/[secure-testing]/data/ospu-candidates.txt
ViewVC logotype

Diff of /data/ospu-candidates.txt

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 10034 by jmm-guest, Tue Oct 7 21:19:21 2008 UTC revision 14606 by jmm-guest, Wed May 5 19:42:44 2010 UTC
# Line 3  but which could be fixed in a stable poi Line 3  but which could be fixed in a stable poi
3  it. If someone wants to address these, please add a note about it  it. If someone wants to address these, please add a note about it
4  and get in contact with debian-release@lists.debian.org  and get in contact with debian-release@lists.debian.org
5    
6    
7  --  --
8    
9  chillispot  abcm2ps (no CVE)
10  #500181  #577014
11  notified maintainer  
12    
13  --  --
14    
15  aegis  acidbase (CVE-2009-4590, CVE-2009-4591, CVE-2009-4592)
 #496400  
16  notified maintainer  notified maintainer
17    
18  --  --
19    
20  apertium  acl (CVE-2009-4411)
21  #496395  #499076
22  notified maintainer  notified maintainer
23    
24  --  --
25    
26  audacity (CVE-2007-6061)  asterisk (CVE-2009-0041)
27  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=453283  #513413
28    notified maintainer
29    
30    asterisk (CVE-2008-3903)
31    #522528
32  notified maintainer  notified maintainer
33    
34  --  --
35    
36  audiolink  avahi (CVE-2009-0758)
37  #496433  #517683
38  notified maintainer  notified maintainer
39    
40  --  --
41    
42  aview  babel (CVE-2009-3736)
43  #496422  #559843
44  notified maintainer  notified maintainer
45    
46  --  --
47    
48  beagle (CVE-2005-4791)  bugzilla (CVE-2009-0481 to CVE-2009-0485)
49  notified maintainer  notified maintainer
50    
51  --  --
52    
53  blam (CVE-2005-4791)  buildbot (CVE-2009-2959, CVE-2009-2967)
54    #543822
55  notified maintainer  notified maintainer
56    
57  --  --
58    
59  boost (CVE-2008-0172/CVE-2008-0171)  compiz-fusion-plugins-main (CVE-2008-6514)
 #461236  
60  notified maintainer  notified maintainer
61    
62  --  --
63    
64  bugzilla (CVE-2008-2103)  cpio (CVE-2010-0624)
 #480190  
65  notified maintainer  notified maintainer
66    
67  --  --
68    
69  byacc (CVE-2008-3196)  couchdb (CVE-2010-0009)
70  #491182  #576304
 notified maintainer  
71    
72  --  --
73    
74  bzip2 (CVE-2008-1372)  cron: Incomplete fix for CVE-2006-2607 (setgid() and initgroups() not checked
75  #471670  #528434
76  Maintainer has been notified  notified maintainer
77    
78  --  --
79    
80  cdcontrol  cups (CVE-2009-3553)
81  #496438  #557740
82    maintainer notified in initial bug report
83    Initial patch was incomplete;
84    
85    cups (CVE-2010-0302)
86    #572940
87  notified maintainer  notified maintainer
88    
89  --  --
90    
91  cdrw-taper  devil (CVE-2009-3994)
92  #496380  #560080
93  notified maintainer  notified maintainer
94    
95  --  --
96    
97  cecilia (CVE-2008-1832)  dopewars (CVE-2009-3591)
98  #476321  #550913
99  notified maintainer  notified maintainer
100    
101  --  --
102    
103  comix (CVE-2008-1568)  dstat (CVE-2009-3894)
104  #462840  http://svn.rpmforge.net/svn/trunk/tools/dstat/ChangeLog
105    notified maintainer
106    
107    dstat (CVE-2009-4081)
108    #559667
109  notified maintainer  notified maintainer
110    
111  --  --
112    
113  crossfire-maps  evolution (CVE-2009-1631)
114  #496358  #526409
115  maintainer doesn't want to fix that, looking at the actual bug I also  notified maintainer through initial bugreport
 think an update is overkill  
116    
117  --  --
118    
119  digitaldj  fcron (CVE-2010-0791)
120  #496399  #572587
121  notified maintainer  notified maintainer through initial bugreport
122    
123  --  --
124    
125  dist  imp4 (CVE-2010-0463)
126  #496412  #569661
 package has been uploaded  
127    
128  --  --
129    
130  emacs21 (CVE-2007-6109/CVE-2008-1694)  libgnucrypto-java (CVE-2008-5659)
131  bug #455433, bug #476612  #559789
132  notified maintainer  removed
133    
134  emacs21 (CVE-2008-2142)  --
135  bug #480877  
136    gnutls26 (CVE-2009-1417)
137    #531614
138  notified maintainer  notified maintainer
139    
140  --  --
141    
142  emacs-jabber  gri (no CVE)
143  #496428  fixed in gri 2.12.18-1:
144    "Improve security when creating temporary files."
145  notified maintainer  notified maintainer
146    
147  --  --
148    
149  emacspeak (CVE-2008-4191)  gupnp (CVE-2009-2174)
150  #496431  #534594
151  notified maintainer  notified maintainer
152    
153  --  --
154    
155  exiv2 (CVE-2008-2696)  htmldoc (CVE-2009-3050)
156  bug #486328  #537637
157  http://dev.robotbattle.com/cgi-bin/viewvc.cgi/exiv2/trunk/src/nikonmn.cpp?r1=1473&r2=1499  notified maintainer through initial bugreport
 notified maintainer  
158    
159  --  --
160    
161  flac123 (CVE-2007-3507)  hypre (CVE-2009-3736)
162    #559834
163  notified maintainer  notified maintainer
164    
165  --  --
166    
167  fml  iceweasel (CVE-2009-0777)
168  #496370  #576466
169  notified maintainer  notified maintainer
170    
171  --  --
172    
173  freeradius (CVE-2008-4474)  kde4libs (CVE-2009-2702)
174  #496489  #546218
175    notified maintainer
176    
177    kde4libs (CVE-2009-0689)
178    notified maintainer
179    
180  --  --
181    
182  fwbuilder  kfreebsd-6
183  #496406  [freebsd Missing permission check on SIOCSIFINFO_IN6 ioctl]
184    http://security.freebsd.org/advisories/FreeBSD-SA-09:10.ipv6.asc
185    notified maintainer
186    
187    [freebsd Local information disclosure via direct pipe writes] (CVE-2009-1935)
188    http://security.freebsd.org/advisories/FreeBSD-SA-09:09.pipe.asc
189  notified maintainer  notified maintainer
190    
191  --  --
192    
193  gdrae  kfreebsd-7
194  #496378  [freebsd Missing permission check on SIOCSIFINFO_IN6 ioctl]
195    http://security.freebsd.org/advisories/FreeBSD-SA-09:10.ipv6.asc
196    notified maintainer
197    
198    [freebsd Local information disclosure via direct pipe writes] (CVE-2009-1935)
199    http://security.freebsd.org/advisories/FreeBSD-SA-09:09.pipe.asc
200  notified maintainer  notified maintainer
201    
202  --  --
203    
204  gpsdrive  kvm 82-1 (CVE-2008-5714)
205  #496436  #509997
206  notified maintainer  notified maintainer
207    
208  --  --
209    
210  ipsec-tools (CVE-2008-3651)  lcms (CVE-2009-0793)
211  http://sourceforge.net/mailarchive/forum.php?thread_name=48a0c7a0.qPeWZAE0PY8bDDq%2B%25olel%40ans.pl&forum_name=ipsec-tools-devel  notified maintainer through initial bugreport
 notified maintainer  
212    
213  --  --
214    
215  jumpnbump (no CVE yet)  libesmtp (CVE-2010-1192)
216  #500611  #572960
 notified maintainer  
217    
218  --  --
219    
220  konwert  libnss-db (CVE-2010-0826)
221  #496379  #577057
 notified maintainer  
222    
223  --  --
224    
225  libapache2-mod-perl2 (CVE-2007-1349)  libpam-ssh (CVE-2009-1273)
226  http://svn.apache.org/viewvc?view=rev&revision=521584  #535877
227  #433549  maintainer notified through initial bug report, said he would work on an update
 notified maintainer  
228    
229  --  --
230    
231  libpam-ssh (CVE-2007-0844)  libpng (CVE-2009-2042)
232  #410236  #533676
233  notified maintainer  notified maintainer
234    
235    CVE-2010-0205
236    #572308
237    
238  --  --
239    
240  libpng (CVE-2008-1382)  libsndfile
241  #476669  potential dos via crafted input
242    #530831
243  notified maintainer  notified maintainer
244    
245  --  --
246    
247  liferea (CVE-2005-4791)  libvorbis (CVE-2008-2009)
248  notified maintainer  notified maintainer and release team
249    
250  --  --
251    
252  lighttpd (CVE-2007-3948)  libstruts1.2-java (CVE-2008-2025)
253  #434888  #528352
 Was accidentally omitted during DSA 1362, but doesn't warrant a DSA on it's own.  
 http://trac.lighttpd.net/trac/changeset/1873?format=diff&new=1873  
 http://trac.lighttpd.net/trac/ticket/1216  
254  notified maintainer  notified maintainer
255    
256  --  --
257    
258  links2 (CVE-2008-3329)  linux-ftpd: null ptr dereference
259  bug #492744  #572813
260  notified maintainer  notified maintainer
261    
262  --  --
263    
264  linux-ftpd-ssl (CVE-2007-6263)  logrotate [logrotate race condition could lead to file disclosure]
265  #454733  Fixed in sid in 3.7.8-4
 notified maintainer  
266    
267  --  --
268    
269  mecab (CVE-2007-3231)  makepasswd (no CVE ID)
270  #429174  #564559
271  notified maintainer  notified maintainer
272    
273  --  --
274    
275  mercurial (CVE-2008-4297)  maradns
276  #500781  http://maradns.org/download/maradns-1.4.02-parse_segfault.patch
277  notified maintainer  notified maintainer
278    
279  --  --
280    
281  mgetty  memcached (CVE-2009-1255)
 #496403  
282  notified maintainer  notified maintainer
283    
284  --  --
285    
286  mgt  mimedecode
287  #496434  potential dos/crash due to invalid input
288  notified maintainer  orphaned
289    #530430
290    
291  --  --
292    
293  mksh (CVE-2008-1845)  mpg123 (CVE-2009-1301)
294  notified maintainer  notified maintainer
295    
296  --  --
297    
298  mldonkey (CVE-2007-4100)  nano (CVE-2010-1160, CVE-2010-1161)
299  #435439  #577817
 notified maintainer  
300    
301  --  --
302    
303  mnogosearch (CVE-2007-5588)  neon27 (CVE-2009-2474)
304  #447753  #542926
305  notified maintainer  notified maintainer
306    
307  --  --
308    
309  myspell  neon26 (CVE-2009-2474)
310  #496392  #542926
311  notified maintainer  notified maintainer
312    
313  ---  --
314    
315    network-manager-applet (CVE-2009-4144)
316    #560067
317    notified maintainer through initial bugreport
318    
319  ngircd (CVE-2008-0285)  CVE-2009-4145
320  notified maintainer  #563371
321    notified maintainer through initial bugreport
322    
323  --  --
324    
325  nvi  ntop (CVE-2009-2732)
326  #496462  #543312
327  notified maintainer  notified maintainer through initial bugreport
328    
329  --  --
330    
331  paramiko (CVE-2008-0299)  postfix (CVE-2009-2939)
 #460706  
332  notified maintainer  notified maintainer
333    
334  --  --
335    
336  python-django (CVE-2007-5712)  squid (CVE-2009-0801)
337  http://media.djangoproject.com/patches/2007-10-26-security-fix/  #521053
 #448838  
338  notified maintainer  notified maintainer
339    
340  --  --
341    
342  r-base  squid3 (CVE-2009-0801)
343  #496418  #521052
344  notified maintainer  notified maintainer
345    
346  --  --
347    
348  rancid  t-prot (CVE-2009-4404)
 #496426  
349  notified maintainer  notified maintainer
350    
351  --  --
352    
353  rccp  net-snmp (CVE-2008-6123)
354  #496364  Noah will see to it.
 notified maintainer  
355    
356  --  --
357    
358  realtimebattle  ocsinventory-server (CVE-2009-3040, CVE-2009-3042, CVE-2009-1443)
359  #496385  #541995
360  notified maintainer  notified maintainer
361    
362  --  --
363    
364  redhat-cluster  openldap
365  #496410  #253838
366  notified maintainer  notified maintainer
367    
368  --  --
369    
370  rkhunter  openssl (CVE-2009-3245)
 #496375  
371  notified maintainer  notified maintainer
372    
373  --  --
374    
375  rsync (CVE-2007-6200)  overkill (no CVE yet)
376  #453652  #549310
 notified maintainer  
377    
378  --  --
379    
380  sabre  owl (CVE-2009-0363)
381  #433996  #515118
382  notified maintainer  notified maintainer
383    
384  --  --
385    
386  scilab  pam (CVE-2009-0579)
387  #496414  #514437
388  notified maintainer  asked maintainer in mail
389    
390  --  --
391    
392  sgml2x  pidgin (CVE-2009-1889, CVE-2009-3083, CVE-2009-3084, CVE-2009-3085)
393  #496368  #535790
394    http://developer.pidgin.im/ticket/9483
395    http://developer.pidgin.im/viewmtn/revision/info/9bac0a540156fb1848eedd61c8630737dee752c7
396  notified maintainer  notified maintainer
397    
398  --  --
399    
400  sip-tester (CVE-2008-1959, CVE-2008-2085)  pptp-linux (no CVE)
401  #479039  #523476
402  notified maintainer  Ola will prepare a fix in a point update
403    
404  --  --
405    
406  slocate (CVE-2007-0227)  puppet (CVE-2009-3564)
407  #411937  #551073
408    notified maintainer in initial bug report
409    
410    CVE-2010-0156
411    #https://bugzilla.redhat.com/show_bug.cgi?id=502881
412  notified maintainer  notified maintainer
413    
414  --  --
415    
416  smb4k (CVE-2007-0475, CVE-2007-0474, CVE-2007-0473, CVE-2007-0472)  python-4suite (CVE-2009-3560, CVE-2009-3720)
417    #560914
418  notified maintainer  notified maintainer
419    
420  --  --
421    
422  sng  rails (CVE-2009-3086)
423  #496407  bug #545063
424  notified maintainer  notified maintainer
425    
426  --  --
427    
428  ssmtp  shibboleth-sp2: world-readable key (no CVE)
429  #498366  #571631
430  notified maintainer  notified maintainer through bugreport
431    
432  --  --
433    
434  streamripper (CVE-2007-4337)  slim (CVE-2009-1756)
435  notified maintainer  bug #529306
436    Maintainer notified through followup in #529306
437    
438  --  --
439    
440  sylpheed (CVE-2007-2958)  squid (CVE-2010-0639)
441  #441854  #572553
442  http://www.colino.net/claws-mail/getpatchset.php3?ver=2.10.0cvs153 fixes the bug  Maintainer notified through initial bugreport
 notified maintainer  
443    
444  --  --
445    
446  sympa  squid3 (CVE-2010-0639)
447  #496405; bug #494969  #572554
448  notified maintainer  Maintainer notified through initial bugreport
449    
450  --  --
451    
452  tintin++ (CVE-2008-0673 CVE-2008-0672 CVE-2008-0671)  sqlite
453  #465643  #566326
 notified maintainer  
454    
455  --  --
456    
457  tomboy (CVE-2005-4790)  tau (CVE-2008-5157)
458    #506348
459  notified maintainer  notified maintainer
460    
461  --  --
462    
463  xmcd  texlive-bin (CVE-2010-0739, CVE-2010-0827)
 #496416  
464  notified maintainer  notified maintainer
465    
466  --  --
467    
468  vobcopy (CVE-2007-5718)  trac (CVE-2009-4405)
 bug #448319  
 notified maintainer  
469    
470  --  --
471    
472  wdiff [insecure tempfile in wdiff]  udev (#462655)
 bug #425254  
473  notified maintainer  notified maintainer
474    
475  --  --
476    
477  wims  planet (CVE-2009-2937)
478  #496387  bug #546178
479  notified maintainer  notified maintainer through initial bugreport
480    
481  --  --
482    
483  wyrd (CVE-2008-0806)  webkit (CVE-2008-4724)
484  bug #466382  #520052
485  notified maintainer  asked maintainer
486    
487  --  --
488    
489  xastir  xemacs21 (CVE-2008-2142)
490  #496383  bug #480877
491    notified maintainer
492    
493    xemacs21 (CVE-2009-2688)
494    #540470
495    Patches at https://bugzilla.redhat.com/show_bug.cgi?id=511994
496  notified maintainer  notified maintainer
497    
498  --  --
499    
500  xcal  xen-3 (CVE-2008-4993)
501  #496393  #496367
502  notified maintainer  notified maintainer
503    
504  --  --
505    
506  xemacs21 (CVE-2007-6109/CVE-2008-1694)  xerces-c2 (CVE-2009-1885)
507  bug #457764, bug #476613  #541986
508  notified maintainer  notified maintainer
509    
510  xemacs21 (CVE-2008-2142)  --
511  bug #480877  
512    xfig
513    25_mkstemp added in 1:3.2.5.a-1
514  notified maintainer  notified maintainer
515    
516    CVE-2009-4228/CVE-2009-4227
517    #559274)
518    https://bugzilla.redhat.com/show_bug.cgi?id=543905
519    
520  --  --
521    
522  xen-3  xmp (CVE-2007-6731, CVE-2007-6732)
523  #496367  #546730
524  notified maintainer  notified maintainer
525    
526  --  --
527    
528  xfce4 (CVE-2007-6351 CVE-2007-6352)  xserver-xorg (no CVE)
529    #555308
530    
531    --
532    
533    ytnef (CVE-2009-3887, CVE-2009-3721)
534  notified maintainer  notified maintainer
535    
536  --  --
537    
538  zabbix (CVE-2008-1353)  ziproxy (CVE-2009-0804)
539  bug #471678  #521051
540  notified maintainer  notified maintainer
541    
542  --  --
543    
544  zsh (CVE-2007-6209)  zope2.10 (no CVE)
545  bug #454073)  https://mail.zope.org/pipermail/zope-announce/2010-January/002229.html
546    
547    --
548    
549    zoph (CVE-2008-6838, CVE-2008-6837, CVE-2009-2343)
550    http://sourceforge.net/tracker/?func=detail&aid=2815898&group_id=69353&atid=524249
551    http://sourceforge.net/project/shownotes.php?group_id=69353&release_id=694128
552  notified maintainer  notified maintainer
553    

Legend:
Removed from v.10034  
changed lines
  Added in v.14606

  ViewVC Help
Powered by ViewVC 1.1.5