This file records minor security issues, which do not warrant a DSA, but which could be fixed in a stable point update if people feel like it. If someone wants to address these, please add a note about it and get in contact with debian-release@lists.debian.org -- audacity (CVE-2007-6061) http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=453283 notified maintainer -- beagle (CVE-2005-4791) notified maintainer -- blam (CVE-2005-4791) notified maintainer -- flac123 (CVE-2007-3507) notified maintainer -- libapache2-mod-perl2 (CVE-2007-1349) http://svn.apache.org/viewvc?view=rev&revision=521584 #433549 notified maintainer -- libpam-ssh (CVE-2007-0844) #410236 notified maintainer -- liferea (CVE-2005-4791) notified maintainer -- lighttpd (CVE-2007-3948) #434888 Was accidentally omitted during DSA 1362, but doesn't warrant a DSA on it's own. http://trac.lighttpd.net/trac/changeset/1873?format=diff&new=1873 http://trac.lighttpd.net/trac/ticket/1216 notified maintainer -- linux-ftpd-ssl (CVE-2007-6263) #454733 notified maintainer -- mecab (CVE-2007-3231) #429174 notified maintainer -- mldonkey (CVE-2007-4100) #435439 notified maintainer --- proftpd-dfsg, proftpd (CVE-2007-2165) update in progress -- python2.4, python2.5 (CVE-2007-4965) http://bugs.python.org/issue1179 notified maintainer -- slocate (CVE-2007-0227) #411937 notified maintainer -- sylpheed (CVE-2007-2958) #441854 http://www.colino.net/claws-mail/getpatchset.php3?ver=2.10.0cvs153 fixes the bug notified maintainer -- tomboy (CVE-2005-4790) notified maintainer -- vobcopy (CVE-2007-5718) bug #448319 notified maintainer -- zsh (CVE-2007-6209) bug #454073) notified maintainer