/[secure-testing]/data/ospu-candidates.txt
ViewVC logotype

Diff of /data/ospu-candidates.txt

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 12653 by jmm-guest, Fri Aug 21 17:50:45 2009 UTC revision 15243 by jmm-guest, Tue Aug 31 16:20:21 2010 UTC
# Line 3  but which could be fixed in a stable poi Line 3  but which could be fixed in a stable poi
3  it. If someone wants to address these, please add a note about it  it. If someone wants to address these, please add a note about it
4  and get in contact with debian-release@lists.debian.org  and get in contact with debian-release@lists.debian.org
5    
6    
7    --
8    
9    abcm2ps (no CVE)
10    #577014
11    
12    
13    --
14    
15    acidbase (CVE-2009-4590, CVE-2009-4591, CVE-2009-4592)
16    notified maintainer
17    
18    CVE-2009-4839  CVE-2009-4838 CVE-2009-4837
19    maintainer contacted us, notified about spu status
20    
21    --
22    
23    acl (CVE-2009-4411)
24    #499076
25    notified maintainer
26    
27  --  --
28    
29  asterisk (CVE-2009-0041)  asterisk (CVE-2009-0041)
30  #513413  #513413
31  notified maintainer  notified maintainer
32    
33  CVE-2008-3903  asterisk (CVE-2008-3903)
34  #522528  #522528
35  notified maintainer  notified maintainer
36    
# Line 21  notified maintainer Line 42  notified maintainer
42    
43  --  --
44    
45    babel (CVE-2009-3736)
46    #559843
47    notified maintainer
48    
49    --
50    
51  bugzilla (CVE-2009-0481 to CVE-2009-0485)  bugzilla (CVE-2009-0481 to CVE-2009-0485)
52  notified maintainer  notified maintainer
53    
54    CVE-2010-1204
55    notified maintainer through initial bugreport
56    
57  --  --
58    
59  burn: (no CVE yet)  buildbot (CVE-2009-2959, CVE-2009-2967)
60  #542329  #543822
61  notified maintainer through bug report  notified maintainer
62    
63  --  --
64    
# Line 37  notified maintainer Line 67  notified maintainer
67    
68  --  --
69    
70    couchdb (CVE-2010-0009)
71    #576304
72    notified maintainer
73    
74    --
75    
76  cron: Incomplete fix for CVE-2006-2607 (setgid() and initgroups() not checked  cron: Incomplete fix for CVE-2006-2607 (setgid() and initgroups() not checked
77  #528434  #528434
78  notified maintainer  notified maintainer
79    
80  --  --
81    
82    cups (CVE-2009-3553)
83    #557740
84    maintainer notified in initial bug report
85    Initial patch was incomplete;
86    
87    cups (CVE-2010-0302)
88    #572940
89    notified maintainer
90    
91    --
92    
93    devil (CVE-2009-3994)
94    #560080
95    notified maintainer
96    
97    --
98    
99    dopewars (CVE-2009-3591)
100    #550913
101    notified maintainer
102    
103    --
104    
105    dstat (CVE-2009-3894)
106    http://svn.rpmforge.net/svn/trunk/tools/dstat/ChangeLog
107    notified maintainer
108    
109    dstat (CVE-2009-4081)
110    #559667
111    notified maintainer
112    
113    --
114    
115  evolution (CVE-2009-1631)  evolution (CVE-2009-1631)
116  #526409  #526409
117  notified maintainer through initial bugreport  notified maintainer through initial bugreport
118    
119  --  --
120    
121  firebird2.0 (CVE-2009-2620)  exim4 (CVE-2010-2023, CVE-2010-2024)
122  #539477  notified maintainers
123    
124    --
125    
126    fastjar (CVE-2010-0831, CVE-2010-2322)
127    
128    --
129    
130    fcron (CVE-2010-0791)
131    #572587
132    notified maintainer through initial bugreport
133    
134    --
135    
136    imp4 (CVE-2010-0463)
137    #569661
138  notified maintainer  notified maintainer
139    
140  --  --
141    
142    libgnucrypto-java (CVE-2008-5659)
143    #559789
144    removed
145    
146    --
147    
148  gnutls26 (CVE-2009-1417)  gnutls26 (CVE-2009-1417)
149  #531614  #531614
150  notified maintainer  notified maintainer
151    
152  --  --
153    
154    gri (no CVE)
155    fixed in gri 2.12.18-1:
156    "Improve security when creating temporary files."
157    notified maintainer
158    
159    --
160    
161    gupnp (CVE-2009-2174)
162    #534594
163    notified maintainer
164    
165    --
166    
167    htmldoc (CVE-2009-3050)
168    #537637
169    notified maintainer through initial bugreport
170    
171    --
172    
173    hypre (CVE-2009-3736)
174    #559834
175    notified maintainer
176    
177    --
178    
179    iceweasel (CVE-2009-0777)
180    #576466
181    notified maintainer
182    
183    --
184    
185    kde4libs (CVE-2009-2702)
186    #546218
187    notified maintainer
188    
189    kde4libs (CVE-2009-0689)
190    notified maintainer
191    
192    --
193    
194  kfreebsd-6  kfreebsd-6
195  [freebsd Missing permission check on SIOCSIFINFO_IN6 ioctl]  [freebsd Missing permission check on SIOCSIFINFO_IN6 ioctl]
196  http://security.freebsd.org/advisories/FreeBSD-SA-09:10.ipv6.asc  http://security.freebsd.org/advisories/FreeBSD-SA-09:10.ipv6.asc
# Line 94  notified maintainer through initial bugr Line 224  notified maintainer through initial bugr
224    
225  --  --
226    
227    libesmtp (CVE-2010-1192)
228    #572960
229    maintainer contacted us, notified about spu status
230    
231    --
232    
233    libnss-db (CVE-2010-0826)
234    #577057
235    
236    --
237    
238  libpam-ssh (CVE-2009-1273)  libpam-ssh (CVE-2009-1273)
239  #535877  #535877
240  maintainer notified through initial bug report  maintainer notified through initial bug report, said he would work on an update
241    
242  --  --
243    
# Line 106  notified maintainer Line 247  notified maintainer
247    
248  --  --
249    
250    libpoe-component-irc-perl
251    #581194
252    maintainer contacted us
253    
254    --
255    
256  libsndfile  libsndfile
257  potential dos via crafted input  potential dos via crafted input
258  #530831  #530831
259    notified maintainer
260    
261  --  --
262    
# Line 117  notified maintainer and release team Line 265  notified maintainer and release team
265    
266  --  --
267    
268    libstruts1.2-java (CVE-2008-2025)
269    #528352
270    notified maintainer
271    
272    --
273    
274    linux-ftpd: null ptr dereference
275    #572813
276    notified maintainer
277    
278    --
279    
280    logrotate [logrotate race condition could lead to file disclosure]
281    Fixed in sid in 3.7.8-4
282    
283    --
284    
285    makepasswd (no CVE ID)
286    #564559
287    notified maintainer
288    
289    --
290    
291    mako (CVE-2010-2480)
292    http://bugs.python.org/issue9061
293    
294    --
295    
296    mapserver (CVE-2010-3484, CVE-2010-3485)
297    fixed in 5.6.4-1
298    
299    --
300    
301    maradns
302    http://maradns.org/download/maradns-1.4.02-parse_segfault.patch
303    notified maintainer
304    
305    --
306    
307  memcached (CVE-2009-1255)  memcached (CVE-2009-1255)
308  notified maintainer  notified maintainer
309    
# Line 134  notified maintainer Line 321  notified maintainer
321    
322  --  --
323    
324    neon27 (CVE-2009-2474)
325    #542926
326    notified maintainer
327    
328    --
329    
330    neon26 (CVE-2009-2474)
331    #542926
332    notified maintainer
333    
334    --
335    
336    network-manager-applet (CVE-2009-4144)
337    #560067
338    notified maintainer through initial bugreport
339    
340    CVE-2009-4145
341    #563371
342    notified maintainer through initial bugreport
343    
344    --
345    
346    ntop (CVE-2009-2732)
347    #543312
348    notified maintainer through initial bugreport
349    
350    --
351    
352    postfix (CVE-2009-2939)
353    notified maintainer
354    
355    --
356    
357    ruby1.8 (CVE-2010-0541)
358    
359    --
360    
361    ruby1.9 (CVE-2010-0541)
362    
363    --
364    
365  squid (CVE-2009-0801)  squid (CVE-2009-0801)
366  #521053  #521053
367    notified maintainer
368    
369  --  --
370    
371  squid3 (CVE-2009-0801)  squid3 (CVE-2009-0801)
372  #521052  #521052
373    notified maintainer
374    
375  --  --
376    
377  stardict (CVE-2009-2260)  t-prot (CVE-2009-4404)
 #534731  
378  notified maintainer  notified maintainer
379    
380  --  --
# Line 155  Noah will see to it. Line 384  Noah will see to it.
384    
385  --  --
386    
387    ocsinventory-server (CVE-2009-3040, CVE-2009-3042, CVE-2009-1443)
388    #541995
389    notified maintainer
390    
391    --
392    
393  openldap  openldap
394  #253838  #253838
395  notified maintainer  notified maintainer
396    
397  --  --
398    
399    overkill (no CVE yet)
400    #549310
401    
402    --
403    
404    owl (CVE-2009-0363)
405    #515118
406    notified maintainer
407    
408    --
409    
410  pam (CVE-2009-0579)  pam (CVE-2009-0579)
411  #514437  #514437
412  asked maintainer in mail  asked maintainer in mail
413    
414  --  --
415    
416    pidgin (CVE-2009-1889, CVE-2009-3083, CVE-2009-3084, CVE-2009-3085)
417    #535790
418    http://developer.pidgin.im/ticket/9483
419    http://developer.pidgin.im/viewmtn/revision/info/9bac0a540156fb1848eedd61c8630737dee752c7
420    notified maintainer
421    
422    --
423    
424  pptp-linux (no CVE)  pptp-linux (no CVE)
425  #523476  #523476
426  Ola will prepare a fix in a point update  Ola will prepare a fix in a point update
427    
428  --  --
429    
430  slim (CVE-2009-1756)  prewikka (CVE-2010-2058)
431  bug #529306  #584469
432  Maintainer notified through followup in #529306  
433    
434    --
435    
436    puppet (CVE-2009-3564)
437    #551073
438    notified maintainer in initial bug report
439    
440    CVE-2010-0156
441    #https://bugzilla.redhat.com/show_bug.cgi?id=502881
442    notified maintainer
443    
444    --
445    
446    python-4suite (CVE-2009-3560, CVE-2009-3720)
447    #560914
448    notified maintainer
449    
450    
451    --
452    
453    python2.4 (CVE-2010-2089, CVE-2010-1634, CVE-2010-1450, CVE-2010-1449, CVE-2009-4134)
454    
455    
456  --  --
457    
458  smarty (CVE-2009-1669)  python2.5 (CVE-2010-2089, CVE-2010-1634, CVE-2010-1450, CVE-2010-1449, CVE-2009-4134)
459  #529810  
460  http://groups.google.com/group/smarty-svn/browse_thread/thread/b2da2e5d1ef8b462  --
461    
462    rails (CVE-2009-3086)
463    bug #545063
464  notified maintainer  notified maintainer
465    
466  --  --
467    
468    shibboleth-sp2: world-readable key (no CVE)
469    #571631
470    notified maintainer through bugreport
471    
472    --
473    
474    squid (CVE-2010-0639)
475    #572553
476    Maintainer notified through initial bugreport
477    
478    --
479    
480    squid3 (CVE-2010-0639)
481    #572554
482    Maintainer notified through initial bugreport
483    
484    --
485    
486    sqlite
487    #566326
488    
489    --
490    
491  tau (CVE-2008-5157)  tau (CVE-2008-5157)
492  #506348  #506348
493  notified maintainer  notified maintainer
494    
495  --  --
496    
497  texlive-bin (CVE-2009-1284)  trac (CVE-2009-4405)
498  #520920  notified maintainer
 https://bugzilla.redhat.com/show_bug.cgi?id=492136  
499    
500  --  --
501    
# Line 203  notified maintainer Line 504  notified maintainer
504    
505  --  --
506    
507    planet (CVE-2009-2937)
508    bug #546178
509    notified maintainer through initial bugreport
510    
511    --
512    
513    w3m (CVE-2010-2074)
514    maintainer notified through bug report
515    
516    --
517    
518  webkit (CVE-2008-4724)  webkit (CVE-2008-4724)
519  #520052  #520052
520  asked maintainer  asked maintainer
# Line 226  notified maintainer Line 538  notified maintainer
538    
539  --  --
540    
541    xerces-c2 (CVE-2009-1885)
542    #541986
543    notified maintainer
544    
545    --
546    
547  xfig  xfig
548  25_mkstemp added in 1:3.2.5.a-1  25_mkstemp added in 1:3.2.5.a-1
549  notified maintainer  notified maintainer
550    
551    CVE-2009-4228/CVE-2009-4227
552    #559274)
553    https://bugzilla.redhat.com/show_bug.cgi?id=543905
554    notified maintainer
555    
556    --
557    
558    xmp (CVE-2007-6731, CVE-2007-6732)
559    #546730
560    notified maintainer
561    
562  --  --
563    
564  xscreensaver (no CVE)  xserver-xorg (no CVE)
565  #539699  #555308
566    
567    --
568    
569    ytnef (CVE-2009-3887, CVE-2009-3721)
570    notified maintainer
571    
572  --  --
573    
574  ziproxy (CVE-2009-0804)  ziproxy (CVE-2009-0804)
575  #521051  #521051
576    notified maintainer
577    
578    --
579    
580    zope2.10 (no CVE)
581    https://mail.zope.org/pipermail/zope-announce/2010-January/002229.html
582    
583    --
584    
585    zoph (CVE-2008-6838, CVE-2008-6837, CVE-2009-2343)
586    http://sourceforge.net/tracker/?func=detail&aid=2815898&group_id=69353&atid=524249
587    http://sourceforge.net/project/shownotes.php?group_id=69353&release_id=694128
588    notified maintainer
589    

Legend:
Removed from v.12653  
changed lines
  Added in v.15243

  ViewVC Help
Powered by ViewVC 1.1.5