/[secure-testing]/hardening/subgoal-dsa.txt
ViewVC logotype

Diff of /hardening/subgoal-dsa.txt

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 17396 by thijs, Sun Oct 9 13:34:01 2011 UTC revision 18197 by jmm, Tue Jan 17 22:44:42 2012 UTC
# Line 13  Instructions: Line 13  Instructions:
13    
14  Candidates:  Candidates:
15    
16  abcmidi  alsaplayer (654518)
17  acpid  amarok (653354)
18  alsaplayer  apt (653504)
19  amarok  asterisk (653944)
20  amule  barnowl (653506)
21  antiword  beid (653956)
22  apache2  bochs (653511)
23  apr  bzip2 (655164)
24  apr-util  capi4hylafax (653539)
25  apt  chrony (655123)
26  asterisk  clamav (653958)
27  audiofile  courier-authlib (655168)
28  avahi  cpio (654522)
29  barnowl  cscope (653490)
30  beid  ctorrent (653536)
31  blender  devil (653535)
32  bluez-hcidump  dspam (655189)
33  bochs  dovecot (653530)
34  bsdgames  drbd8 (currently broken: #654459)
35  bzip2  e2fsprogs (654457)
 cabextract  
 capi4hylafax  
 cgiirc  
 cheesetracker  
 chmlib  
 chrony  
 citadel  
 clamav  
 collectd  
 courier  
 courier-authlib  
 cpio  
 crawl  
 cscope  
 ctorrent  
 curl  
 cyrus-imapd-2.2  
 devil  
 devscripts  
 dia  
 djbdns  
 dkim-milter  
 dovecot  
 dpkg  
 drbd8  
 dspam  
 e2fsprogs  
36  ejabberd  ejabberd
37  ekg  ekg (653531)
38  elinks  emacs23 (655118)
39  emacs23  expat (653526)
40  enscript  file (653481)
41  exiftags  flex (655414)
42  exiv2  freeciv (654809)
 expat  
 fbi  
 fetchmail  
 file  
 firebird2.5  
 flac  
 flex  
 fontforge  
 freeciv  
43  freeradius  freeradius
44  freetype  ganglia (655126)
 fuse  
 ganglia  
 git-core  
45  eglibc  eglibc
46  gmime2.4  gmime2.4
47  pioneers  pioneers
48  gnumeric  gnumeric
49  gnupg  gnupg (653480)
50  gv  gzip (currently broken: 653960)
51  gzip  hashcash (655864)
 hashcash  
52  heartbeat  heartbeat
53  hostapd  hostapd
54  hplip  hplip
 htdig  
55  httrack  httrack
56  hybserv  hylafax (656260)
 hylafax  
57  iceape  iceape
58  iceweasel  iceweasel (653191)
 id3lib3.8.3  
59  imagemagick  imagemagick
60  imlib2  imlib2
61  inotify-tools  inotify-tools
62  ircd-hybrid  ircd-hybrid
63  isakmpd  isakmpd
 isc-dhcp  
64  iscsitarget  iscsitarget
 jasper  
 kaffeine  
65  kazehakase  kazehakase
 kde4libs  
 kdebase  
 kdegraphics  
 kolab-cyrus-imapd  
 krb5  
66  krb5-appl  krb5-appl
 ktorrent  
 kvirc  
67  l2tpns  l2tpns
68  lasso  lasso
69  lcms  lcms (654821)
 lftp  
70  libapache2-mod-authnz-external  libapache2-mod-authnz-external
71  libapache2-mod-auth-pgsql  libapache2-mod-auth-pgsql
72  libapache-mod-auth-kerb  libapache-mod-auth-kerb
73  libapache-mod-jk  libapache-mod-jk
 libarchive  
74  libav  libav
75  cairo  cairo (655128)
76  libcdaudio  libcgroup (654819)
 libcgroup  
 libdbd-pg-perl  
77  libdumb  libdumb
78  libexif  libexif (650998)
79  libextractor  libextractor
80  libfishsound  libfishsound
 libhtml-parser-perl  
 libimager-perl  
81  libmikmod  libmikmod
82  libmodplug  libmodplug (654817)
83  libnet-dns-perl  librpcsecgss (654808)
 libpam-heimdal  
 libpam-krb5  
 libpng  
 librpcsecgss  
 libsmi  
 libsndfile  
 libthai  
84  libtk-img  libtk-img
85  libtool  libtool
86  libtorrent-rasterbar  libtunepimp (654832)
 libtunepimp  
87  libvorbis  libvorbis
88  libwpd  libwpd (653947)
89  libxfont  libxfont (654154)
90  libxml2  libxslt (655601)
91  libxslt  links2 (654807)
92  lighttpd  linux-ftpd (656005)
93  links2  loop-aes-utils (656009)
 linux-ftpd  
 loop-aes-utils  
94  ltsp  ltsp
95  lurker  lurker
96  lvm2  lvm2
97  lynx-cur  maildrop (655133)
 maildrop  
98  mapserver  mapserver
99  maradns  maradns
100  memcached  memcached (655134)
101  mimetex  mimetex
102  mldonkey  mlmmj (655893)
 mlmmj  
 mon  
103  mono  mono
 mpg123  
104  mplayer  mplayer
105  mplayer2  mplayer2
106  forked-daapd  forked-daapd (654147)
 mtr  
107  multipath-tools  multipath-tools
108  mutt  mutt (654148)
109  mysql-ocaml  mysql-ocaml
110  icinga  icinga
111  nas  nas (655743)
112  nbd  nbd (653954)
113  ndiswrapper  ndiswrapper (655249)
114  netpbm-free  netpbm-free (655737)
115  netrik  netrik (656004)
116  net-snmp  net-snmp
 network-manager  
117  newt  newt
118  nginx  nginx
 no-ip  
119  noweb  noweb
 nsd3  
120  nspr  nspr
121  nss  nss
 nss-pam-ldapd  
122  ntp  ntp
123  openafs  openafs
 openexr  
124  open-iscsi  open-iscsi
125  openjdk-6  openjdk-6
 openldap  
126  libreoffice  libreoffice
127  opensaml2  opensaml2 (656006)
128  opensc  openssl (653495)
129  openssl  openswan (655139)
130  openswan  openvpn (655130)
131  openvpn  pam-pgsql (656003)
132  oprofile  pcre3 (656008)
 osiris  
 pam-pgsql  
 pcre3  
 pcsc-lite  
133  pdns  pdns
134  pdns-recursor  pdns-recursor
135  perdition  perdition (655412)
136  perl  perl
 petris  
 pimd  
 pinball  
 pound  
137  ppp  ppp
138  pptpd  pptpd
139  proftpd-dfsg  proftpd-dfsg
140  psi  pstotext (655105)
 pstotext  
141  pygresql  pygresql
 python2.6  
142  python2.7  python2.7
143  python3.2  python3.2
144  python-cjson  python-cjson
 python-crypto  
145  qemu  qemu
146  qemu-kvm  qemu-kvm
147  qt4-x11  qt4-x11
148  qt-x11-free  qt-x11-free
149  rdesktop  rssh (654155)
150  reprepro  rsync (652248)
151  rssh  ruby-gnome2 (655415)
152  rsync  sash (654909)
 ruby-gnome2  
 samba  
 sash  
153  scponly  scponly
154  screen  screen
 sdl-image1.2  
155  slurm-llnl  slurm-llnl
156  smstools  smstools
157  snmptrapfmt  snmptrapfmt
158  socat  socat (654152)
159  spamassassin  spamassassin
160  spamass-milter  spamass-milter
161  speex  speex (655880)
162  splitvt  splitvt (656027)
163  squidguard  squidguard (656028)
164  strongswan  strongswan
165  subversion  subversion
166  sudo  suphp (655419)
167  suphp  syslog-ng (655163)
168  syslog-ng  systemtap (655882)
169  systemtap  tcpreen (655250)
 tcpreen  
170  telepathy-gabble  telepathy-gabble
171  texinfo  texinfo
172  tgt  tgt (656127)
173  thttpd  tinyproxy (655870)
 tinymux  
 tinyproxy  
174  tk8.4  tk8.4
175  tk8.5  tk8.5
 tuxpaint  
 typespeed  
176  unbound  unbound
177  unicon  unicon
178  unzip  unzip (656268)
 util-linux  
 vim  
179  vlc  vlc
180  vnc4  vnc4
181  webcit  webcit
182  webkit  webkit
 wesnoth  
 wget  
183  wine  wine
 wml  
 wv2  
 wxwidgets2.6  
184  wxwidgets2.8  wxwidgets2.8
185  wzdftpd  wzdftpd (655141)
186  x11-xserver-utils  x11-xserver-utils (655503)
187  xapian-omega  xapian-omega
188  xfs  xine-lib (655146)
 xine-lib  
 xmcd  
189  xmlsec1  xmlsec1
190  xml-security-c  xml-security-c
191  xmltooling  xmltooling
 xorg-server  
 xpdf  
 xterm  
192  zabbix  zabbix
 zgv  
193  zodb  zodb
194  zoo  vsftpd (655103)
195    collectd
196    
197    
198  Candidate packages using cdbs, fixed with the next upload after 2011-09-23 with  Packages using dh, but which need additional multiarch changes for compat 9:
199    the upload of dpkg/1.16.1:  opensc
200  koffice  openexr
201  kphone  libtorrent-rasterbar
202    exiv2
203    libcdaudio
204    pcsc-lite
205    id3lib3.8.3
206    
207    
208    Packages using Makefile.PL, needs additional research:
209    libhtml-parser-perl
210    libdbd-pg-perl
211    libimager-perl
212    libnet-dns-perl
213    wml
214    
215    
216    Packages using Scons, needs additional research:
217    blender
218    
219    Packages using cmake, needs additional research:
220    kaffeine
221    kdebase
222    kde4libs
223    kdegraphics
224    ktorrent
225    kvirc
226    wesnoth-1.9
227    psi
228    
229    
230    Packages, which should rather be removed than hardened:
231    cgiirc (suggested removal in #653510)
232    djbdns
233    dkim-milter (currently broken, dropped from testing: #629663)
234    kolab-cyrus-imapd (will be removed and built from the cyrus-2.4 package; #647221)
235    osiris (suggested removal in 655116)
236    
237    
238    
239    Candidate packages using cdbs, needs further studying:
240    sympa
241  libgd2  libgd2
242    icedove
243    ghostscript
244    libvirt
245    gimp
246    koffice
247  libspf2  libspf2
248  wordnet  wordnet
249  sendmail  sendmail
# Line 327  glib2.0 Line 259  glib2.0
259  gnutls26  gnutls26
260  gst-plugins-bad0.10  gst-plugins-bad0.10
261  gst-plugins-good0.10  gst-plugins-good0.10
 gtetrinet  
262  heimdal  heimdal
 icedove  
263  icu  icu
264  jabberd14  jabberd14
265  libapache2-mod-fcgid  libapache2-mod-fcgid
# Line 341  libpam-ldap Line 271  libpam-ldap
271  libsoup2.4  libsoup2.4
272  libtasn1-3  libtasn1-3
273  libtheora  libtheora
 libwmf  
274  link-grammar  link-grammar
275  lsh-server  lsh-server
276  mediawiki  mediawiki
# Line 357  ruby1.9.1 Line 286  ruby1.9.1
286  squid3  squid3
287  streamripper  streamripper
288  sword  sword
 sympa (#644827)  
289  t1lib  t1lib
290  unalz  unalz
291  uw-imap  uw-imap
292  vino  vino
293    
294    
295  Partially fixed:  Fixed:
296  -  samba (2:3.5.11~dfsg-2)
297    mailman (1:2.1.14-3)
298    flac (1.2.1-6)
299    xorg-server (2:1.11.1.901-1)
300    openldap (2.4.25-4)
301    vim (2:7.3.346-1)
302    freetype (2.4.7-2)
303    python-crypto (2.4-1)
304    xorg-server (2:1.11.1.901-1)
305    xpdf (3.03-7)
306    fetchmail (6.3.21-3)
307    libmusicbrainz-2.1 (2.1_2.1.5-6.1)
308    network-manager (0.9.1.95-1)
309    libmusicbrainz-2.1 (2.1_2.1.5-6.1)
310    tmux (1.6~svn2630-2)
311    tcpdump (4.2.0~rc1-2)
312    libthai (0.1.16-1)
313    git (1:1.7.7.2-1)
314    man-db (2.6.0.2-3)
315    elinks (0.12~pre5-6)
316    zgv (5.9-4)
317    jasper (1.900.1-11)
318    xfs (1.0.8-7)
319    fbi (2.07-9)
320    reprepro (4.5.0-1)
321    antiword (0.37-8) (653499)
322    wv2 (0.4.2.dfsg.1-5)
323    dpkg (1.16.1)
324    fuse (2.8.6-3)
325    fontforge (0.0.20110222-6) (653534)
326    apache2 (2.2.21-4)
327    cabextract (1.4-2) (653509)
328    htdig (3.2.0b6-12)
329    xterm (276-2) (653488)
330    enscript (1.6.5.90-2) (653528)
331    amule (2.3.1-2) (653503)
332    gv (1:3.7.1-2)
333    bluez-hcidump (2.1-2) (653507)
334    lighttpd (1.4.30-1) (654151)
335    pimd (2.1.8-2) (654081)
336    chmlib (2:0.40a-2) (653955)
337    lynx-cur (6.6.7-4) (654097)
338    rdesktop (1.7.0-2) (653498)
339    libpam-krb5 (4.5-3) (654293)
340    curl (7.23.1-3) (654521)
341    audiofile (0.3.2-1) (651029)
342    libarchive (2.8.5-2)
343    courier (0.66.3-2) (654794)
344    libsndfile (1.0.25-4) (654831)
345    libwmf (0.2.8.4-10)
346    exiftags (1.01-5) (654804)
347    nss-pam-ldapd (0.8.5)
348    isc-dhcp (4.2.2-2)
349    sdl-image1.2 (1.2.10-3)
350    mtr (0.82-2) (654117)
351    dia (0.97.2-4)
352    libpng (1.2.46-4) (654149)
353    mldonkey (3.1.0-3) (655140)
354    avahi (0.6.30-6) (655188)
355    mon (1.2.0-5) (655137)
356    acpid (1:2.0.14-2) (653502)
357    libsmi (0.4.8+dfsg2-5) (654812)
358    sudo (1.8.3p1-3) (655417)
359    zoo (2.10-25) (655499)
360    citadel (8.04-1) (653514)
361    firebird2.5 (2.5.2~svn+53854.ds4-1) (654793)
362    wget (1.13.4-2) (654908)
363    krb5 (1.10+dfsg~beta1-1) (655248)
364    libxml2 (2.7.8.dfsg-6) (654903)
365    lftp (4.3.4-1)
366    
367    
368    
369    
370    Hardening incomplete:
371    gtetrinet (653443)
372    ncompress (relro missing)
373    
 Fixed through cdbs (log or pkg should be checked, before moving to  
 Resolved/fixed, since some Makefile or buildsystem foo might reset  
 flags)  
 libvirt (0.9.6-1)  
 gimp (2.6.11-4)  
 ghostscript (9.04~dfsg-1)  
374    
375    Packages, which use hardened build flags manually, but not yet dpkg-buildflags:
376    apr
377    apr-util
378    pound (654833)
379    mpg123
380    
 Resolved/fixed:  
 mailman (1:2.1.14-3)  
 ncompress (4.2.4.4-3)  
 xzgv (5.9-3)  
 libmusicbrainz-2.1 (2.1_2.1.5-6.1)  
381    
382    
383  Packages using hardening-wrapper/-includes (these are considered fixed, although  Packages using hardening-wrapper/-includes (these are considered fixed, although
384     switching them over to dpkg-buildflags might be worthwhile later on):     switching them over to dpkg-buildflags might be worthwhile later on):
 tmux  
385  netatalk  netatalk
 man-db  
386  graphicsmagick  graphicsmagick
387  udev  udev
388  xfce4-terminal  xfce4-terminal
389  openssh  openssh
390  evolution  evolution
391  dbus  dbus
 tcpdump  
392  libgsf  libgsf
393  tor  tor
394  evolution-data-server  evolution-data-server
# Line 421  znc Line 416  znc
416  cyrus-sasl2  cyrus-sasl2
417  ldns  ldns
418  quagga  quagga
419    nsd3
420    
421    
422    

Legend:
Removed from v.17396  
changed lines
  Added in v.18197

  ViewVC Help
Powered by ViewVC 1.1.5