Log of /data/ospu-candidates.txt
Parent Directory
|
Revision Log
Revision
15536 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Oct 28 21:31:39 2010 UTC
(2 years, 6 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 8363 byte(s)
Diff to
previous 15506
,
to
selected 13640
- ember fixed
- two more dovecot issues (fixed in Squeeze, N/A in Lenny)
- new mozilla issue and various mozilla updates
- postgresql9 issue (sid only)
- new python issue (already fixed in 3.1, 2.6 and 2.5 still needed)
- eglibc issue unimportant
- NFUs
- mantis fixed
Revision
15387 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Sep 29 17:26:54 2010 UTC
(2 years, 7 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 8092 byte(s)
Diff to
previous 15384
,
to
selected 13640
- multiple CVE IDs assigned for typo3 DSA
- ardour and brostol fixed and no-dsa for Lenny
- new Chromium/Webkit issue
- NFUs
Further cleanups of issues w/o a CVE ID:
- remove /dev/mem entry, this is a hardening feature not a vulnerability
- remove gmanedit and warzone entries, not a vulnerability as config
files are under local control
- remove duplicated piwigo entry
Revision
15383 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Sep 28 15:10:01 2010 UTC
(2 years, 7 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 8054 byte(s)
Diff to
previous 15251
,
to
selected 13640
- new clamav issue (already fixed in sid)
- qtparted and dropbox: fixed and no-dsa
- add srcpkg names for new poppler issues
- mydms has been removed
- new wireshark issue no-dsa, only code injection bugs are treated as DSA-worthy issues
Revision
14951 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Jul 2 17:51:39 2010 UTC
(2 years, 10 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 7523 byte(s)
Diff to
previous 14945
,
to
selected 13640
- NFUs
- redmine not in Lenny
- rewrite old kdebase entry
- rewrite old rails entry
- fastjar fixed
- remove policykit TODO, has been removed
- webkit issue is in Ruby
- old OO exploit never appeared, mark as NFU. If there ever is
one, we'll learn about it anyway
- remove a few obsolete TODOs
Revision
14935 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Jun 30 17:25:28 2010 UTC
(2 years, 10 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 7419 byte(s)
Diff to
previous 14916
,
to
selected 13640
- three new bugzilla issues, two not-affected, one no-dsa
- new minor xulrunner issue, one xulrunner issue not-affected
- Fix openjdk srcpkg name
- remove a few old undetermined entries for webkit copies for new,
we won't be able to realistically triage/support them if
this isn't even done upstream
Revision
14916 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Jun 28 17:34:16 2010 UTC
(2 years, 10 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 7358 byte(s)
Diff to
previous 14897
,
to
selected 13640
- pgp4pine removed
- squirrelmail already tracked by separate ID
- remove spu entries for issues fixed in latest point release
- mono fix was uploaded to unstable
- another slim issue was fixed in 5.0.5 point update
- 5.0.5 point update also introduced fixed sun-java[56] packages
- ziproxy fixed
- feh fixed
- new issues in wget (dsa), lftp (dsa) and libwww-perl (no-dsa)
- bug filed for w3m/ssl validation
- convert older safari TODOs to undetermined entries
- bug filed for tomcat6 information disclosure
Revision
14897 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Jun 23 20:29:12 2010 UTC
(2 years, 10 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 7603 byte(s)
Diff to
previous 14874
,
to
selected 13640
- new squirrelmail non-issue (Thijs, please change severity
if you disagree)
- pyftpd fixed in spu upload
- hamlib/ltdl code copy fixed
- multiple moodle issues fixed
- new moodle issues
- new htmlpurifier issue
- new bozohttpd issues
- horde not affected by Xinha issue
- new ziproxy issue not in Lenny
- activeldap prototype.js code copy fixed
- mono fixed
- new round of mozilla issues, already fixed in unstable and experimental for
xulrunner and in iceape
- two new pscs assignments already covered by CVE ID from DSA
- new fastjar issue no-dsa
- xen issue is in the Hypervisor, not the kernel (but already fixed anyway)
Revision
14420 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Apr 6 21:52:24 2010 UTC
(3 years, 1 month ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 6927 byte(s)
Diff to
previous 14398
,
to
selected 13640
- opendchub CVEfied
- new libnss-db issue
- latest round of mozilla issues affects icedove as well
- emacsen movemail issues no-dsa
- fix entry for fwbuilder
- squid not affected by slowloris attack
- postgres no-dsa
- arora issue a non-issue
- one libesmtp issue fixed in 2008, the other one no-dsa
Revision
14185 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Mar 4 16:58:17 2010 UTC
(3 years, 2 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 6044 byte(s)
Diff to
previous 14136
,
to
selected 13640
- libpng no-dsa
- new moin issues fixed
- fix version for sudo NMU
- annotate the split for CVE-2009-3297 (splitting this several weeks after
multiple issues have been released really sucks)
- asterisk design issue discussed with maintainers, no update planned
- fix typo in wordpress source package name
- flex fixed even before Lenny
Revision
14136 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Feb 22 18:10:14 2010 UTC
(3 years, 2 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 6021 byte(s)
Diff to
previous 14124
,
to
selected 13640
- webworker issues affects Firefox 3.0 according to Mozilla
- remove dead ITP for webmin
- iceape fixed
- don't treat pidgin as unimportant
- ircd-hybrid fixed
- automake1.10 fixed
- makepasswd fixed
- overkill fixed
- pyfribidi fixed
- python-4suite fixed
Revision
13640 -
(
view)
(
download)
(
annotate)
-
[selected]
Modified
Thu Dec 24 10:44:32 2009 UTC
(3 years, 4 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 5444 byte(s)
Diff to
previous 13620
* imagemagick uses system copy of ltdl
* several no-dsa for ltdl issue
* new libhaml-ruby issue already fixed
* another expat no-dsa
* qt4 triage
* python expat issues should be fixed through DSAs
Revision
13557 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Dec 15 18:53:59 2009 UTC
(3 years, 5 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 5234 byte(s)
Diff to
previous 13490
,
to
selected 13640
* updates on libtool issues
* xfig fixed
* zoph fixed
* liboggplay fixed
* update fixed version for firefox-sage
* wxwidgets code copies of expat fixed
* ayttm/expat fixed
* start readjusting some of the expat issue, calling most of
them security issues is stretching things too far
* fix acpid entry
* xen fixed
Revision
13490 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Dec 8 17:09:50 2009 UTC
(3 years, 5 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 5145 byte(s)
Diff to
previous 13464
,
to
selected 13640
- updates on libtool code copies:
* snbc, dico and unixodbc use the system copy
* hypre and babel fixed, but no-dsa for Lenny/Etch
- update poppler issue for code copies
- fix kfreebsd bug num
- new devil issue
- fix tracking for dstat
Revision
13302 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Nov 17 18:08:03 2009 UTC
(3 years, 6 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 4881 byte(s)
Diff to
previous 13165
,
to
selected 13640
- track grub2 fix for unstable, not experimental
- asterisk, kernel, xmltooling, net-snmp fixed
- various no-dsa
- remove dubious VulnDisco "issues" from the tracker
until details are published
- old kvm issue doesn't affect us, CVE description is wrong,
confirmed by KVM upstream
Revision
13165 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sun Nov 1 10:45:03 2009 UTC
(3 years, 6 months ago)
by
derevko-guest
Original Path:
data/spu-candidates.txt
File length: 4804 byte(s)
Diff to
previous 13040
,
to
selected 13640
- wireshark issues
- CVE-2009-3765: mutt not-affected, our mutt is linked against gnutls
- CVE-2009-3641: DoS while printing specially-crafted IPv6 packet using the -v option in snort
- CVE-2009-3616: Multiple use-after-free vulnerabilities in qemu and kvm
- CVE-2006-5031: fixed in cakephp 1.1.13.4450-1
- CVE-2006-4067: fixed in cakephp 1.1.13.4450-1
Revision
12244 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Jul 1 18:24:25 2009 UTC
(3 years, 10 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 2514 byte(s)
Diff to
previous 12200
,
to
selected 13640
- new phpmyadmin issue
- libpng and browser randomness issues no-dsa
- ocsinventory documented as not to be used
with a public web server (TODO: document in
debtag)
- moin non-issue
- samba fixed
- add epoch to compface entry
- new icedove issues
Revision
12108 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Jun 11 21:59:06 2009 UTC
(3 years, 11 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 2313 byte(s)
Diff to
previous 12057
,
to
selected 13640
- new issues: kfreebsd (2x), adtool, kernel, webkit (2x), tomcat
- bugnum
- cscope fixed
- fix webkit entries, all issues are tracked by source packages,
not binary package names
- atmailopen was removed from the archive
Revision
11944 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu May 21 12:24:46 2009 UTC
(3 years, 11 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 1315 byte(s)
Diff to
previous 11911
,
to
selected 13640
- minor ntp issue has been fixed in DSA alongside with a more severe issue,
remove from ospu/spu candidates list
- kernel fixed
- selinux issue was fixed for 2.6.29 through stable kernel update
- issue tracked as openjdk is actually a lcms issue
- CVE-2008-5519 is listed on the Tomcat web site, but it's actually within
mod-jk only
- clone ffmpeg-debian issue for the ffmpeg version in etch
- clone gnutls issue for the gnutls version in etch
- remove duplicate etch entry for older apache issue
Revision
9522 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Aug 6 19:37:44 2008 UTC
(4 years, 9 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 3343 byte(s)
Diff to
previous 9425
,
to
selected 13640
links2, exiv2 no-dsa
add php to packages with special security support
add one missing mozilla CVE ID, which was split off
one moin issue doesn't affect etch
two dnsmasq issues don't affect etch, dnsmasq CVEfied
one iceweasel issue Mac specific
add note on firebird in etch
one issues marked as php is only relevant to libgd
Revision
9331 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jul 15 09:54:17 2008 UTC
(4 years, 10 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 3391 byte(s)
Diff to
previous 9137
,
to
selected 13640
record several upstream fixes for the upcoming 2.6.26 upload
remove <unfixed> entries for [etch], since they're always implicitly unfixed
if the version number is lower than the entry for unstable
do not record 2.6.24 entries if the fixed version in unstable is lower than
2.6.24
Revision
9135 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jun 24 20:54:08 2008 UTC
(4 years, 10 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 3319 byte(s)
Diff to
previous 9067
,
to
selected 13640
updates on embedded code copies
bugzilla no-dsa
add missing CVE ID to libimager-perl DSA
fix two incorrect ruby entries
remove some NOTEs present in the respective CVE entries
new kernel issue, mark unfixed for now until it's been figured
out when this was fixed upstream
resolve old gpg TODO
NFUs
Revision
7856 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jan 8 18:41:19 2008 UTC
(5 years, 4 months ago)
by
jmm-guest
Original Path:
data/spu-candidates.txt
File length: 979 byte(s)
Diff to
previous 7848
,
to
selected 13640
- Firefly Media Server is in the archive, but under a different name (marked
unfixed w/o further checks for now as a temporary measure)
- one rails issue doesn't affect Etch
- nufw, mldonkey no-dsa
- rewrite phpsysinfo as unimportant, rather than no-dsa
This form allows you to request diffs between any two revisions of this file.
For each of the two "sides" of the diff,
enter a numeric revision.