-0664} |
| 11 |
|
- libexif 0.6.9-5 |
| 12 |
|
[15 Apr 2005] DSA-708-1 php3 - missing input sanitising |
| 13 |
|
{CAN-2005-0525} |
| 14 |
|
- php3 3.0.18-31 |
| 15 |
|
[13 Apr 2005] DSA-707-1 mysql - several |
| 16 |
|
{CAN-2004-0957 CAN-2005-0709 CAN-2005-0710 CAN-2005-0711} |
| 17 |
|
- mysql-dfsg 4.0.24-5 |
| 18 |
|
- mysql-dfsg-4.1 4.1.10a-6 |
| 19 |
|
NOTE: not fixed in testing at time of DSA |
| 20 |
|
[13 Apr 2005] DSA-706-1 axel - buffer overflow |
| 21 |
|
{CAN-2005-0390} |
| 22 |
|
- axel 1.0b-1 |
| 23 |
|
NOTE: fixed in testing in time of DSA |
| 24 |
|
[04 Apr 2005] DSA-705-1 wu-ftpd - missing input sanitising |
| 25 |
|
{CAN-2005-0256 CAN-2003-0854} |
| 26 |
|
- wu-ftpd 2.6.2-19 |
| 27 |
|
[04 Apr 2005] DSA-704-1 remstats - tempfile, missing input sanitising |
| 28 |
|
{CAN-2005-0387 CAN-2005-0388} |
| 29 |
|
- remstats 1.0.13a-5 |
| 30 |
|
NOTE: not fixed in testing at time of DSA |
| 31 |
|
[01 Apr 2005] DSA-703-1 krb5 - buffer overflows |
| 32 |
|
{CAN-2005-0468 CAN-2005-0469} |
| 33 |
|
- krb5 1.3.6-1 |
| 34 |
|
[01 Apr 2005] DSA-702-1 imagemagick - several |
| 35 |
|
{CAN-2005-0397 CAN-2005-0759 CAN-2005-0760 CAN-2005-0762} |
| 36 |
|
- imagemagick 6.0.6.2-2.2 |
| 37 |
|
[31 Mar 2005] DSA-701-1 samba - integer overflows |
| 38 |
|
{CAN-2004-1154} |
| 39 |
|
- samba 3.0.10-1 |
| 40 |
|
[30 Mar 2005] DSA-700-1 mailreader - missing input sanitising |
| 41 |
|
{CAN-2005-0386} |
| 42 |
|
- mailreader 2.3.29-11 |
| 43 |
|
NOTE: not fixed in testing at time of DSA |
| 44 |
|
[29 Mar 2005] DSA-699-1 netkit-telnet-ssl - buffer overflow |
| 45 |
|
{CAN-2005-0469} |
| 46 |
|
- netkit-telnet-ssl 0.17.24+0.1-7.1 |
| 47 |
|
NOTE: not fixed in testing at time of DSA |
| 48 |
|
[29 Mar 2005] DSA-698-1 mc - buffer overflow |
| 49 |
|
{CAN-2005-0763} |
| 50 |
|
NOTE: Not clear which unstable/testing version fixed this, |
| 51 |
|
NOTE: but advisory says it's fixed. |
| 52 |
|
[29 Mar 2005] DSA-697-1 netkit-telnet - buffer overflow |
| 53 |
|
{CAN-2005-0469} |
| 54 |
|
- netkit-telnet 0.17-28 |
| 55 |
|
NOTE: not fixed in testing at time of DSA |
| 56 |
|
[22 Mar 2005] DSA-696-1 perl - design flaw |
| 57 |
|
{CAN-2005-0448} |
| 58 |
|
- perl 5.8.4-8 |
| 59 |
|
NOTE: fixed in testing at time of DSA |
| 60 |
|
[21 Mar 2005] DSA-695-1 xli - buffer overflow, input sanitising, integer overflow |
| 61 |
|
{CAN-2001-0775 CAN-2005-0638 CAN-2005-0639} |
| 62 |
|
- xli 1.17.0-18 |
| 63 |
|
NOTE: not fixed in testing at time of DSA |
| 64 |
|
[21 Mar 2005] DSA-694-1 xloadimage - missing input sanitising, integer overflow |
| 65 |
|
{CAN-2005-0638 CAN-2005-0639} |
| 66 |
|
- xloadimage 4.1-14.2 |
| 67 |
|
NOTE: not fixed in testing at time of DSA |
| 68 |
|
[14 Mar 2005] DSA-693-1 luxman - buffer overflow |
| 69 |
|
{CAN-2005-0385} |
| 70 |
|
NOTE: not fixed in testing at time of DSA |
| 71 |
|
NOTE: not in unstable at time of DSA though DSA claimed it was |
| 72 |
|
- luxman 0.41-20 |
| 73 |
|
[14 Mar 2005] DSA-662-2 squirrelmail - several |
| 74 |
|
NOTE: only an update to a prior DSA, did not affct sid/sarge. |
| 75 |
|
[08 Mar 2005] DSA-692-1 kppp - design flaw |
| 76 |
|
{CAN-2005-0205} |
| 77 |
|
- kppp 4:3.1.6 |
| 78 |
|
NOTE: fixed in testing at time of DSA |
| 79 |
|
[07 Mar 2005] DSA-691-1 abuse - several |
| 80 |
|
{CAN-2005-0098 CAN-2005-0099} |
| 81 |
|
NOTE: not in unstable/testing |
| 82 |
|
[25 Feb 2005] DSA-690-1 bsmtpd - missing input sanitising |
| 83 |
|
{CAN-2005-0107} |
| 84 |
|
- bsmtpd 2.3pl8b-16 |
| 85 |
|
NOTE: not fixed in testing at time of DSA |
| 86 |
|
[23 Feb 2005] DSA-689-1 libapache-mod-python - missing input sanitising |
| 87 |
|
{CAN-2005-0088} |
| 88 |
|
- libapache-mod-python 2.7.10-4 |
| 89 |
|
NOTE: fixed in testing at time of DSA |
| 90 |
|
- libapache2-mod-python 3.1.3-3 |
| 91 |
|
NOTE: fixed in testing at time of DSA |
| 92 |
|
[23 Feb 2005] DSA-688-1 squid - mising input sanitising |
| 93 |
|
{CAN-2005-0446} |
| 94 |
|
- squid 2.5.8-3 |
| 95 |
|
NOTE: fixed in testing at time of DSA |
| 96 |
|
[21 Feb 2005] DSA-674-3 mailman - cross-site scripting, directory traversal |
| 97 |
|
NOTE: only fixed bug in DSA |
| 98 |
[18 Feb 2005] DSA-687-1 bidwatcher - format string |
[18 Feb 2005] DSA-687-1 bidwatcher - format string |
| 99 |
{CAN-2005-0158} |
{CAN-2005-0158} |
| 100 |
- bidwatcher 1.3.17-1 |
- bidwatcher 1.3.17-1 |
| 298 |
{CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176} |
{CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176} |
| 299 |
NOTE: unstable not vulnerable according to DSA |
NOTE: unstable not vulnerable according to DSA |
| 300 |
NOTE: DSA was wrong.. |
NOTE: DSA was wrong.. |
| 301 |
- mc (unfixed; bug #295261) |
- mc 1:4.6.0-4.6.1-pre3-1 |
| 302 |
NOTE: not fixed in testing at time of DSA |
NOTE: not fixed in testing at time of DSA |
| 303 |
[13 Jan 2005] DSA-638-1 gopher - several |
[13 Jan 2005] DSA-638-1 gopher - several |
| 304 |
{CAN-2004-0560 CAN-2004-0561} |
{CAN-2004-0560 CAN-2004-0561} |
| 428 |
- hpsockd 0.14 |
- hpsockd 0.14 |
| 429 |
[01 Dec 2004] DSA-603-1 openssl - insecure temporary file |
[01 Dec 2004] DSA-603-1 openssl - insecure temporary file |
| 430 |
{CAN-2004-0975} |
{CAN-2004-0975} |
| 431 |
- openssl 0.9.7e-1 |
- openssl 0.9.7e-3 |
| 432 |
[29 Nov 2004] DSA-602-1 libgd2 - integer overlow |
[29 Nov 2004] DSA-602-1 libgd2 - integer overlow |
| 433 |
{CAN-2004-0941 CAN-2004-0990} |
{CAN-2004-0941 CAN-2004-0990} |
| 434 |
NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new |
NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new |
| 730 |
{CAN-2004-0522} |
{CAN-2004-0522} |
| 731 |
- gallery 1.4.3-pl2-1 |
- gallery 1.4.3-pl2-1 |
| 732 |
[30 May 2004] DSA-511 ethereal - buffer overflows |
[30 May 2004] DSA-511 ethereal - buffer overflows |
| 733 |
{CAN-2004-0176 |
{CAN-2004-0176} |
| 734 |
- ethereal 0.10.3-1 |
- ethereal 0.10.3-1 |
| 735 |
[29 May 2004] DSA-510 jftpgw - format string |
[29 May 2004] DSA-510 jftpgw - format string |
| 736 |
{CAN-2004-0448} |
{CAN-2004-0448} |