Log of /data/spu-candidates.txt
Parent Directory
|
Revision Log
Revision
14185 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Mar 4 16:58:17 2010 UTC
(3 years, 2 months ago)
by
jmm-guest
File length: 6044 byte(s)
Diff to
previous 14136
,
to
selected 10586
- libpng no-dsa
- new moin issues fixed
- fix version for sudo NMU
- annotate the split for CVE-2009-3297 (splitting this several weeks after
multiple issues have been released really sucks)
- asterisk design issue discussed with maintainers, no update planned
- fix typo in wordpress source package name
- flex fixed even before Lenny
Revision
14136 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Feb 22 18:10:14 2010 UTC
(3 years, 3 months ago)
by
jmm-guest
File length: 6021 byte(s)
Diff to
previous 14124
,
to
selected 10586
- webworker issues affects Firefox 3.0 according to Mozilla
- remove dead ITP for webmin
- iceape fixed
- don't treat pidgin as unimportant
- ircd-hybrid fixed
- automake1.10 fixed
- makepasswd fixed
- overkill fixed
- pyfribidi fixed
- python-4suite fixed
Revision
13640 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Dec 24 10:44:32 2009 UTC
(3 years, 5 months ago)
by
jmm-guest
File length: 5444 byte(s)
Diff to
previous 13620
,
to
selected 10586
* imagemagick uses system copy of ltdl
* several no-dsa for ltdl issue
* new libhaml-ruby issue already fixed
* another expat no-dsa
* qt4 triage
* python expat issues should be fixed through DSAs
Revision
13618 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Dec 21 18:55:22 2009 UTC
(3 years, 5 months ago)
by
jmm-guest
File length: 5358 byte(s)
Diff to
previous 13617
,
to
selected 10586
* mark several ltdl issues as no-dsa
* devil no-dsa
* jetty issues not in binary package
* record more openjdk fixes
* iceape in lenny only a stub package
Revision
13557 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Dec 15 18:53:59 2009 UTC
(3 years, 5 months ago)
by
jmm-guest
File length: 5234 byte(s)
Diff to
previous 13490
,
to
selected 10586
* updates on libtool issues
* xfig fixed
* zoph fixed
* liboggplay fixed
* update fixed version for firefox-sage
* wxwidgets code copies of expat fixed
* ayttm/expat fixed
* start readjusting some of the expat issue, calling most of
them security issues is stretching things too far
* fix acpid entry
* xen fixed
Revision
13490 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Dec 8 17:09:50 2009 UTC
(3 years, 5 months ago)
by
jmm-guest
File length: 5145 byte(s)
Diff to
previous 13464
,
to
selected 10586
- updates on libtool code copies:
* snbc, dico and unixodbc use the system copy
* hypre and babel fixed, but no-dsa for Lenny/Etch
- update poppler issue for code copies
- fix kfreebsd bug num
- new devil issue
- fix tracking for dstat
Revision
13302 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Nov 17 18:08:03 2009 UTC
(3 years, 6 months ago)
by
jmm-guest
File length: 4881 byte(s)
Diff to
previous 13165
,
to
selected 10586
- track grub2 fix for unstable, not experimental
- asterisk, kernel, xmltooling, net-snmp fixed
- various no-dsa
- remove dubious VulnDisco "issues" from the tracker
until details are published
- old kvm issue doesn't affect us, CVE description is wrong,
confirmed by KVM upstream
Revision
13165 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sun Nov 1 10:45:03 2009 UTC
(3 years, 6 months ago)
by
derevko-guest
File length: 4804 byte(s)
Diff to
previous 13040
,
to
selected 10586
- wireshark issues
- CVE-2009-3765: mutt not-affected, our mutt is linked against gnutls
- CVE-2009-3641: DoS while printing specially-crafted IPv6 packet using the -v option in snort
- CVE-2009-3616: Multiple use-after-free vulnerabilities in qemu and kvm
- CVE-2006-5031: fixed in cakephp 1.1.13.4450-1
- CVE-2006-4067: fixed in cakephp 1.1.13.4450-1
Revision
13021 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Oct 15 13:23:11 2009 UTC
(3 years, 7 months ago)
by
derevko-guest
File length: 4947 byte(s)
Diff to
previous 13013
,
to
selected 10586
- CVE-2009-3564 no-dsa
- CVE-2009-3589 fixed in incron 0.5.7-1
- CVE-2009-3575: Buffer overflow in DHTRoutingTableDeserializer.cc in aria2
- openoffice.org issues
- NFUs
Revision
12757 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Sep 7 17:39:41 2009 UTC
(3 years, 8 months ago)
by
jmm-guest
File length: 3493 byte(s)
Diff to
previous 12711
,
to
selected 10586
- gri, buildbot no-dsa
- xulrunner fixes for Lenny
- sdm, burn fixed
- remove silc temp entry
- gaim not affected in lenny, only a transitional package
Revision
12244 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Jul 1 18:24:25 2009 UTC
(3 years, 10 months ago)
by
jmm-guest
File length: 2514 byte(s)
Diff to
previous 12200
,
to
selected 10586
- new phpmyadmin issue
- libpng and browser randomness issues no-dsa
- ocsinventory documented as not to be used
with a public web server (TODO: document in
debtag)
- moin non-issue
- samba fixed
- add epoch to compface entry
- new icedove issues
Revision
12108 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Jun 11 21:59:06 2009 UTC
(3 years, 11 months ago)
by
jmm-guest
File length: 2313 byte(s)
Diff to
previous 12057
,
to
selected 10586
- new issues: kfreebsd (2x), adtool, kernel, webkit (2x), tomcat
- bugnum
- cscope fixed
- fix webkit entries, all issues are tracked by source packages,
not binary package names
- atmailopen was removed from the archive
Revision
11944 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu May 21 12:24:46 2009 UTC
(4 years ago)
by
jmm-guest
File length: 1315 byte(s)
Diff to
previous 11911
,
to
selected 10586
- minor ntp issue has been fixed in DSA alongside with a more severe issue,
remove from ospu/spu candidates list
- kernel fixed
- selinux issue was fixed for 2.6.29 through stable kernel update
- issue tracked as openjdk is actually a lcms issue
- CVE-2008-5519 is listed on the Tomcat web site, but it's actually within
mod-jk only
- clone ffmpeg-debian issue for the ffmpeg version in etch
- clone gnutls issue for the gnutls version in etch
- remove duplicate etch entry for older apache issue
Revision
11479 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Mar 26 17:36:15 2009 UTC
(4 years, 1 month ago)
by
jmm-guest
File length: 578 byte(s)
Diff to
previous 11405
,
to
selected 10586
- new kfreebsd issue
- remove etch-specific unfixed entry, unneeded and might cause problems
- clone mikmod no-dsas for lenny
- unimportant bash issue fixed
Revision
11367 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Mar 10 13:58:03 2009 UTC
(4 years, 2 months ago)
by
nion
File length: 7389 byte(s)
Diff to
previous 11362
,
to
selected 10586
- spu notifications
- CVE-2009-0819 does not affect mysql in Debian
- CVE-2009-0737 fixed in mediawiki 1:1.14.0-1
- CVE-2008-5076 fixed in htop 0.8.1-2
- CVE-2008-4968 fixed in lmbench 3.0-a9-1
Revision
11213 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Feb 13 22:10:07 2009 UTC
(4 years, 3 months ago)
by
jmm-guest
File length: 7233 byte(s)
Diff to
previous 11210
,
to
selected 10586
- add libarchive-tar-perl to spu candidates
- libsamplerate, python/imageop no-dsa
- add one missing CVE ID to python-dns DSA
- two mediawiki issues don't affect etch
- tar module not yet present in Etch's perl
Revision
11210 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Feb 13 21:30:33 2009 UTC
(4 years, 3 months ago)
by
jmm-guest
File length: 6992 byte(s)
Diff to
previous 11202
,
to
selected 10586
- no-dsa: mailscanner, tsqllib, mikmod, sdlmixer
- remove CVEfied trac temp entry
- one tomcat issue is actually a JVM issue
- libnet-dns-perl isn't fixed DNS randomisation-wise
Revision
11195 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Feb 11 21:56:37 2009 UTC
(4 years, 3 months ago)
by
jmm-guest
File length: 6793 byte(s)
Diff to
previous 11184
,
to
selected 10586
- no-dsa: acidbase, bluez, motion, nfs-utils, systemimager, kdelibs
- three new wireshark issues already resolved for
etch and lenny
- arb fixed
Revision
11111 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Jan 29 22:17:45 2009 UTC
(4 years, 3 months ago)
by
jmm-guest
File length: 6655 byte(s)
Diff to
previous 11106
,
to
selected 10586
* no-dsa for some python2.5 issues which have been fixed for
2.4 (even through they've been borderline cases already)
* tcl no-dsa
* cleanup older php issue
Revision
10586 -
(
view)
(
download)
(
annotate)
-
[selected]
Modified
Tue Dec 2 22:49:00 2008 UTC
(4 years, 5 months ago)
by
jmm-guest
File length: 5934 byte(s)
Diff to
previous 10556
dnspython no-dsa
one kernel issue fixed
Revision
9994 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sat Oct 4 20:51:05 2008 UTC
(4 years, 7 months ago)
by
jmm-guest
File length: 5148 byte(s)
Diff to
previous 9991
,
to
selected 10586
Etch triage:
- Three recent kernel issues don't affect 2.6.18 from Etch
- twiki issue has been rejected
- ed issue no-dsa, was also duplicated
- links2 minor information leak no-dsa
Revision
9978 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Oct 3 20:44:02 2008 UTC
(4 years, 7 months ago)
by
jmm-guest
File length: 4637 byte(s)
Diff to
previous 9976
,
to
selected 10586
more SPUs
openswan should be fixed
not much point in fixing LTP in Etch, in Lenny it has been documented to only
work for isolated environments
Revision
9522 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Aug 6 19:37:44 2008 UTC
(4 years, 9 months ago)
by
jmm-guest
File length: 3343 byte(s)
Diff to
previous 9425
,
to
selected 10586
links2, exiv2 no-dsa
add php to packages with special security support
add one missing mozilla CVE ID, which was split off
one moin issue doesn't affect etch
two dnsmasq issues don't affect etch, dnsmasq CVEfied
one iceweasel issue Mac specific
add note on firebird in etch
one issues marked as php is only relevant to libgd
Revision
9331 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jul 15 09:54:17 2008 UTC
(4 years, 10 months ago)
by
jmm-guest
File length: 3391 byte(s)
Diff to
previous 9137
,
to
selected 10586
record several upstream fixes for the upcoming 2.6.26 upload
remove <unfixed> entries for [etch], since they're always implicitly unfixed
if the version number is lower than the entry for unstable
do not record 2.6.24 entries if the fixed version in unstable is lower than
2.6.24
Revision
9135 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jun 24 20:54:08 2008 UTC
(4 years, 11 months ago)
by
jmm-guest
File length: 3319 byte(s)
Diff to
previous 9067
,
to
selected 10586
updates on embedded code copies
bugzilla no-dsa
add missing CVE ID to libimager-perl DSA
fix two incorrect ruby entries
remove some NOTEs present in the respective CVE entries
new kernel issue, mark unfixed for now until it's been figured
out when this was fixed upstream
resolve old gpg TODO
NFUs
Revision
8055 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jan 29 20:57:31 2008 UTC
(5 years, 3 months ago)
by
jmm-guest
File length: 1895 byte(s)
Diff to
previous 8024
,
to
selected 10586
one kernel issue doesn't affect etch
denyhosts fixed in stable update
php5 ini issue no-dsa due to regressions
one php issue unimportant
ruby1.9 no-dsa
streamripper no-dsa
Revision
7883 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sat Jan 12 01:07:37 2008 UTC
(5 years, 4 months ago)
by
jmm-guest
File length: 1402 byte(s)
Diff to
previous 7876
,
to
selected 10586
two new no-dsa issues
xscreensaver issue doesn't affect etch
rss-glx was only a workaround, the real fix was xscreensaver
two moin issues were mixed around
Revision
7871 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Jan 10 22:49:21 2008 UTC
(5 years, 4 months ago)
by
jmm-guest
File length: 1196 byte(s)
Diff to
previous 7870
,
to
selected 10586
- When I tried to assist the maintainer to extract a patch to backport
I noticed the code isn't present in Etch at all, noting accordingly
- Sylpheed issue not worth a DSA
Revision
7856 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jan 8 18:41:19 2008 UTC
(5 years, 4 months ago)
by
jmm-guest
File length: 979 byte(s)
Diff to
previous 7848
,
to
selected 10586
- Firefly Media Server is in the archive, but under a different name (marked
unfixed w/o further checks for now as a temporary measure)
- one rails issue doesn't affect Etch
- nufw, mldonkey no-dsa
- rewrite phpsysinfo as unimportant, rather than no-dsa
Revision
7532 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Added
Thu Dec 6 18:19:31 2007 UTC
(5 years, 5 months ago)
by
jmm-guest
File length: 457 byte(s)
Diff
to
selected 10586
This file records minor security issues, which do not warrant a DSA,
but which could be fixed in a stable point update if people feel like
it. If someone wants to address these, please add a note about it
and get in contact with debian-release@lists.debian.org
This form allows you to request diffs between any two revisions of this file.
For each of the two "sides" of the diff,
enter a numeric revision.