/[secure-testing]/data/ospu-candidates.txt
ViewVC logotype

Diff of /data/ospu-candidates.txt

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 12571 by derevko-guest, Tue Aug 11 20:45:32 2009 UTC revision 14420 by jmm-guest, Tue Apr 6 21:52:24 2010 UTC
# Line 3  but which could be fixed in a stable poi Line 3  but which could be fixed in a stable poi
3  it. If someone wants to address these, please add a note about it  it. If someone wants to address these, please add a note about it
4  and get in contact with debian-release@lists.debian.org  and get in contact with debian-release@lists.debian.org
5    
6    
7    --
8    
9    acidbase (CVE-2009-4590, CVE-2009-4591, CVE-2009-4592)
10    notified maintainer
11    
12    --
13    
14    acl (CVE-2009-4411)
15    #499076
16    notified maintainer
17    
18  --  --
19    
20  asterisk (CVE-2009-0041)  asterisk (CVE-2009-0041)
21  #513413  #513413
22  notified maintainer  notified maintainer
23    
24  CVE-2008-3903  asterisk (CVE-2008-3903)
25  #522528  #522528
26  notified maintainer  notified maintainer
27    
# Line 21  notified maintainer Line 33  notified maintainer
33    
34  --  --
35    
36    babel (CVE-2009-3736)
37    #559843
38    notified maintainer
39    
40    --
41    
42  bugzilla (CVE-2009-0481 to CVE-2009-0485)  bugzilla (CVE-2009-0481 to CVE-2009-0485)
43  notified maintainer  notified maintainer
44    
45  --  --
46    
47    buildbot (CVE-2009-2959, CVE-2009-2967)
48    #543822
49    notified maintainer
50    
51    --
52    
53  compiz-fusion-plugins-main (CVE-2008-6514)  compiz-fusion-plugins-main (CVE-2008-6514)
54  notified maintainer  notified maintainer
55    
56  --  --
57    
58    cpio (CVE-2010-0624)
59    notified maintainer
60    
61    --
62    
63  cron: Incomplete fix for CVE-2006-2607 (setgid() and initgroups() not checked  cron: Incomplete fix for CVE-2006-2607 (setgid() and initgroups() not checked
64  #528434  #528434
65  notified maintainer  notified maintainer
66    
67  --  --
68    
69    cups (CVE-2009-3553)
70    #557740
71    maintainer notified in initial bug report
72    Initial patch was incomplete;
73    
74    cups (CVE-2010-0302)
75    #572940
76    notified maintainer
77    
78    --
79    
80    devil (CVE-2009-3994)
81    #560080
82    notified maintainer
83    
84    --
85    
86    dopewars (CVE-2009-3591)
87    #550913
88    notified maintainer
89    
90    --
91    
92    dstat (CVE-2009-3894)
93    http://svn.rpmforge.net/svn/trunk/tools/dstat/ChangeLog
94    notified maintainer
95    
96    dstat (CVE-2009-4081)
97    #559667
98    notified maintainer
99    
100    --
101    
102  evolution (CVE-2009-1631)  evolution (CVE-2009-1631)
103  #526409  #526409
104  notified maintainer through initial bugreport  notified maintainer through initial bugreport
105    
106  --  --
107    
108  firebird2.0 (CVE-2009-2620)  fcron (CVE-2010-0791)
109  #539477  #572587
110    notified maintainer through initial bugreport
111    
112    --
113    
114    libgnucrypto-java (CVE-2008-5659)
115    #559789
116    removed
117    
118  --  --
119    
# Line 54  notified maintainer Line 123  notified maintainer
123    
124  --  --
125    
126    gri (no CVE)
127    fixed in gri 2.12.18-1:
128    "Improve security when creating temporary files."
129    notified maintainer
130    
131    --
132    
133    gupnp (CVE-2009-2174)
134    #534594
135    notified maintainer
136    
137    --
138    
139    htmldoc (CVE-2009-3050)
140    #537637
141    notified maintainer through initial bugreport
142    
143    --
144    
145    hypre (CVE-2009-3736)
146    #559834
147    notified maintainer
148    
149    --
150    
151    iceweasel (CVE-2009-0777)
152    #576466
153    notified maintainer
154    
155    --
156    
157    kde4libs (CVE-2009-2702)
158    #546218
159    notified maintainer
160    
161    kde4libs (CVE-2009-0689)
162    notified maintainer
163    
164    --
165    
166  kfreebsd-6  kfreebsd-6
167  [freebsd Missing permission check on SIOCSIFINFO_IN6 ioctl]  [freebsd Missing permission check on SIOCSIFINFO_IN6 ioctl]
168  http://security.freebsd.org/advisories/FreeBSD-SA-09:10.ipv6.asc  http://security.freebsd.org/advisories/FreeBSD-SA-09:10.ipv6.asc
# Line 87  notified maintainer through initial bugr Line 196  notified maintainer through initial bugr
196    
197  --  --
198    
199    libesmtp (CVE-2010-1192)
200    #572960
201    
202    --
203    
204    libpam-ssh (CVE-2009-1273)
205    #535877
206    maintainer notified through initial bug report, said he would work on an update
207    
208    --
209    
210  libpng (CVE-2009-2042)  libpng (CVE-2009-2042)
211  #533676  #533676
212  notified maintainer  notified maintainer
213    
214    CVE-2010-0205
215    #572308
216    
217  --  --
218    
219  libsndfile  libsndfile
220  potential dos via crafted input  potential dos via crafted input
221  #530831  #530831
222    notified maintainer
223    
224  --  --
225    
# Line 104  notified maintainer and release team Line 228  notified maintainer and release team
228    
229  --  --
230    
231    libstruts1.2-java (CVE-2008-2025)
232    #528352
233    notified maintainer
234    
235    --
236    
237    linux-ftpd: null ptr dereference
238    #572813
239    notified maintainer
240    
241    --
242    
243    makepasswd (no CVE ID)
244    #564559
245    notified maintainer
246    
247    --
248    
249    maradns
250    http://maradns.org/download/maradns-1.4.02-parse_segfault.patch
251    notified maintainer
252    
253    --
254    
255  memcached (CVE-2009-1255)  memcached (CVE-2009-1255)
256  notified maintainer  notified maintainer
257    
# Line 121  notified maintainer Line 269  notified maintainer
269    
270  --  --
271    
272    neon27 (CVE-2009-2474)
273    #542926
274    notified maintainer
275    
276    --
277    
278    neon26 (CVE-2009-2474)
279    #542926
280    notified maintainer
281    
282    --
283    
284    network-manager-applet (CVE-2009-4144)
285    #560067
286    notified maintainer through initial bugreport
287    
288    CVE-2009-4145
289    #563371
290    notified maintainer through initial bugreport
291    
292    --
293    
294    ntop (CVE-2009-2732)
295    #543312
296    notified maintainer through initial bugreport
297    
298    --
299    
300    postfix (CVE-2009-2939)
301    notified maintainer
302    
303    --
304    
305  squid (CVE-2009-0801)  squid (CVE-2009-0801)
306  #521053  #521053
307    notified maintainer
308    
309  --  --
310    
311  squid3 (CVE-2009-0801)  squid3 (CVE-2009-0801)
312  #521052  #521052
313    notified maintainer
314    
315  --  --
316    
317  stardict (CVE-2009-2260)  t-prot (CVE-2009-4404)
 #534731  
318  notified maintainer  notified maintainer
319    
320  --  --
# Line 142  Noah will see to it. Line 324  Noah will see to it.
324    
325  --  --
326    
327    ocsinventory-server (CVE-2009-3040, CVE-2009-3042, CVE-2009-1443)
328    #541995
329    notified maintainer
330    
331    --
332    
333  openldap  openldap
334  #253838  #253838
335  notified maintainer  notified maintainer
336    
337  --  --
338    
339    openssl (CVE-2009-3245)
340    notified maintainer
341    
342    --
343    
344    overkill (no CVE yet)
345    #549310
346    
347    --
348    
349    owl (CVE-2009-0363)
350    #515118
351    notified maintainer
352    
353    --
354    
355  pam (CVE-2009-0579)  pam (CVE-2009-0579)
356  #514437  #514437
357  asked maintainer in mail  asked maintainer in mail
358    
359  --  --
360    
361    pidgin (CVE-2009-1889, CVE-2009-3083, CVE-2009-3084, CVE-2009-3085)
362    #535790
363    http://developer.pidgin.im/ticket/9483
364    http://developer.pidgin.im/viewmtn/revision/info/9bac0a540156fb1848eedd61c8630737dee752c7
365    notified maintainer
366    
367    --
368    
369  pptp-linux (no CVE)  pptp-linux (no CVE)
370  #523476  #523476
371  Ola will prepare a fix in a point update  Ola will prepare a fix in a point update
372    
373  --  --
374    
375    puppet (CVE-2009-3564)
376    #551073
377    notified maintainer in initial bug report
378    
379    CVE-2010-0156
380    #https://bugzilla.redhat.com/show_bug.cgi?id=502881
381    notified maintainer
382    
383    --
384    
385    python-4suite (CVE-2009-3560, CVE-2009-3720)
386    #560914
387    notified maintainer
388    
389    --
390    
391    rails (CVE-2009-3086)
392    bug #545063
393    notified maintainer
394    
395    --
396    
397    shibboleth-sp2: world-readable key (no CVE)
398    #571631
399    notified maintainer through bugreport
400    
401    --
402    
403  slim (CVE-2009-1756)  slim (CVE-2009-1756)
404  bug #529306  bug #529306
405  Maintainer notified through followup in #529306  Maintainer notified through followup in #529306
406    
407  --  --
408    
409  smarty (CVE-2009-1669)  squid (CVE-2010-0639)
410  #529810  #572553
411  http://groups.google.com/group/smarty-svn/browse_thread/thread/b2da2e5d1ef8b462  Maintainer notified through initial bugreport
412  notified maintainer  
413    --
414    
415    squid3 (CVE-2010-0639)
416    #572554
417    Maintainer notified through initial bugreport
418    
419    --
420    
421    sqlite
422    #566326
423    
424  --  --
425    
# Line 179  notified maintainer Line 429  notified maintainer
429    
430  --  --
431    
432  texlive-bin (CVE-2009-1284)  udev (#462655)
433  #520920  notified maintainer
 https://bugzilla.redhat.com/show_bug.cgi?id=492136  
434    
435  --  --
436    
437  udev (#462655)  planet (CVE-2009-2937)
438  notified maintainer  bug #546178
439    notified maintainer through initial bugreport
440    
441  --  --
442    
# Line 200  xemacs21 (CVE-2008-2142) Line 450  xemacs21 (CVE-2008-2142)
450  bug #480877  bug #480877
451  notified maintainer  notified maintainer
452    
453    xemacs21 (CVE-2009-2688)
454    #540470
455    Patches at https://bugzilla.redhat.com/show_bug.cgi?id=511994
456    notified maintainer
457    
458  --  --
459    
460  xen-3 (CVE-2008-4993)  xen-3 (CVE-2008-4993)
# Line 208  notified maintainer Line 463  notified maintainer
463    
464  --  --
465    
466    xerces-c2 (CVE-2009-1885)
467    #541986
468    notified maintainer
469    
470    --
471    
472  xfig  xfig
473  25_mkstemp added in 1:3.2.5.a-1  25_mkstemp added in 1:3.2.5.a-1
474  notified maintainer  notified maintainer
475    
476    CVE-2009-4228/CVE-2009-4227
477    #559274)
478    https://bugzilla.redhat.com/show_bug.cgi?id=543905
479    
480    --
481    
482    xmp (CVE-2007-6731, CVE-2007-6732)
483    #546730
484    notified maintainer
485    
486    --
487    
488    xserver-xorg (no CVE)
489    #555308
490    
491    --
492    
493    ytnef (CVE-2009-3887, CVE-2009-3721)
494    notified maintainer
495    
496  --  --
497    
498  ziproxy (CVE-2009-0804)  ziproxy (CVE-2009-0804)
499  #521051  #521051
500    notified maintainer
501    
502    --
503    
504    zope2.10 (no CVE)
505    https://mail.zope.org/pipermail/zope-announce/2010-January/002229.html
506    
507    --
508    
509    zoph (CVE-2008-6838, CVE-2008-6837, CVE-2009-2343)
510    http://sourceforge.net/tracker/?func=detail&aid=2815898&group_id=69353&atid=524249
511    http://sourceforge.net/project/shownotes.php?group_id=69353&release_id=694128
512    notified maintainer
513    

Legend:
Removed from v.12571  
changed lines
  Added in v.14420

  ViewVC Help
Powered by ViewVC 1.1.5