Log of /data/spu-candidates.txt
Parent Directory
|
Revision Log
Revision
15619 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sat Nov 27 12:09:05 2010 UTC
(2 years, 5 months ago)
by
jmm-guest
File length: 8467 byte(s)
Diff to
previous 15536
- new chrome/webkit issues
- new library path issues in banshee, gnome-shell, gnucash, tomboy
- vim issue Windows-specific
- one typo3 issue was fixed in previous DSA
- NFUs
Revision
15536 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Oct 28 21:31:39 2010 UTC
(2 years, 6 months ago)
by
jmm-guest
File length: 8363 byte(s)
Diff to
previous 15506
- ember fixed
- two more dovecot issues (fixed in Squeeze, N/A in Lenny)
- new mozilla issue and various mozilla updates
- postgresql9 issue (sid only)
- new python issue (already fixed in 3.1, 2.6 and 2.5 still needed)
- eglibc issue unimportant
- NFUs
- mantis fixed
Revision
15413 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sun Oct 3 20:43:54 2010 UTC
(2 years, 7 months ago)
by
jmm-guest
File length: 8218 byte(s)
Diff to
previous 15404
- lastfm, roaraudio, ike no-dsa
- mahara/tinymce code copy fixed
- otrs fixed
- cleanup older issues
Revision
15404 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Sep 30 21:02:01 2010 UTC
(2 years, 7 months ago)
by
jmm-guest
File length: 8124 byte(s)
Diff to
previous 15398
- fix spu version number for libpoe-component-irc-perl
- record lenny kernel point update fixes
- mark several issues not affecting lenny kernel
- scilab and teamspeak are non-free and no-dsa
Revision
15398 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Sep 30 09:22:29 2010 UTC
(2 years, 7 months ago)
by
jmm-guest
File length: 8019 byte(s)
Diff to
previous 15387
- ardour and magics++ fixed
- bristol and ardour not in Lenny, remove no-dsa tags and spu-candidates entry
- bug filed for mysql
Revision
15387 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Sep 29 17:26:54 2010 UTC
(2 years, 7 months ago)
by
jmm-guest
File length: 8092 byte(s)
Diff to
previous 15384
- multiple CVE IDs assigned for typo3 DSA
- ardour and brostol fixed and no-dsa for Lenny
- new Chromium/Webkit issue
- NFUs
Further cleanups of issues w/o a CVE ID:
- remove /dev/mem entry, this is a hardening feature not a vulnerability
- remove gmanedit and warzone entries, not a vulnerability as config
files are under local control
- remove duplicated piwigo entry
Revision
15384 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Sep 28 17:51:01 2010 UTC
(2 years, 7 months ago)
by
jmm-guest
File length: 8019 byte(s)
Diff to
previous 15383
xserver spu upload
new piwigo issue (fixed in squeeze, not in lenny)
record clamav/bzip2 issue
Revision
15383 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Sep 28 15:10:01 2010 UTC
(2 years, 7 months ago)
by
jmm-guest
File length: 8054 byte(s)
Diff to
previous 15251
- new clamav issue (already fixed in sid)
- qtparted and dropbox: fixed and no-dsa
- add srcpkg names for new poppler issues
- mydms has been removed
- new wireshark issue no-dsa, only code injection bugs are treated as DSA-worthy issues
Revision
15251 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Sep 1 16:54:03 2010 UTC
(2 years, 8 months ago)
by
jmm-guest
File length: 7975 byte(s)
Diff to
previous 15243
- remove rejected LXR issue, mark remaining ones no-dsa
- libgdiplus stable point update
- remove one phpbb3 dupe, two no-dsa
Revision
15243 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Aug 31 16:20:21 2010 UTC
(2 years, 8 months ago)
by
jmm-guest
File length: 7911 byte(s)
Diff to
previous 15123
- fix drupal c&p error
- no-dsa: libhx, libgdiplus, mapserver
- fix phpmyadmin entry, was still marked as unfixed for lenny
Revision
15026 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jul 27 02:59:06 2010 UTC
(2 years, 9 months ago)
by
jmm-guest
File length: 7624 byte(s)
Diff to
previous 14951
- fix incorrect Plone NFU
- spu status updates
- openttd CVEfied
- libesmtp fixed
- Mozilla fixes
- new rpcbind issue
Revision
14951 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Jul 2 17:51:39 2010 UTC
(2 years, 10 months ago)
by
jmm-guest
File length: 7523 byte(s)
Diff to
previous 14945
- NFUs
- redmine not in Lenny
- rewrite old kdebase entry
- rewrite old rails entry
- fastjar fixed
- remove policykit TODO, has been removed
- webkit issue is in Ruby
- old OO exploit never appeared, mark as NFU. If there ever is
one, we'll learn about it anyway
- remove a few obsolete TODOs
Revision
14945 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Jul 1 20:19:08 2010 UTC
(2 years, 10 months ago)
by
jmm-guest
File length: 7465 byte(s)
Diff to
previous 14935
- moodle fixed
- adapt severity of tiff crashers; without real security impact
- bugnums
- acidbase issue (mostly fixed, all no-dsa)
- rewrite cherokee entry
Revision
14935 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Jun 30 17:25:28 2010 UTC
(2 years, 10 months ago)
by
jmm-guest
File length: 7419 byte(s)
Diff to
previous 14916
- three new bugzilla issues, two not-affected, one no-dsa
- new minor xulrunner issue, one xulrunner issue not-affected
- Fix openjdk srcpkg name
- remove a few old undetermined entries for webkit copies for new,
we won't be able to realistically triage/support them if
this isn't even done upstream
Revision
14916 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Jun 28 17:34:16 2010 UTC
(2 years, 10 months ago)
by
jmm-guest
File length: 7358 byte(s)
Diff to
previous 14897
- pgp4pine removed
- squirrelmail already tracked by separate ID
- remove spu entries for issues fixed in latest point release
- mono fix was uploaded to unstable
- another slim issue was fixed in 5.0.5 point update
- 5.0.5 point update also introduced fixed sun-java[56] packages
- ziproxy fixed
- feh fixed
- new issues in wget (dsa), lftp (dsa) and libwww-perl (no-dsa)
- bug filed for w3m/ssl validation
- convert older safari TODOs to undetermined entries
- bug filed for tomcat6 information disclosure
Revision
14897 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Jun 23 20:29:12 2010 UTC
(2 years, 10 months ago)
by
jmm-guest
File length: 7603 byte(s)
Diff to
previous 14874
- new squirrelmail non-issue (Thijs, please change severity
if you disagree)
- pyftpd fixed in spu upload
- hamlib/ltdl code copy fixed
- multiple moodle issues fixed
- new moodle issues
- new htmlpurifier issue
- new bozohttpd issues
- horde not affected by Xinha issue
- new ziproxy issue not in Lenny
- activeldap prototype.js code copy fixed
- mono fixed
- new round of mozilla issues, already fixed in unstable and experimental for
xulrunner and in iceape
- two new pscs assignments already covered by CVE ID from DSA
- new fastjar issue no-dsa
- xen issue is in the Hypervisor, not the kernel (but already fixed anyway)
Revision
14874 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jun 15 22:07:45 2010 UTC
(2 years, 11 months ago)
by
jmm-guest
File length: 7559 byte(s)
Diff to
previous 14842
- new minor w3m issue
- notified maintainer on pyftpd spu upload, he's preparing one
- deluge of new webkit issues
Revision
14529 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Apr 19 22:34:53 2010 UTC
(3 years ago)
by
jmm-guest
File length: 7268 byte(s)
Diff to
previous 14497
- rewrite clamav with EOL tag
- couchdb fixed
- two fixes in Sun Java 6
- couchdb no-dsa
- begin qt4-x11 triage
Revision
14470 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Apr 13 21:44:56 2010 UTC
(3 years, 1 month ago)
by
jmm-guest
File length: 6987 byte(s)
Diff to
previous 14439
- konversation not-affected
- trac no-dsa
- more information on RTSP issue affecting mplayer and VLC
- opendchub not-affected in Lenny
- tgt fixed
Revision
14420 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Apr 6 21:52:24 2010 UTC
(3 years, 1 month ago)
by
jmm-guest
File length: 6927 byte(s)
Diff to
previous 14398
- opendchub CVEfied
- new libnss-db issue
- latest round of mozilla issues affects icedove as well
- emacsen movemail issues no-dsa
- fix entry for fwbuilder
- squid not affected by slowloris attack
- postgres no-dsa
- arora issue a non-issue
- one libesmtp issue fixed in 2008, the other one no-dsa
Revision
14241 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Mar 10 20:26:46 2010 UTC
(3 years, 2 months ago)
by
jmm-guest
File length: 6607 byte(s)
Diff to
previous 14226
- libpurple/qutecom code copy fixed
- new minor mediawiki issues
- cpio/tar maintainers notified about no-dsa for minor rmt issue
Revision
14214 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sun Mar 7 21:03:17 2010 UTC
(3 years, 2 months ago)
by
jmm-guest
File length: 6421 byte(s)
Diff to
previous 14212
puppet no-dsa
bugnums for linux-ftpd and libesmtp
samba/dir trav no-dsa
fix bugnum for kfreebsd
Revision
14185 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Mar 4 16:58:17 2010 UTC
(3 years, 2 months ago)
by
jmm-guest
File length: 6044 byte(s)
Diff to
previous 14136
- libpng no-dsa
- new moin issues fixed
- fix version for sudo NMU
- annotate the split for CVE-2009-3297 (splitting this several weeks after
multiple issues have been released really sucks)
- asterisk design issue discussed with maintainers, no update planned
- fix typo in wordpress source package name
- flex fixed even before Lenny
Revision
14136 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Feb 22 18:10:14 2010 UTC
(3 years, 2 months ago)
by
jmm-guest
File length: 6021 byte(s)
Diff to
previous 14124
- webworker issues affects Firefox 3.0 according to Mozilla
- remove dead ITP for webmin
- iceape fixed
- don't treat pidgin as unimportant
- ircd-hybrid fixed
- automake1.10 fixed
- makepasswd fixed
- overkill fixed
- pyfribidi fixed
- python-4suite fixed
Revision
14019 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Feb 3 18:39:30 2010 UTC
(3 years, 3 months ago)
by
jmm-guest
File length: 5970 byte(s)
Diff to
previous 13984
- acl fixed
- xotcl fixed by using system copy of expat
- asterisk issue unstable/testing only
- acl/struts no-dsa
Revision
13640 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Dec 24 10:44:32 2009 UTC
(3 years, 4 months ago)
by
jmm-guest
File length: 5444 byte(s)
Diff to
previous 13620
* imagemagick uses system copy of ltdl
* several no-dsa for ltdl issue
* new libhaml-ruby issue already fixed
* another expat no-dsa
* qt4 triage
* python expat issues should be fixed through DSAs
Revision
13620 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Dec 21 22:09:22 2009 UTC
(3 years, 4 months ago)
by
derevko-guest
File length: 5386 byte(s)
Diff to
previous 13618
CVE-2009-4079 and CVE-2009-4078 fixed in redmine 0.9.0~svn2902-1
CVE-2009-3701 fixed in horde3 3.3.6+debian0-1
jbossas4 issues
Revision
13618 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Dec 21 18:55:22 2009 UTC
(3 years, 4 months ago)
by
jmm-guest
File length: 5358 byte(s)
Diff to
previous 13617
* mark several ltdl issues as no-dsa
* devil no-dsa
* jetty issues not in binary package
* record more openjdk fixes
* iceape in lenny only a stub package
Revision
13557 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Dec 15 18:53:59 2009 UTC
(3 years, 5 months ago)
by
jmm-guest
File length: 5234 byte(s)
Diff to
previous 13490
* updates on libtool issues
* xfig fixed
* zoph fixed
* liboggplay fixed
* update fixed version for firefox-sage
* wxwidgets code copies of expat fixed
* ayttm/expat fixed
* start readjusting some of the expat issue, calling most of
them security issues is stretching things too far
* fix acpid entry
* xen fixed
Revision
13490 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Dec 8 17:09:50 2009 UTC
(3 years, 5 months ago)
by
jmm-guest
File length: 5145 byte(s)
Diff to
previous 13464
- updates on libtool code copies:
* snbc, dico and unixodbc use the system copy
* hypre and babel fixed, but no-dsa for Lenny/Etch
- update poppler issue for code copies
- fix kfreebsd bug num
- new devil issue
- fix tracking for dstat
Revision
13302 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Nov 17 18:08:03 2009 UTC
(3 years, 6 months ago)
by
jmm-guest
File length: 4881 byte(s)
Diff to
previous 13165
- track grub2 fix for unstable, not experimental
- asterisk, kernel, xmltooling, net-snmp fixed
- various no-dsa
- remove dubious VulnDisco "issues" from the tracker
until details are published
- old kvm issue doesn't affect us, CVE description is wrong,
confirmed by KVM upstream
Revision
13165 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sun Nov 1 10:45:03 2009 UTC
(3 years, 6 months ago)
by
derevko-guest
File length: 4804 byte(s)
Diff to
previous 13040
- wireshark issues
- CVE-2009-3765: mutt not-affected, our mutt is linked against gnutls
- CVE-2009-3641: DoS while printing specially-crafted IPv6 packet using the -v option in snort
- CVE-2009-3616: Multiple use-after-free vulnerabilities in qemu and kvm
- CVE-2006-5031: fixed in cakephp 1.1.13.4450-1
- CVE-2006-4067: fixed in cakephp 1.1.13.4450-1
Revision
13021 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Oct 15 13:23:11 2009 UTC
(3 years, 7 months ago)
by
derevko-guest
File length: 4947 byte(s)
Diff to
previous 13013
- CVE-2009-3564 no-dsa
- CVE-2009-3589 fixed in incron 0.5.7-1
- CVE-2009-3575: Buffer overflow in DHTRoutingTableDeserializer.cc in aria2
- openoffice.org issues
- NFUs
Revision
12947 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Oct 6 21:43:20 2009 UTC
(3 years, 7 months ago)
by
derevko-guest
File length: 4709 byte(s)
Diff to
previous 12928
- htmldoc NMUed
- CVE-2009-3242,CVE-2009-3241 fixed in wireshark 1.2.2-1
- CVE-2009-3490 fixed in wget 1.12-1
Revision
12922 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Oct 2 23:18:07 2009 UTC
(3 years, 7 months ago)
by
jmm-guest
File length: 4532 byte(s)
Diff to
previous 12892
- planet-venus scheduled for point update
- backuppc no-dsa
- new libfwbuilder issue
- new opensaml issue
- rewrite some not-affected entries
Revision
12780 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Sep 10 08:36:51 2009 UTC
(3 years, 8 months ago)
by
derevko-guest
File length: 3422 byte(s)
Diff to
previous 12757
- NFUs
- two minor no-dsa candidate mod_proxy_ftp issues
- CVE-2008-607{0,1,2) were fixed in graphicsmagick 1.2.3-1
- two new rails issues
Revision
12757 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Sep 7 17:39:41 2009 UTC
(3 years, 8 months ago)
by
jmm-guest
File length: 3493 byte(s)
Diff to
previous 12711
- gri, buildbot no-dsa
- xulrunner fixes for Lenny
- sdm, burn fixed
- remove silc temp entry
- gaim not affected in lenny, only a transitional package
Revision
12244 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Jul 1 18:24:25 2009 UTC
(3 years, 10 months ago)
by
jmm-guest
File length: 2514 byte(s)
Diff to
previous 12200
- new phpmyadmin issue
- libpng and browser randomness issues no-dsa
- ocsinventory documented as not to be used
with a public web server (TODO: document in
debtag)
- moin non-issue
- samba fixed
- add epoch to compface entry
- new icedove issues
Revision
12191 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Jun 24 18:47:22 2009 UTC
(3 years, 10 months ago)
by
jmm-guest
File length: 2398 byte(s)
Diff to
previous 12148
- xfs fixed
- convirt fixed
- jasper fixed
- some cleanups of CVE requests
- I've begun triaging the xine-lib issues for etch
Revision
12108 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Jun 11 21:59:06 2009 UTC
(3 years, 11 months ago)
by
jmm-guest
File length: 2313 byte(s)
Diff to
previous 12057
- new issues: kfreebsd (2x), adtool, kernel, webkit (2x), tomcat
- bugnum
- cscope fixed
- fix webkit entries, all issues are tracked by source packages,
not binary package names
- atmailopen was removed from the archive
Revision
12024 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jun 2 21:03:28 2009 UTC
(3 years, 11 months ago)
by
derevko-guest
File length: 1632 byte(s)
Diff to
previous 12020
- compiz-fusion-plugins-main spu notification
- new gst-plugins-good0.10 Integer Overflow Vulnerability
Revision
11944 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu May 21 12:24:46 2009 UTC
(3 years, 11 months ago)
by
jmm-guest
File length: 1315 byte(s)
Diff to
previous 11911
- minor ntp issue has been fixed in DSA alongside with a more severe issue,
remove from ospu/spu candidates list
- kernel fixed
- selinux issue was fixed for 2.6.29 through stable kernel update
- issue tracked as openjdk is actually a lcms issue
- CVE-2008-5519 is listed on the Tomcat web site, but it's actually within
mod-jk only
- clone ffmpeg-debian issue for the ffmpeg version in etch
- clone gnutls issue for the gnutls version in etch
- remove duplicate etch entry for older apache issue
Revision
11850 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sat May 9 13:06:05 2009 UTC
(4 years ago)
by
jmm-guest
File length: 1303 byte(s)
Diff to
previous 11813
- CVE-2009-0164 won't be fixed in spu updates
- fix date in DSA list
- new minor hex-a-hop issue
- fix jetty issue, why was this marked unimportant?
Revision
11775 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon May 4 19:44:38 2009 UTC
(4 years ago)
by
gilbert-guest
File length: 1263 byte(s)
Diff to
previous 11773
CVE-2008-2009 vulnerability already fixed; additional hardening features to be considered as an spu/ospu candidate
Revision
11712 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Apr 24 17:35:12 2009 UTC
(4 years ago)
by
jmm-guest
File length: 995 byte(s)
Diff to
previous 11707
- mark slurm as fixed for lenny
- remove wireshark duplicates
- one kernel issue has been renamed
- pptp-linux no-dsa
Revision
11559 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Apr 3 22:00:29 2009 UTC
(4 years, 1 month ago)
by
jmm-guest
File length: 724 byte(s)
Diff to
previous 11553
marked as no-dsa, added to xspu candidates. Please remember
to do so if you mark an issue as no-dsa and if it makes
sense
Revision
11490 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Mar 30 17:06:47 2009 UTC
(4 years, 1 month ago)
by
jmm-guest
File length: 600 byte(s)
Diff to
previous 11479
- multiple java6 issues fixed
- new xfig issue
- systemtap fixed
- avahi fixed
- opensc fixed
- openldap no-dsa
Revision
11479 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Mar 26 17:36:15 2009 UTC
(4 years, 1 month ago)
by
jmm-guest
File length: 578 byte(s)
Diff to
previous 11405
- new kfreebsd issue
- remove etch-specific unfixed entry, unneeded and might cause problems
- clone mikmod no-dsas for lenny
- unimportant bash issue fixed
Revision
11367 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Mar 10 13:58:03 2009 UTC
(4 years, 2 months ago)
by
nion
File length: 7389 byte(s)
Diff to
previous 11362
- spu notifications
- CVE-2009-0819 does not affect mysql in Debian
- CVE-2009-0737 fixed in mediawiki 1:1.14.0-1
- CVE-2008-5076 fixed in htop 0.8.1-2
- CVE-2008-4968 fixed in lmbench 3.0-a9-1
Revision
11213 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Feb 13 22:10:07 2009 UTC
(4 years, 3 months ago)
by
jmm-guest
File length: 7233 byte(s)
Diff to
previous 11210
- add libarchive-tar-perl to spu candidates
- libsamplerate, python/imageop no-dsa
- add one missing CVE ID to python-dns DSA
- two mediawiki issues don't affect etch
- tar module not yet present in Etch's perl
Revision
11210 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Feb 13 21:30:33 2009 UTC
(4 years, 3 months ago)
by
jmm-guest
File length: 6992 byte(s)
Diff to
previous 11202
- no-dsa: mailscanner, tsqllib, mikmod, sdlmixer
- remove CVEfied trac temp entry
- one tomcat issue is actually a JVM issue
- libnet-dns-perl isn't fixed DNS randomisation-wise
Revision
11195 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Feb 11 21:56:37 2009 UTC
(4 years, 3 months ago)
by
jmm-guest
File length: 6793 byte(s)
Diff to
previous 11184
- no-dsa: acidbase, bluez, motion, nfs-utils, systemimager, kdelibs
- three new wireshark issues already resolved for
etch and lenny
- arb fixed
Revision
11111 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Jan 29 22:17:45 2009 UTC
(4 years, 3 months ago)
by
jmm-guest
File length: 6655 byte(s)
Diff to
previous 11106
* no-dsa for some python2.5 issues which have been fixed for
2.4 (even through they've been borderline cases already)
* tcl no-dsa
* cleanup older php issue
Revision
10547 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sun Nov 30 01:13:50 2008 UTC
(4 years, 5 months ago)
by
jmm-guest
File length: 5838 byte(s)
Diff to
previous 10546
* add one CVD ID to horde3 DSA
* bugzilla <no-dsa>
* add a TODO a <confirmed> tag
* document glibc stub resolver situation
Revision
10131 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Oct 20 17:23:13 2008 UTC
(4 years, 6 months ago)
by
jmm-guest
File length: 5607 byte(s)
Diff to
previous 10116
ipsec-tools no-dsa
some kernel issues fixed
mantis updated fix
one network issue affects freeBSD
Revision
9994 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sat Oct 4 20:51:05 2008 UTC
(4 years, 7 months ago)
by
jmm-guest
File length: 5148 byte(s)
Diff to
previous 9991
Etch triage:
- Three recent kernel issues don't affect 2.6.18 from Etch
- twiki issue has been rejected
- ed issue no-dsa, was also duplicated
- links2 minor information leak no-dsa
Revision
9978 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Oct 3 20:44:02 2008 UTC
(4 years, 7 months ago)
by
jmm-guest
File length: 4637 byte(s)
Diff to
previous 9976
more SPUs
openswan should be fixed
not much point in fixing LTP in Etch, in Lenny it has been documented to only
work for isolated environments
Revision
9976 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Fri Oct 3 19:57:41 2008 UTC
(4 years, 7 months ago)
by
jmm-guest
File length: 4577 byte(s)
Diff to
previous 9975
more SPUs
bulmages not in etch
some bugs were already archived, which initially confused me
Revision
9959 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Oct 2 16:08:52 2008 UTC
(4 years, 7 months ago)
by
jmm-guest
File length: 4213 byte(s)
Diff to
previous 9953
remove plait and lazarus from spu-candidates, they're not present in Etch
more temp triage
new kernel issue
Revision
9930 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Oct 1 21:35:38 2008 UTC
(4 years, 7 months ago)
by
jmm-guest
File length: 3921 byte(s)
Diff to
previous 9929
more tmp triage
it seems as if Dmitry didn't file bugs for all issues in his
MBF, the remaining ones need to be evaluated and filed
Revision
9641 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sun Aug 24 23:10:38 2008 UTC
(4 years, 8 months ago)
by
nion
File length: 3586 byte(s)
Diff to
previous 9638
CVE-2008-3688 fixed in havp 20070509-1.1
notified ipsec-tools maintainer for spu, fixed upstream link
Revision
9522 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Aug 6 19:37:44 2008 UTC
(4 years, 9 months ago)
by
jmm-guest
File length: 3343 byte(s)
Diff to
previous 9425
links2, exiv2 no-dsa
add php to packages with special security support
add one missing mozilla CVE ID, which was split off
one moin issue doesn't affect etch
two dnsmasq issues don't affect etch, dnsmasq CVEfied
one iceweasel issue Mac specific
add note on firebird in etch
one issues marked as php is only relevant to libgd
Revision
9331 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jul 15 09:54:17 2008 UTC
(4 years, 10 months ago)
by
jmm-guest
File length: 3391 byte(s)
Diff to
previous 9137
record several upstream fixes for the upcoming 2.6.26 upload
remove <unfixed> entries for [etch], since they're always implicitly unfixed
if the version number is lower than the entry for unstable
do not record 2.6.24 entries if the fixed version in unstable is lower than
2.6.24
Revision
9135 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jun 24 20:54:08 2008 UTC
(4 years, 10 months ago)
by
jmm-guest
File length: 3319 byte(s)
Diff to
previous 9067
updates on embedded code copies
bugzilla no-dsa
add missing CVE ID to libimager-perl DSA
fix two incorrect ruby entries
remove some NOTEs present in the respective CVE entries
new kernel issue, mark unfixed for now until it's been figured
out when this was fixed upstream
resolve old gpg TODO
NFUs
Revision
8912 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue May 27 15:52:31 2008 UTC
(4 years, 11 months ago)
by
jmm-guest
File length: 3018 byte(s)
Diff to
previous 8647
emacs no-dsa
one missing ID for openssh
snort issue doesn't affect etch
sql-ledger issues fixed
Revision
8526 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Mon Apr 14 17:01:00 2008 UTC
(5 years, 1 month ago)
by
jmm-guest
File length: 2581 byte(s)
Diff to
previous 8492
- bzip2 and paramiko no-dsa
- two new python issues
- mediawiki/etch not affected twice
Revision
8476 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Apr 3 21:59:30 2008 UTC
(5 years, 1 month ago)
by
jmm-guest
File length: 2404 byte(s)
Diff to
previous 8448
boost spu no-dsa
cld issue/glibc not needed for etch
eterm rather harmless, more of a design bug than a vulnerability
Revision
8055 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jan 29 20:57:31 2008 UTC
(5 years, 3 months ago)
by
jmm-guest
File length: 1895 byte(s)
Diff to
previous 8024
one kernel issue doesn't affect etch
denyhosts fixed in stable update
php5 ini issue no-dsa due to regressions
one php issue unimportant
ruby1.9 no-dsa
streamripper no-dsa
Revision
8023 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Wed Jan 23 17:11:57 2008 UTC
(5 years, 3 months ago)
by
jmm-guest
File length: 1841 byte(s)
Diff to
previous 8009
one kernel issue not affecting etch
safe mode bypass unimportant (report has been posted to full disclosure)
mnogosearch minor issue
Revision
8009 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jan 22 00:13:33 2008 UTC
(5 years, 3 months ago)
by
jmm-guest
File length: 1799 byte(s)
Diff to
previous 7988
turned out that etch and sarge don't ship the affected tool
in the libcdio binary packages
Revision
7932 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jan 15 22:58:39 2008 UTC
(5 years, 4 months ago)
by
jmm-guest
File length: 1729 byte(s)
Diff to
previous 7904
minor lighttpd issue to spu candidates
gforge will be fixed in a DSA
one nagios-plugins issue doesn't affect Etch
Revision
7883 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sat Jan 12 01:07:37 2008 UTC
(5 years, 4 months ago)
by
jmm-guest
File length: 1402 byte(s)
Diff to
previous 7876
two new no-dsa issues
xscreensaver issue doesn't affect etch
rss-glx was only a workaround, the real fix was xscreensaver
two moin issues were mixed around
Revision
7871 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Thu Jan 10 22:49:21 2008 UTC
(5 years, 4 months ago)
by
jmm-guest
File length: 1196 byte(s)
Diff to
previous 7870
- When I tried to assist the maintainer to extract a patch to backport
I noticed the code isn't present in Etch at all, noting accordingly
- Sylpheed issue not worth a DSA
Revision
7856 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Tue Jan 8 18:41:19 2008 UTC
(5 years, 4 months ago)
by
jmm-guest
File length: 979 byte(s)
Diff to
previous 7848
- Firefly Media Server is in the archive, but under a different name (marked
unfixed w/o further checks for now as a temporary measure)
- one rails issue doesn't affect Etch
- nufw, mldonkey no-dsa
- rewrite phpsysinfo as unimportant, rather than no-dsa
Revision
7681 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Modified
Sat Dec 22 12:29:08 2007 UTC
(5 years, 4 months ago)
by
jmm-guest
File length: 636 byte(s)
Diff to
previous 7554
remove rejected ID from qemu DSA
remove some notes on rejected entries
one older php issue unimportant per PHP security policy
Revision
7532 -
(
view)
(
download)
(
annotate)
-
[select for diffs]
Added
Thu Dec 6 18:19:31 2007 UTC
(5 years, 5 months ago)
by
jmm-guest
File length: 457 byte(s)
This file records minor security issues, which do not warrant a DSA,
but which could be fixed in a stable point update if people feel like
it. If someone wants to address these, please add a note about it
and get in contact with debian-release@lists.debian.org
This form allows you to request diffs between any two revisions of this file.
For each of the two "sides" of the diff,
enter a numeric revision.