/[secure-testing]/data/DSA/list
ViewVC logotype

Diff of /data/DSA/list

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 452 by joeyh, Sat Feb 19 18:25:41 2005 UTC revision 858 by jmm-guest, Tue Apr 19 11:03:01 2005 UTC
# Line 1  Line 1 
1    [19 Apr 2005] DSA-711-1 info2www - missing input sanitising
2            {CAN-2004-1341}
3            - info2www 1.2.2.9-23
4            NOTE: fixed in testing in time of DSA
5    [18 Apr 2005] DSA-710-1 gtkhtml - null pointer dereference
6            {CAN-2003-0541}
7            - gtkhtml 1.0.4-6.2
8            NOTE: fixed in testing at time of DSA
9    [15 Apr 2005] DSA-709-1 libexif - buffer overflow
10            {CAN-2005-0664}
11            - libexif 0.6.9-5
12    [15 Apr 2005] DSA-708-1 php3 - missing input sanitising
13            {CAN-2005-0525}
14            - php3 3.0.18-31
15    [13 Apr 2005] DSA-707-1 mysql - several
16            {CAN-2004-0957 CAN-2005-0709 CAN-2005-0710 CAN-2005-0711}
17            - mysql-dfsg 4.0.24-5
18            - mysql-dfsg-4.1 4.1.10a-6
19            NOTE: not fixed in testing at time of DSA
20    [13 Apr 2005] DSA-706-1 axel - buffer overflow
21            {CAN-2005-0390}
22            - axel 1.0b-1
23            NOTE: fixed in testing in time of DSA
24    [04 Apr 2005] DSA-705-1 wu-ftpd - missing input sanitising
25            {CAN-2005-0256 CAN-2003-0854}
26            - wu-ftpd 2.6.2-19
27    [04 Apr 2005] DSA-704-1 remstats - tempfile, missing input sanitising
28            {CAN-2005-0387 CAN-2005-0388}
29            - remstats 1.0.13a-5
30            NOTE: not fixed in testing at time of DSA
31    [01 Apr 2005] DSA-703-1 krb5 - buffer overflows
32            {CAN-2005-0468 CAN-2005-0469}
33            - krb5 1.3.6-1
34    [01 Apr 2005] DSA-702-1 imagemagick - several
35            {CAN-2005-0397 CAN-2005-0759 CAN-2005-0760 CAN-2005-0762}
36            - imagemagick 6.0.6.2-2.2
37    [31 Mar 2005] DSA-701-1 samba - integer overflows
38            {CAN-2004-1154}
39            - samba 3.0.10-1
40    [30 Mar 2005] DSA-700-1 mailreader - missing input sanitising
41            {CAN-2005-0386}
42            - mailreader 2.3.29-11
43            NOTE: not fixed in testing at time of DSA
44    [29 Mar 2005] DSA-699-1 netkit-telnet-ssl - buffer overflow
45            {CAN-2005-0469}
46            - netkit-telnet-ssl 0.17.24+0.1-7.1
47            NOTE: not fixed in testing at time of DSA
48    [29 Mar 2005] DSA-698-1 mc - buffer overflow
49            {CAN-2005-0763}
50            NOTE: Not clear which unstable/testing version fixed this,
51            NOTE: but advisory says it's fixed.
52    [29 Mar 2005] DSA-697-1 netkit-telnet - buffer overflow
53            {CAN-2005-0469}
54            - netkit-telnet 0.17-28
55            NOTE: not fixed in testing at time of DSA
56    [22 Mar 2005] DSA-696-1 perl - design flaw
57            {CAN-2005-0448}
58            - perl 5.8.4-8
59            NOTE: fixed in testing at time of DSA
60    [21 Mar 2005] DSA-695-1 xli - buffer overflow, input sanitising, integer overflow
61            {CAN-2001-0775 CAN-2005-0638 CAN-2005-0639}
62            - xli 1.17.0-18
63            NOTE: not fixed in testing at time of DSA
64    [21 Mar 2005] DSA-694-1 xloadimage - missing input sanitising, integer overflow
65            {CAN-2005-0638 CAN-2005-0639}
66            - xloadimage 4.1-14.2
67            NOTE: not fixed in testing at time of DSA
68    [14 Mar 2005] DSA-693-1 luxman - buffer overflow
69            {CAN-2005-0385}
70            NOTE: not fixed in testing at time of DSA
71            NOTE: not in unstable at time of DSA though DSA claimed it was
72            - luxman 0.41-20
73    [14 Mar 2005] DSA-662-2 squirrelmail - several
74            NOTE: only an update to a prior DSA, did not affct sid/sarge.
75    [08 Mar 2005] DSA-692-1 kppp - design flaw
76            {CAN-2005-0205}
77            - kppp 4:3.1.6
78            NOTE: fixed in testing at time of DSA
79    [07 Mar 2005] DSA-691-1 abuse - several
80            {CAN-2005-0098 CAN-2005-0099}
81            NOTE: not in unstable/testing
82    [25 Feb 2005] DSA-690-1 bsmtpd - missing input sanitising
83            {CAN-2005-0107}
84            - bsmtpd 2.3pl8b-16
85            NOTE: not fixed in testing at time of DSA
86    [23 Feb 2005] DSA-689-1 libapache-mod-python - missing input sanitising
87            {CAN-2005-0088}
88            - libapache-mod-python 2.7.10-4
89            NOTE: fixed in testing at time of DSA
90            - libapache2-mod-python 3.1.3-3
91            NOTE: fixed in testing at time of DSA
92    [23 Feb 2005] DSA-688-1 squid - mising input sanitising
93            {CAN-2005-0446}
94            - squid 2.5.8-3
95            NOTE: fixed in testing at time of DSA
96    [21 Feb 2005] DSA-674-3 mailman - cross-site scripting, directory traversal
97            NOTE: only fixed bug in DSA
98  [18 Feb 2005] DSA-687-1 bidwatcher - format string  [18 Feb 2005] DSA-687-1 bidwatcher - format string
99          {CAN-2005-0158}          {CAN-2005-0158}
100          - bidwatcher 1.3.17-1          - bidwatcher 1.3.17-1
# Line 201  Line 298 
298          {CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176}          {CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176}
299          NOTE: unstable not vulnerable according to DSA          NOTE: unstable not vulnerable according to DSA
300          NOTE: DSA was wrong..          NOTE: DSA was wrong..
301          - mc (unfixed; bug #295261)          - mc 1:4.6.0-4.6.1-pre3-1
302          NOTE: not fixed in testing at time of DSA          NOTE: not fixed in testing at time of DSA
303  [13 Jan 2005] DSA-638-1 gopher - several  [13 Jan 2005] DSA-638-1 gopher - several
304          {CAN-2004-0560 CAN-2004-0561}          {CAN-2004-0560 CAN-2004-0561}
# Line 331  Line 428 
428          - hpsockd 0.14          - hpsockd 0.14
429  [01 Dec 2004] DSA-603-1 openssl - insecure temporary file  [01 Dec 2004] DSA-603-1 openssl - insecure temporary file
430          {CAN-2004-0975}          {CAN-2004-0975}
431          - openssl 0.9.7e-1          - openssl 0.9.7e-3
432  [29 Nov 2004] DSA-602-1 libgd2 - integer overlow  [29 Nov 2004] DSA-602-1 libgd2 - integer overlow
433          {CAN-2004-0941 CAN-2004-0990}          {CAN-2004-0941 CAN-2004-0990}
434          NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new          NOTE: different from fixes from earlier DSA for these CANs; 2004-0941 new
# Line 633  Line 730 
730          {CAN-2004-0522}          {CAN-2004-0522}
731          - gallery 1.4.3-pl2-1          - gallery 1.4.3-pl2-1
732  [30 May 2004] DSA-511 ethereal - buffer overflows  [30 May 2004] DSA-511 ethereal - buffer overflows
733          {CAN-2004-0176          {CAN-2004-0176}
734          - ethereal 0.10.3-1          - ethereal 0.10.3-1
735  [29 May 2004] DSA-510 jftpgw - format string  [29 May 2004] DSA-510 jftpgw - format string
736          {CAN-2004-0448}          {CAN-2004-0448}

Legend:
Removed from v.452  
changed lines
  Added in v.858

  ViewVC Help
Powered by ViewVC 1.1.5