/[secure-testing]/sarge-checks/CAN/list
ViewVC logotype

Diff of /sarge-checks/CAN/list

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 75 by stef-guest, Thu Nov 4 20:20:53 2004 UTC revision 127 by joeyh, Wed Nov 17 19:13:26 2004 UTC
# Line 1  Line 1 
1    CAN-2004-1033
2            NOTE: not in database yet
3            NOTE: bugtraq 1CE07882ECEE894CA2D5A89B8DEBC4010A2DD3@porgy.admin.idefense.com
4            - fcron 2.9.5.1 (unfixed; bug #281436)
5    CAN-2004-1032
6            NOTE: not in database yet
7            NOTE: bugtraq 1CE07882ECEE894CA2D5A89B8DEBC4010A2DD3@porgy.admin.idefense.com
8            - fcron 2.9.5.1 (unfixed; bug #281436)
9    CAN-2004-1031
10            NOTE: not in database yet
11            NOTE: bugtraq 1CE07882ECEE894CA2D5A89B8DEBC4010A2DD3@porgy.admin.idefense.com
12            - fcron 2.9.5.1 (unfixed; bug #281436)
13    CAN-2004-1030
14            NOTE: not in database yet
15            NOTE: bugtraq 1CE07882ECEE894CA2D5A89B8DEBC4010A2DD3@porgy.admin.idefense.com
16            - fcron 2.9.5.1 (unfixed; bug #281436)
17    
18    CAN-2004-1024
19            NOTE: reserved
20    CAN-2004-1023
21            NOTE: reserved
22    CAN-2004-1022
23            NOTE: reserved
24    CAN-2004-1021
25            NOTE: reserved
26    CAN-2004-1020
27            NOTE: reserved
28    CAN-2004-1019
29            NOTE: reserved
30    CAN-2004-1018
31            NOTE: reserved
32    CAN-2004-1017
33            NOTE: reserved
34    CAN-2004-1016
35            NOTE: reserved
36    CAN-2004-1015
37            NOTE: reserved
38    CAN-2004-1014
39            NOTE: reserved
40    CAN-2004-1013
41            NOTE: reserved
42    CAN-2004-1012
43            NOTE: reserved
44    CAN-2004-1011
45            NOTE: reserved
46    CAN-2004-1010
47            - zip 2.30-7
48    CAN-2004-1009
49            NOTE: reserved
50  CAN-2004-1008  CAN-2004-1008
51          NOTE: reserved          NOTE: reserved
52  CAN-2004-1007  CAN-2004-1007
# Line 5  CAN-2004-1007 Line 54  CAN-2004-1007
54  CAN-2004-1006  CAN-2004-1006
55          NOTE: reserved          NOTE: reserved
56          NOTE: covered by DSA-584-1          NOTE: covered by DSA-584-1
57            - dhcp 2.0pl5-19.1
58  CAN-2004-1005  CAN-2004-1005
59          NOTE: reserved          NOTE: reserved
60  CAN-2004-1004  CAN-2004-1004
# Line 36  CAN-2004-0992 Line 86  CAN-2004-0992
86  CAN-2004-0991  CAN-2004-0991
87          NOTE: reserved          NOTE: reserved
88  CAN-2004-0990  CAN-2004-0990
89          TODO: probably vulnerable, check libgd1 and libgd2 and file bugs          NOTE: covered by DSA-589-1
90            NOTE: covered by DSA-591-1
91  CAN-2004-0989  CAN-2004-0989
92          NOTE: covered by DSA-582-1          NOTE: covered by DSA-582-1
93  CAN-2004-0988  CAN-2004-0988
# Line 45  CAN-2004-0987 Line 96  CAN-2004-0987
96          NOTE: reserved          NOTE: reserved
97  CAN-2004-0986  CAN-2004-0986
98          NOTE: reserved          NOTE: reserved
99            - iptables 1.2.11-4
100  CAN-2004-0985  CAN-2004-0985
101          NOTE: not-for-us (windows)          NOTE: not-for-us (windows)
102  CAN-2004-0984  CAN-2004-0984
103          NOTE: reserved          NOTE: reserved
104            - mailutils 1:0.5-4
105  CAN-2004-0983  CAN-2004-0983
106          NOTE: reserved          NOTE: reserved
107            - ruby1.8 1.8.1+1.8.2pre2-4
108            - ruby1.6 1.6.8-12
109  CAN-2004-0982  CAN-2004-0982
110          NOTE: reserved          NOTE: reserved
111            - mpg123 0.59r-17
112  CAN-2004-0981  CAN-2004-0981
113          NOTE: reserved          NOTE: reserved
114            - imagemagick 6:6.0.6.2-1.5
115            NOTE: covered by DSA-593-1
116  CAN-2004-0980  CAN-2004-0980
117          NOTE: reserved          NOTE: reserved
118            - ez-ipupdate 3.0.11b8-8
119  CAN-2004-0979  CAN-2004-0979
120          NOTE: not-for-us (windows)          NOTE: not-for-us (windows)
121  CAN-2004-0978  CAN-2004-0978
122          NOTE: not-for-us (windows)          NOTE: not-for-us (windows)
123  CAN-2004-0977 [local; low]  CAN-2004-0977
124          - postgresql 7.4.6-1          - postgresql 7.4.6-1
125  CAN-2004-0976 [local; low]  CAN-2004-0976
126          - perl (unfixed; bug #278404)          - perl 5.8.4-4
127  CAN-2004-0975 [local; low]  CAN-2004-0975
128          - openssl (unfixed; bug #278260)          - openssl 0.9.7e-1
129            NOTE: also includes other security fixes than this CAN
130  CAN-2004-0974 [local; low]  CAN-2004-0974 [local; low]
131          - netatalk 1.6.4a-1          - netatalk 1.6.4a-1
132  CAN-2004-0973  CAN-2004-0973
133          NOTE: rejected          NOTE: rejected
134  CAN-2004-0972  CAN-2004-0972
135          NOTE: lvmcreate_initrd not in debian          NOTE: lvmcreate_initrd not in debian
136  CAN-2004-0971 [local; low]  CAN-2004-0971
137          - kbr5 (unfixed; bug #278271; not shipped in binary package)          - kbr5 (unfixed; bug #278271; not shipped in binary package)
138          - arla 0.36.2-11          - arla 0.36.2-11
139  CAN-2004-0970 [local; medium]  CAN-2004-0970
140          NOTE: sarge is not vulnerable as our version uses set -C          NOTE: sarge is not vulnerable as our version uses set -C
141  CAN-2004-0969 [local; medium]  CAN-2004-0969
142          - groff 1.18.1.1-2          - groff 1.18.1.1-2
143  CAN-2004-0968 [local; medium]  CAN-2004-0968
144          - libc6 (unfixed; bug #278278)          - libc6 (unfixed; bug #278278)
145  CAN-2004-0967 [local; medium]  CAN-2004-0967
146          - gs-common 0.3.6-0.1          - gs-common 0.3.6-0.1
147  CAN-2004-0966 [local; medium]  CAN-2004-0966
148          - gettext 0.14.1-6          - gettext 0.14.1-6
149  CAN-2004-0965  CAN-2004-0965
150          NOTE: reserved          NOTE: reserved
151  CAN-2004-0964  CAN-2004-0964
152            NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
153            NOTE: DSA says zinf not vulnerable in sarge
154          - zinf 2.2.5          - zinf 2.2.5
155  CAN-2004-0963  CAN-2004-0963
156          NOTE: not-for-us (windows)          NOTE: not-for-us (windows)
# Line 106  CAN-2004-0957 Line 168  CAN-2004-0957
168          - mysql-dfsg 3.23.58          - mysql-dfsg 3.23.58
169          - mysql 3.23.58          - mysql 3.23.58
170  CAN-2004-0956  CAN-2004-0956
171            NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
172          NOTE: reserved          NOTE: reserved
173  CAN-2004-0955  CAN-2004-0955
174          NOTE: reserved          NOTE: reserved
# Line 136  CAN-2004-0943 Line 199  CAN-2004-0943
199          NOTE: reserved          NOTE: reserved
200  CAN-2004-0942  CAN-2004-0942
201          NOTE: reserved          NOTE: reserved
202            - apache2 2.0.52-2
203  CAN-2004-0941  CAN-2004-0941
204          NOTE: reserved          NOTE: reserved
205  CAN-2004-0940  CAN-2004-0940
206          NOTE: reserved          NOTE: reserved
207            - apache 1.3.33-2
208  CAN-2004-0939  CAN-2004-0939
209          NOTE: reserved          NOTE: reserved
210  CAN-2004-0938  CAN-2004-0938
# Line 160  CAN-2004-0931 Line 225  CAN-2004-0931
225          NOTE: reserved          NOTE: reserved
226  CAN-2004-0930  CAN-2004-0930
227          NOTE: reserved          NOTE: reserved
228            NOTE: according to bugtraq post, this is a DOS in samba 3.0.x <= 3.0.7
229            NOTE: newer version in testing
230  CAN-2004-0929  CAN-2004-0929
231          NOTE: reserved          NOTE: reserved
232  CAN-2004-0928  CAN-2004-0928
# Line 263  CAN-2004-0890 Line 330  CAN-2004-0890
330  CAN-2004-0889  CAN-2004-0889
331          NOTE: reserved          NOTE: reserved
332          NOTE: covered by DSA-573-1          NOTE: covered by DSA-573-1
333            - 3.00-10
334  CAN-2004-0888  CAN-2004-0888
335          NOTE: reserved          NOTE: reserved
336          NOTE: covered by DSA-573-1          NOTE: covered by DSA-573-1
# Line 275  CAN-2004-0886 Line 343  CAN-2004-0886
343          NOTE: reserved          NOTE: reserved
344          NOTE: covered by DSA-567-1          NOTE: covered by DSA-567-1
345  CAN-2004-0885  CAN-2004-0885
346          - apache2 2.0.53          - apache2 2.0.52-2
347  CAN-2004-0884  CAN-2004-0884
348          NOTE: covered by DSA-563-1          NOTE: covered by DSA-563-1
349  CAN-2004-0883  CAN-2004-0883
350          NOTE: reserved          NOTE: reserved
351  CAN-2004-0882  CAN-2004-0882
352          NOTE: reserved          NOTE: reserved
353            NOTE: details http://security.e-matters.de/advisories/132004.html
354            - samba 3.0.7
355  CAN-2004-0881  CAN-2004-0881
356          NOTE: covered by DSA-553-1          NOTE: covered by DSA-553-1
357  CAN-2004-0880  CAN-2004-0880
# Line 348  CAN-2004-0851 Line 418  CAN-2004-0851
418  CAN-2004-0850  CAN-2004-0850
419          - star 1.5a46          - star 1.5a46
420  CAN-2004-0849  CAN-2004-0849
421            NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
422          HELP: which radius daemon in debian is "GNU Radius" (if any)?          HELP: which radius daemon in debian is "GNU Radius" (if any)?
423  CAN-2004-0848  CAN-2004-0848
424          NOTE: reserved          NOTE: reserved
# Line 394  CAN-2004-0828 Line 465  CAN-2004-0828
465          NOTE: not-fos-us (AIX)          NOTE: not-fos-us (AIX)
466  CAN-2004-0827  CAN-2004-0827
467          NOTE: covered by DSA-547-1          NOTE: covered by DSA-547-1
468            - imagemagick 5:6.0.7.1-1
469  CAN-2004-0826  CAN-2004-0826
470          NOTE: not-for-us (netscape NSS)          NOTE: not-for-us (netscape NSS)
471  CAN-2004-0825  CAN-2004-0825
# Line 412  CAN-2004-0819 Line 484  CAN-2004-0819
484          NOTE: not-for-us (openbsd)          NOTE: not-for-us (openbsd)
485    
486  CAN-2004-0818  CAN-2004-0818
487            NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
488          NOTE: reserved          NOTE: reserved
489  CAN-2004-0817  CAN-2004-0817
490          NOTE: covered by DSA-548-1          NOTE: covered by DSA-548-1
# Line 442  CAN-2004-0806 Line 515  CAN-2004-0806
515          - cdrtools 4:2.0+a34-2          - cdrtools 4:2.0+a34-2
516  CAN-2004-0805  CAN-2004-0805
517          NOTE: covered by DSA-564-1          NOTE: covered by DSA-564-1
518            - mpg123 0.59r-16
519  CAN-2004-0804  CAN-2004-0804
520            NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
521          NOTE: covered by DSA-567-1          NOTE: covered by DSA-567-1
522  CAN-2004-0803  CAN-2004-0803
523          NOTE: reserved          NOTE: reserved
# Line 480  CAN-2004-0788 Line 555  CAN-2004-0788
555  CAN-2004-0787  CAN-2004-0787
556          NOTE: not-for-us (seems OpenCA is not in Debian)          NOTE: not-for-us (seems OpenCA is not in Debian)
557  CAN-2004-0786  CAN-2004-0786
558            NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
559          - apache2 2.0.51          - apache2 2.0.51
560  CAN-2004-0785  CAN-2004-0785
561          - gaim 0.82          - gaim 0.82
# Line 499  CAN-2004-0779 Line 575  CAN-2004-0779
575  CAN-2004-0778  CAN-2004-0778
576          - cvs 1.12.9          - cvs 1.12.9
577  CAN-2004-0777  CAN-2004-0777
578            NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
579          - courier-imap 2.2.2          - courier-imap 2.2.2
580  CAN-2004-0776  CAN-2004-0776
581          NOTE: reserved          NOTE: reserved
# Line 568  CAN-2004-0749 Line 645  CAN-2004-0749
645  CAN-2004-0748  CAN-2004-0748
646          - apache2 2.0.51          - apache2 2.0.51
647  CAN-2004-0747  CAN-2004-0747
648            NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
649          - apache2 2.0.51          - apache2 2.0.51
650  CAN-2004-0746  CAN-2004-0746
651          - kdelibs 4:3.2.3-3.sarge.1          - kdelibs 4:3.2.3-3.sarge.1
652          NOTE: in t-p-u; 4.3.3 in unstable also fixes it          NOTE: in t-p-u; 4.3.3 in unstable also fixes it
653  CAN-2004-0745  CAN-2004-0745
654          TODO: unsure if fixed, probably not. Mailed lha maintainer.          - lha 1.14i-10
         NOTE: GOTO says first he heard of it, is checking.  
655  CAN-2004-0744  CAN-2004-0744
656          NOTE: not-for-us (MacOS)          NOTE: not-for-us (MacOS)
657  CAN-2004-0743  CAN-2004-0743
# Line 680  CAN-2004-0695 Line 757  CAN-2004-0695
757          NOTE: not-for-us (WebSTAR)          NOTE: not-for-us (WebSTAR)
758  CAN-2004-0694  CAN-2004-0694
759          NOTE: reserved          NOTE: reserved
760            - lha 1.14i-10
761  CAN-2004-0693  CAN-2004-0693
762          NOTE: covered by DSA-542-1          NOTE: covered by DSA-542-1
763  CAN-2004-0692  CAN-2004-0692
# Line 752  CAN-2004-0660 Line 830  CAN-2004-0660
830  CAN-2004-0659  CAN-2004-0659
831          NOTE: not-for-us (mplayer)          NOTE: not-for-us (mplayer)
832  CAN-2004-0658  CAN-2004-0658
833          TODO: what kernel version fixed this?          NOTE: invalid according to www.osvdb.org/7253
834  CAN-2004-0657  CAN-2004-0657
835          - ntp 4.0          - ntp 4.0
836  CAN-2004-0656  CAN-2004-0656
# Line 833  CAN-2004-0621 Line 911  CAN-2004-0621
911  CAN-2004-0620  CAN-2004-0620
912          NOTE: not-for-us (vBulletin)          NOTE: not-for-us (vBulletin)
913  CAN-2004-0619  CAN-2004-0619
914          TODO: unchecked          NOTE: not-for-us (Linux Broadcom 5820 cryptonet driver)
915            NOTE: does not seem to be part of linux kernel or other package
916  CAN-2004-0618  CAN-2004-0618
917          NOTE: not-for-us (freebsd)          NOTE: not-for-us (freebsd)
918  CAN-2004-0617  CAN-2004-0617
# Line 924  CAN-2004-0578 Line 1003  CAN-2004-0578
1003  CAN-2004-0577  CAN-2004-0577
1004          NOTE: not-for-us (Wingate)          NOTE: not-for-us (Wingate)
1005  CAN-2004-0576  CAN-2004-0576
1006          HELP: which one is GNU radius?          NOTE: not-for-us (GNU radius not in Debian)
         TODO: unchecked  
1007  CAN-2004-0575  CAN-2004-0575
1008          NOTE: not-for-us (Windows)          NOTE: not-for-us (Windows)
1009  CAN-2004-0574  CAN-2004-0574
# Line 1097  CAN-2004-0493 Line 1175  CAN-2004-0493
1175          - apache2 2.0.50-1          - apache2 2.0.50-1
1176  CAN-2004-0492  CAN-2004-0492
1177          NOTE: covered by DSA-525          NOTE: covered by DSA-525
1178            - apache 1.3.31-2
1179  CAN-2004-0491  CAN-2004-0491
1180          NOTE: reserved          NOTE: reserved
1181  CAN-2004-0490  CAN-2004-0490
# Line 1294  CAN-2004-0401 Line 1373  CAN-2004-0401
1373          - libtasn1 0.1.2-2          - libtasn1 0.1.2-2
1374  CAN-2004-0400  CAN-2004-0400
1375          NOTE: covered by DSA-501          NOTE: covered by DSA-501
1376            - exim 3.36-11
1377  CAN-2004-0399  CAN-2004-0399
1378          NOTE: covered by DSA-501          NOTE: covered by DSA-501
1379            - exim 3.36-11
1380  CAN-2004-0398  CAN-2004-0398
1381          NOTE: covered by DSA-506          NOTE: covered by DSA-506
1382    
# Line 1704  CAN-2004-0186 Line 1785  CAN-2004-0186
1785          NOTE: covered by DSA-463          NOTE: covered by DSA-463
1786  CAN-2004-0184  CAN-2004-0184
1787          NOTE: covered by DSA-478          NOTE: covered by DSA-478
1788            - tcpdump 3.7.2-4
1789  CAN-2004-0183  CAN-2004-0183
1790          NOTE: covered by DSA-478          NOTE: covered by DSA-478
1791            - tcpdump 3.7.2-4
1792  CAN-2004-0182  CAN-2004-0182
1793          NOTE: not-for-us (mailman; RedHat specific bug)          NOTE: not-for-us (mailman; RedHat specific bug)
1794  CAN-2004-0181  CAN-2004-0181
# Line 2329  begin claimed by pdwerryh-guest Line 2412  begin claimed by pdwerryh-guest
2412  CAN-2003-0899  CAN-2003-0899
2413          NOTE: covered by DSA-396          NOTE: covered by DSA-396
2414  CAN-2003-0898  CAN-2003-0898
2415            NOTE: not-for-us (IBM DB2)
2416  CAN-2003-0897  CAN-2003-0897
2417            NOTE: not-for-us (microsoft)
2418  CAN-2003-0896  CAN-2003-0896
2419            NOTE: not-for-us (Sun/Java)
2420  CAN-2003-0895  CAN-2003-0895
2421            NOTE: not-for-us (Apple)
2422  CAN-2003-0894  CAN-2003-0894
2423            NOTE: not-for-us (Oracle)
2424  CAN-2003-0893  CAN-2003-0893
2425          NOTE: reserved          NOTE: reserved
2426  CAN-2003-0892  CAN-2003-0892
# Line 2354  CAN-2003-0885 Line 2442  CAN-2003-0885
2442  CAN-2003-0884  CAN-2003-0884
2443          NOTE: reserved          NOTE: reserved
2444  CAN-2003-0883  CAN-2003-0883
2445            NOTE: not-for-us (Apple)
2446  CAN-2003-0882  CAN-2003-0882
2447            NOTE: not-for-us (Apple)
2448  CAN-2003-0881  CAN-2003-0881
2449            NOTE: not-for-us (Apple)
2450  CAN-2003-0880  CAN-2003-0880
2451            NOTE: not-for-us (Apple)
2452  CAN-2003-0879  CAN-2003-0879
2453          NOTE: rejected          NOTE: rejected
2454  CAN-2003-0878  CAN-2003-0878
2455            NOTE: not-for-us (Apple)
2456  CAN-2003-0877  CAN-2003-0877
2457            NOTE: not-for-us (Apple)
2458  CAN-2003-0876  CAN-2003-0876
2459  CAN-2003-0875          NOTE: not-for-us (Apple)
2460    CAN-2003-0875 [source package only]
2461            NOTE: openslp: slpd.all_init symlink vuln
2462            NOTE: this file is not used in Debian, so it's not a problem for us.
2463            NOTE: source package still distributes the file, however.
2464            TODO: submitted to BTS. waiting for response.
2465            - openslp (unfixed; bug #279973; only problem in source package)
2466  CAN-2003-0874  CAN-2003-0874
2467            NOTE: not-for-us (Deskpro)
2468  CAN-2003-0873  CAN-2003-0873
2469          NOTE: reserved          NOTE: reserved
2470  CAN-2003-0872  CAN-2003-0872
2471            NOTE: not-for-us (SCO)
2472  CAN-2003-0871  CAN-2003-0871
2473            NOTE: not-for-us (Apple)
2474  CAN-2003-0870  CAN-2003-0870
2475            NOTE: not-for-us (Opera)
2476  CAN-2003-0869  CAN-2003-0869
2477          NOTE: reserved          NOTE: reserved
2478  CAN-2003-0868  CAN-2003-0868
# Line 2379  CAN-2003-0866 Line 2483  CAN-2003-0866
2483          NOTE: covered by DSA-395          NOTE: covered by DSA-395
2484  CAN-2003-0865  CAN-2003-0865
2485          NOTE: covered by DSA-435          NOTE: covered by DSA-435
2486            - mpg123 0.59r-15
2487  CAN-2003-0864  CAN-2003-0864
2488            - ircd-irc2 2.10.3p5-1
2489  CAN-2003-0863  CAN-2003-0863
2490            NOTE: php4, this bug appears not to have been fixed.
2491            NOTE: submitted to BTS on libapache-mod-php4
2492            TODO: waiting for response
2493  CAN-2003-0862  CAN-2003-0862
2494          NOTE: rejected          NOTE: rejected
2495  CAN-2003-0861  CAN-2003-0861
2496            - php4 4:4.3.3-1
2497  CAN-2003-0860  CAN-2003-0860
2498            - php4 4:4.3.3-1
2499  CAN-2003-0859  CAN-2003-0859
2500            NOTE: affects glibc 2.2.4, Debian uses 2.3.2
2501  CAN-2003-0858  CAN-2003-0858
2502          NOTE: covered by DSA-415          NOTE: covered by DSA-415
2503  CAN-2003-0857  CAN-2003-0857
2504          NOTE: reserved          NOTE: reserved
2505  CAN-2003-0856  CAN-2003-0856
2506          NOTE: covered by DSA-492          NOTE: covered by DSA-492
2507            - iproute 20010824-13.1
2508  CAN-2003-0855  CAN-2003-0855
2509            - pan 0.13.4-1
2510  CAN-2003-0854  CAN-2003-0854
2511            - coreutils 5.2.1-1
2512  CAN-2003-0853  CAN-2003-0853
2513            - coreutils 5.2.1-1
2514  CAN-2003-0852  CAN-2003-0852
2515            - sylpheed-claws 0.9.8claws-1
2516  CAN-2003-0851  CAN-2003-0851
2517            NOTE: affects openssl 0.9.6. Testing uses 0.9.7.
2518  CAN-2003-0850  CAN-2003-0850
2519          NOTE: covered by DSA-410          NOTE: covered by DSA-410
2520            - libnids1 1.18-1
2521  CAN-2003-0849  CAN-2003-0849
2522            - cfengine2 2.0.9+2.1.0b3-1
2523  CAN-2003-0848  CAN-2003-0848
2524          NOTE: covered by DSA-428          NOTE: covered by DSA-428
2525            - slocate 2.7-3
2526  CAN-2003-0847  CAN-2003-0847
2527            NOTE: not-for-us (SuSE)
2528  CAN-2003-0846  CAN-2003-0846
2529            NOTE: not-for-us (SuSE)
2530  CAN-2003-0845  CAN-2003-0845
2531            NOTE: not-for-us (JBoss)
2532  CAN-2003-0844  CAN-2003-0844
2533            NOTE: libapache-mod-gzip, vulnerable only when compiled in debug mode
2534            NOTE: Debian doesn't enable MOD_GZIP_DEBUG1.
2535  CAN-2003-0843  CAN-2003-0843
2536            NOTE: libapache-mod-gzip, vulnerable only when compiled in debug mode
2537            NOTE: Debian doesn't enable MOD_GZIP_DEBUG1.
2538  CAN-2003-0842  CAN-2003-0842
2539            NOTE: libapache-mod-gzip, vulnerable only when compiled in debug mode
2540            NOTE: Debian doesn't enable MOD_GZIP_DEBUG1.
2541  CAN-2003-0841  CAN-2003-0841
2542            NOTE: not-for-us (Peoplesoft)
2543  CAN-2003-0840  CAN-2003-0840
2544            NOTE: not-for-us (HPUX)
2545  CAN-2003-0839  CAN-2003-0839
2546            NOTE: not-for-us (microsoft)
2547  CAN-2003-0838  CAN-2003-0838
2548            NOTE: not-for-us (microsoft)
2549  CAN-2003-0837  CAN-2003-0837
2550            NOTE: not-for-us (IBM DB2)
2551  CAN-2003-0836  CAN-2003-0836
2552            NOTE: not-for-us (IBM DB2)
2553  CAN-2003-0835  CAN-2003-0835
2554            NOTE: not-for-us (mplayer)
2555  CAN-2003-0834  CAN-2003-0834
2556            NOTE: not-for-us (CDE)
2557  CAN-2003-0833  CAN-2003-0833
2558          NOTE: covered by DSA-392          NOTE: covered by DSA-392
2559            - webfs 1.20
2560  CAN-2003-0832  CAN-2003-0832
2561          NOTE: covered by DSA-392          NOTE: covered by DSA-392
2562            - webfs 1.20
2563  CAN-2003-0831  CAN-2003-0831
2564            - proftpd 1.2.9-1
2565  CAN-2003-0830  CAN-2003-0830
2566          NOTE: covered by DSA-390          NOTE: covered by DSA-390
2567            NOTE: marbles package not in testing or unstable
2568  CAN-2003-0829  CAN-2003-0829
2569          NOTE: reserved          NOTE: reserved
2570  CAN-2003-0828  CAN-2003-0828
2571          NOTE: covered by DSA-391          NOTE: covered by DSA-391
2572            - freesweep 0.88-4.1
2573  CAN-2003-0827  CAN-2003-0827
2574            NOTE: not-for-us (IBM DB2)
2575  CAN-2003-0826  CAN-2003-0826
2576            - lsh-server 1.4.2-6
2577  CAN-2003-0824  CAN-2003-0824
2578            NOTE: not-for-us (microsoft)
2579  CAN-2003-0823  CAN-2003-0823
2580            NOTE: not-for-us (microsoft)
2581  CAN-2003-0822  CAN-2003-0822
2582            NOTE: not-for-us (microsoft)
2583  CAN-2003-0821  CAN-2003-0821
2584            NOTE: not-for-us (microsoft)
2585  CAN-2003-0820  CAN-2003-0820
2586            NOTE: not-for-us (microsoft)
2587  CAN-2003-0819  CAN-2003-0819
2588            NOTE: not-for-us (microsoft)
2589  CAN-2003-0818  CAN-2003-0818
2590            NOTE: not-for-us (microsoft)
2591  CAN-2003-0817  CAN-2003-0817
2592            NOTE: not-for-us (microsoft)
2593  CAN-2003-0816  CAN-2003-0816
2594            NOTE: not-for-us (microsoft)
2595  CAN-2003-0815  CAN-2003-0815
2596            NOTE: not-for-us (microsoft)
2597  CAN-2003-0814  CAN-2003-0814
2598            NOTE: not-for-us (microsoft)
2599  CAN-2003-0813  CAN-2003-0813
2600            NOTE: not-for-us (microsoft)
2601  CAN-2003-0812  CAN-2003-0812
2602            NOTE: not-for-us (microsoft)
2603  CAN-2003-0811  CAN-2003-0811
2604          NOTE: reserved          NOTE: reserved
2605  CAN-2003-0810  CAN-2003-0810
2606          NOTE: reserved          NOTE: reserved
2607  CAN-2003-0809  CAN-2003-0809
2608          - apache2 2.0.51          NOTE: not-for-us (microsoft)
2609  CAN-2003-0808  CAN-2003-0808
2610          NOTE: reserved          NOTE: reserved
2611  CAN-2003-0807  CAN-2003-0807
2612            NOTE: not-for-us (microsoft)
2613  CAN-2003-0806  CAN-2003-0806
2614            NOTE: not-for-us (microsoft)
2615  CAN-2003-0805  CAN-2003-0805
2616          NOTE: covered by DSA-387          NOTE: covered by DSA-387
2617            NOTE: gopherd not in testing or unstable (deprecated)
2618  CAN-2003-0804  CAN-2003-0804
2619            NOTE: not-for-us (BSD)
2620  CAN-2003-0803  CAN-2003-0803
2621            NOTE: not-for-us (Nokia)
2622  CAN-2003-0802  CAN-2003-0802
2623            NOTE: not-for-us (Nokia)
2624  CAN-2003-0801  CAN-2003-0801
2625            NOTE: not-for-us (Nokia)
2626  CAN-2003-0800  CAN-2003-0800
2627          NOTE: reserved          NOTE: reserved
2628    
# Line 2671  CAN-2003-0699 Line 2836  CAN-2003-0699
2836          NOTE: fixed in 2.4.21-rc2          NOTE: fixed in 2.4.21-rc2
2837  CAN-2003-0698  CAN-2003-0698
2838          NOTE: reserved          NOTE: reserved
2839            - exim 3.36-8
2840  CAN-2003-0697  CAN-2003-0697
2841          NOTE: not-for-us (AIX)          NOTE: not-for-us (AIX)
2842  CAN-2003-0696  CAN-2003-0696
# Line 2683  CAN-2003-0694 Line 2849  CAN-2003-0694
2849  CAN-2003-0693  CAN-2003-0693
2850          NOTE: covered by DSA-382          NOTE: covered by DSA-382
2851          NOTE: covered by DSA-383          NOTE: covered by DSA-383
2852            - openssh 1:3.6.1p2-6.0
2853  CAN-2003-0692  CAN-2003-0692
2854          NOTE: covered by DSA-388          NOTE: covered by DSA-388
2855  CAN-2003-0691  CAN-2003-0691
# Line 2707  CAN-2003-0683 Line 2874  CAN-2003-0683
2874  CAN-2003-0682  CAN-2003-0682
2875          NOTE: covered by DSA-382          NOTE: covered by DSA-382
2876          NOTE: covered by DSA-383          NOTE: covered by DSA-383
2877            - openssh 1:3.6.1p2-9
2878  CAN-2003-0681  CAN-2003-0681
2879          NOTE: covered by DSA-384          NOTE: covered by DSA-384
2880  CAN-2003-0680  CAN-2003-0680
# Line 2871  CAN-2003-0601 Line 3039  CAN-2003-0601
3039          NOTE: not-for-us (Apple)          NOTE: not-for-us (Apple)
3040  CAN-2003-0600  CAN-2003-0600
3041          NOTE: reserved          NOTE: reserved
   
 begin claimed by joeyh  
   
3042  CAN-2003-0599  CAN-2003-0599
3043          NOTE: covered by DSA-365          NOTE: covered by DSA-365
3044  CAN-2003-0598  CAN-2003-0598
3045          NOTE: rejected          NOTE: rejected
3046  CAN-2003-0597  CAN-2003-0597
3047          TODO: check          NOTE: not-for-us (Unixware)
3048  CAN-2003-0596  CAN-2003-0596
3049          NOTE: covered by DSA-352          - fdclone 2.02a
3050  CAN-2003-0595  CAN-2003-0595
3051          TODO: check          NOTE: not-for-us (WiTango Application Server and Tango 2000)
3052  CAN-2003-0594  CAN-2003-0594
3053            NOTE: cannot find reference to it being fixed.
3054          TODO: check          TODO: check
3055  CAN-2003-0593  CAN-2003-0593
3056          TODO: check          NOTE: not-for-us (opera)
3057  CAN-2003-0592  CAN-2003-0592
3058          NOTE: covered by DSA-459          NOTE: covered by DSA-459
3059  CAN-2003-0591  CAN-2003-0591
3060          NOTE: rejected          NOTE: rejected
3061  CAN-2003-0590  CAN-2003-0590
3062          TODO: check          NOTE: not-for-us (Splatt Forum)
3063  CAN-2003-0589  CAN-2003-0589
3064          TODO: check          NOTE: not-for-us (Digi-ads)
3065  CAN-2003-0588  CAN-2003-0588
3066          TODO: check          NOTE: not-for-us (Digi-news)
3067  CAN-2003-0587  CAN-2003-0587
3068          TODO: check          NOTE: not-for-us (Infopop Ultimate Bulletin Board (UBB))
3069  CAN-2003-0586  CAN-2003-0586
3070          TODO: check          NOTE: not-for-us (Brooky eStore)
3071  CAN-2003-0585  CAN-2003-0585
3072          TODO: check          NOTE: not-for-us (Brooky eStore)
3073  CAN-2003-0584  CAN-2003-0584
3074          TODO: check          NOTE: not-for-us (BRU)
3075  CAN-2003-0583  CAN-2003-0583
3076          - usermin 1.090-1          NOTE: not-for-us (BRU)
3077  CAN-2003-0582  CAN-2003-0582
3078          NOTE: rejected          NOTE: rejected
3079  CAN-2003-0581  CAN-2003-0581
3080          NOTE: covered by DSA-360          NOTE: covered by DSA-360
3081  CAN-2003-0580  CAN-2003-0580
3082          TODO: check          NOTE: not-for-us (IBM U2 UniVerse)
3083  CAN-2003-0579  CAN-2003-0579
3084          TODO: check          NOTE: not-for-us (IBM U2 UniVerse)
3085  CAN-2003-0578  CAN-2003-0578
3086          TODO: check          NOTE: not-for-us (IBM U2 UniVerse)
3087  CAN-2003-0577  CAN-2003-0577
3088          TODO: check          - mpg123 0.59r-1
3089  CAN-2003-0576  CAN-2003-0576
3090          TODO: check          NOTE: not-for-us (IRIX)
3091  CAN-2003-0575  CAN-2003-0575
3092          TODO: check          NOTE: not-for-us (IRIX)
3093  CAN-2003-0574  CAN-2003-0574
3094          TODO: check          NOTE: not-for-us (IRIX)
3095  CAN-2003-0573  CAN-2003-0573
3096          TODO: check          NOTE: not-for-us (IRIX)
3097  CAN-2003-0572  CAN-2003-0572
3098          TODO: check          NOTE: not-for-us (IRIX)
3099  CAN-2003-0571  CAN-2003-0571
3100          NOTE: reserved          NOTE: reserved
3101  CAN-2003-0570  CAN-2003-0570
# Line 2939  CAN-2003-0569 Line 3105  CAN-2003-0569
3105  CAN-2003-0568  CAN-2003-0568
3106          NOTE: reserved          NOTE: reserved
3107  CAN-2003-0567  CAN-2003-0567
3108          TODO: check          NOTE: not-for-us (Cisco)
3109  CAN-2003-0566  CAN-2003-0566
3110          NOTE: reserved          NOTE: reserved
3111  CAN-2003-0565  CAN-2003-0565
3112          TODO: check          NOTE: affects many implementations of the X.400 protocol
3113            TODO: see if anything in debian uses X.400 and is vulnerable.
3114  CAN-2003-0564  CAN-2003-0564
3115          TODO: check          NOTE: affects multiple S/MIME implementations
3116            NOTE: checked current mozilla, which contains safe NSS 3.9.1
3117            - mozilla 2:1.7.3
3118            TODO: see if anything else in debian uses S/MIME and is vulnerable.
3119  CAN-2003-0563  CAN-2003-0563
3120          NOTE: reserved          NOTE: reserved
3121  CAN-2003-0562  CAN-2003-0562
3122          TODO: check          NOTE: not-for-us (Novell Netware)
3123  CAN-2003-0561  CAN-2003-0561
3124          TODO: check          NOTE: not-for-us (IglooFTP)
3125  CAN-2003-0560  CAN-2003-0560
3126          TODO: check          NOTE: not-for-us (VP-ASP)
3127  CAN-2003-0559  CAN-2003-0559
3128          TODO: check          NOTE: not-for-us (phpforum)
3129  CAN-2003-0558  CAN-2003-0558
3130          TODO: check          NOTE: not-for-us (LeapFTP)
3131  CAN-2003-0557  CAN-2003-0557
3132          TODO: check          NOTE: not-for-us (StoreFront)
3133  CAN-2003-0556  CAN-2003-0556
3134          TODO: check          NOTE: not-for-us (Polycom MGC)
3135  CAN-2003-0555  CAN-2003-0555
3136          TODO: check          NOTE: imagemagick %x exploit failed with 6.0.6.2-1.5
3137  CAN-2003-0554  CAN-2003-0554
3138          TODO: check          NOTE: not-for-us (NeoModus Direct Connect)
3139  CAN-2003-0553  CAN-2003-0553
3140          TODO: check          NOTE: not-for-us (Netscape)
3141  CAN-2003-0552  CAN-2003-0552
3142          NOTE: covered by DSA-358          NOTE: covered by DSA-358
3143          NOTE: fixed in 2.4.22-pre3          NOTE: fixed in 2.4.22-pre3
# Line 2978  CAN-2003-0550 Line 3148  CAN-2003-0550
3148          NOTE: covered by DSA-358          NOTE: covered by DSA-358
3149          NOTE: fixed in 2.4.22-pre3          NOTE: fixed in 2.4.22-pre3
3150  CAN-2003-0549  CAN-2003-0549
3151          TODO: check          - gdm 2.4.1.5
3152  CAN-2003-0548  CAN-2003-0548
3153          TODO: check          - gdm 2.4.1.5
3154  CAN-2003-0547  CAN-2003-0547
3155          TODO: check          - gdm 2.4.1.5
3156  CAN-2003-0546  CAN-2003-0546
3157          TODO: check          NOTE: not-for-us (up2date)
3158  CAN-2003-0545  CAN-2003-0545
3159          NOTE: covered by DSA-393          NOTE: covered by DSA-393
3160  CAN-2003-0544  CAN-2003-0544
# Line 2993  CAN-2003-0543 Line 3163  CAN-2003-0543
3163          NOTE: covered by DSA-393          NOTE: covered by DSA-393
3164  CAN-2003-0542  CAN-2003-0542
3165          - apache2 2.0.48          - apache2 2.0.48
3166            - apache 1.3.29
3167  CAN-2003-0541  CAN-2003-0541
3168          - squid 2.5.5-5          NOTE: does not affect evolution on debian
3169            - gtkhtml (unfixed; bug #279726)
3170  CAN-2003-0540  CAN-2003-0540
3171          NOTE: covered by DSA-363          NOTE: covered by DSA-363
3172  CAN-2003-0539  CAN-2003-0539
# Line 3010  CAN-2003-0535 Line 3182  CAN-2003-0535
3182  CAN-2003-0534  CAN-2003-0534
3183          NOTE: reserved          NOTE: reserved
3184  CAN-2003-0533  CAN-2003-0533
3185          TODO: check          NOTE: not-for-us (Microsoft)
3186  CAN-2003-0532  CAN-2003-0532
3187          TODO: check          NOTE: not-for-us (Microsoft)
3188  CAN-2003-0531  CAN-2003-0531
3189          TODO: check          NOTE: not-for-us (Microsoft)
3190  CAN-2003-0530  CAN-2003-0530
3191          TODO: check          NOTE: not-for-us (Microsoft)
3192  CAN-2003-0529  CAN-2003-0529
3193          NOTE: reserved          NOTE: reserved
3194  CAN-2003-0528  CAN-2003-0528
3195          TODO: check          NOTE: not-for-us (Microsoft)
3196  CAN-2003-0527  CAN-2003-0527
3197          NOTE: reserved          NOTE: reserved
3198  CAN-2003-0526  CAN-2003-0526
3199          TODO: check          NOTE: not-for-us (Microsoft)
3200  CAN-2003-0525  CAN-2003-0525
3201          TODO: check          NOTE: not-for-us (Microsoft)
3202  CAN-2003-0524  CAN-2003-0524
3203          TODO: check          NOTE: appears specific to the knoppix CD
3204  CAN-2003-0523  CAN-2003-0523
3205          TODO: check          NOTE: not-for-us (ProductCart)
3206  CAN-2003-0522  CAN-2003-0522
3207          TODO: check          NOTE: not-for-us (ProductCart)
3208  CAN-2003-0521  CAN-2003-0521
3209          TODO: check          NOTE: not-for-us (cPanel is not our cpanel)
3210  CAN-2003-0520  CAN-2003-0520
3211          TODO: check          NOTE: not-for-us (Trillian)
3212  CAN-2003-0519  CAN-2003-0519
3213          TODO: check          NOTE: not-for-us (Microsoft)
3214  CAN-2003-0518  CAN-2003-0518
3215          TODO: check          NOTE: not-for-us (MacOS)
3216  CAN-2003-0517  CAN-2003-0517
3217          TODO: check          - mgetty 1.1.29
3218  CAN-2003-0516  CAN-2003-0516
3219          TODO: check          - mgetty 1.1.29
3220  CAN-2003-0515  CAN-2003-0515
3221          NOTE: covered by DSA-347          NOTE: covered by DSA-347
3222  CAN-2003-0514  CAN-2003-0514
3223          TODO: check          NOTE: not-for-us (Safari)
3224  CAN-2003-0513  CAN-2003-0513
3225          TODO: check          NOTE: not-for-us (MSIE)
3226  CAN-2003-0512  CAN-2003-0512
3227          TODO: check          NOTE: not-for-us (Cisco)
3228  CAN-2003-0511  CAN-2003-0511
3229          TODO: check          NOTE not-for-us (Cisco Aironet AP1x00 Series Wireless devices)
3230  CAN-2003-0510  CAN-2003-0510
3231          TODO: check          NOTE: not-for-us (ezbounce)
3232  CAN-2003-0509  CAN-2003-0509
3233          TODO: check          NOTE: not-for-us (Cyberstrong eShop)
3234  CAN-2003-0508  CAN-2003-0508
3235          TODO: check          NOTE: not-for-us (acroread)
3236  CAN-2003-0507  CAN-2003-0507
3237          TODO: check          NOTE: not-for-us (Microsoft)
3238  CAN-2003-0506  CAN-2003-0506
3239          TODO: check          NOTE: not-for-us (Microsoft)
3240  CAN-2003-0505  CAN-2003-0505
3241          TODO: check          NOTE: not-for-us (Microsoft)
3242  CAN-2003-0504  CAN-2003-0504
3243          NOTE: covered by DSA-365          NOTE: covered by DSA-365
3244  CAN-2003-0503  CAN-2003-0503
3245          TODO: check          NOTE: not-for-us (Microsoft)
3246  CAN-2003-0502  CAN-2003-0502
3247          TODO: check          NOTE: not-for-us (Apple Quicktime)
3248  CAN-2003-0501  CAN-2003-0501
3249          NOTE: covered by DSA-358          NOTE: covered by DSA-358
3250          NOTE: fixed in 2.4.22-pre10          NOTE: fixed in 2.4.22-pre10
3251  CAN-2003-0500  CAN-2003-0500
3252          NOTE: covered by DSA-338          NOTE: covered by DSA-338
   
 end claimed by joeyh  
   
 begin claimed by stef-guest  
   
3253  CAN-2003-0499  CAN-2003-0499
3254          NOTE: covered by DSA-335          NOTE: covered by DSA-335
3255  CAN-2003-0498  CAN-2003-0498
3256          TODO: check          NOTE: not-for-us (Intersystems Cache database)
3257  CAN-2003-0497  CAN-2003-0497
3258          TODO: check          NOTE: not-for-us (Intersystems Cache database)
3259  CAN-2003-0496  CAN-2003-0496
3260          TODO: check          NOTE: not-for-us (Microsoft)
3261  CAN-2003-0495  CAN-2003-0495
3262          TODO: check          NOTE: not-for-us (lednews; not in debian)
3263  CAN-2003-0494  CAN-2003-0494
3264          TODO: check          NOTE: not-for-us (snitz forums; not in debian)
3265  CAN-2003-0493  CAN-2003-0493
3266          - apache2 2.0.50          NOTE: not-for-us (snitz forums; not in debian)
3267  CAN-2003-0492  CAN-2003-0492
3268          TODO: check          NOTE: not-for-us (snitz forums; not in debian)
3269  CAN-2003-0491  CAN-2003-0491
3270          TODO: check          NOTE: not-for-us (xoop; not in debian)
3271  CAN-2003-0490  CAN-2003-0490
3272          TODO: check          NOTE: not-for-us (Dantz Retrospect)
3273  CAN-2003-0489  CAN-2003-0489
3274          NOTE: covered by DSA-330          NOTE: covered by DSA-330
3275  CAN-2003-0488  CAN-2003-0488
3276          - apache2 2.0.50          NOTE: not-for-us (Kerio Mail server)
3277  CAN-2003-0487  CAN-2003-0487
3278          TODO: check          NOTE: not-for-us (Kerio Mail server)
3279  CAN-2003-0486  CAN-2003-0486
3280          TODO: check          - phpbb2 2.0.6
3281  CAN-2003-0485  CAN-2003-0485
3282          TODO: check          NOTE: not-for-us (Progress 4GL Compiler)
3283  CAN-2003-0484  CAN-2003-0484
3284          TODO: check          - phpbb2 2.0.6d-3
3285  CAN-2003-0483  CAN-2003-0483
3286          TODO: check          NOTE: not-for-us (XMB Forum)
3287  CAN-2003-0482  CAN-2003-0482
3288          TODO: check          - tutos 1.1.20030715-1
3289  CAN-2003-0481  CAN-2003-0481
3290          TODO: check          - tutos 1.1.20030715-1
3291  CAN-2003-0480  CAN-2003-0480
3292          TODO: check          NOTE: not-for-us (VMware)
3293  CAN-2003-0479  CAN-2003-0479
3294          TODO: check          NOTE: not-for-us (WebBBS; not in debian)
3295  CAN-2003-0478  CAN-2003-0478
3296          TODO: check          NOTE: not-for-us (bahamut and other irc daemons; not in debian)
3297  CAN-2003-0477  CAN-2003-0477
3298          TODO: check          - wzdftpd 0.2
3299  CAN-2003-0476  CAN-2003-0476
3300          NOTE: covered by DSA-358          NOTE: covered by DSA-358
3301          NOTE: fixed in 2.4.22-pre4          NOTE: fixed in 2.4.22-pre4
3302  CAN-2003-0475  CAN-2003-0475
3303          TODO: check          NOTE: not-for-us (iWeb server)
3304  CAN-2003-0474  CAN-2003-0474
3305          TODO: check          NOTE: not-for-us (iWeb server)
3306  CAN-2003-0473  CAN-2003-0473
3307          TODO: check          NOTE: not-for-us (SGI IRIX)
3308  CAN-2003-0472  CAN-2003-0472
3309          TODO: check          NOTE: not-for-us (SGI IRIX)
3310  CAN-2003-0471  CAN-2003-0471
3311          TODO: check          NOTE: not-for-us (webadmin / win)
3312  CAN-2003-0470  CAN-2003-0470
3313          TODO: check          NOTE: not-for-us (symantec activex)
3314  CAN-2003-0469  CAN-2003-0469
3315          TODO: check          NOTE: not-for-us (microsoft)
3316  CAN-2003-0468  CAN-2003-0468
3317          NOTE: covered by DSA-363          NOTE: covered by DSA-363
3318  CAN-2003-0467  CAN-2003-0467
3319          TODO: check          NOTE: fixed in linux 2.4.21
3320  CAN-2003-0466  CAN-2003-0466
3321          TODO: check          NOTE: covered by DSA-357
3322  CAN-2003-0465  CAN-2003-0465 strncpy in kernel does not pad with zeroes
3323          TODO: check          - kernel-source-2.4.27 (unfixed; bug #280492)
3324            NOTE: generic .c version fixed in 2.6.x but not in 2.4.x
3325            NOTE: arch specific asm versions:
3326            NOTE: x86 is not affected
3327            NOTE: ppc32 fixed in 2.4.22-rc4
3328  CAN-2003-0464  CAN-2003-0464
3329          TODO: check          NOTE: fixed in linux 2.4.22-pre8
3330  CAN-2003-0463  CAN-2003-0463
3331          NOTE: reserved          NOTE: reserved
3332  CAN-2003-0462  CAN-2003-0462
# Line 3163  CAN-2003-0462 Line 3334  CAN-2003-0462
3334  CAN-2003-0461  CAN-2003-0461
3335          NOTE: covered by DSA-358          NOTE: covered by DSA-358
3336  CAN-2003-0460  CAN-2003-0460
3337          TODO: check          NOTE: not-for-us (apache for win and os/2)
3338  CAN-2003-0459  CAN-2003-0459
3339          NOTE: covered by DSA-361          NOTE: covered by DSA-361
3340  CAN-2003-0458  CAN-2003-0458
3341          TODO: check          NOTE: not-for-us (HP)
3342  CAN-2003-0457  CAN-2003-0457
3343          NOTE: reserved          NOTE: reserved
3344          - mysql-dfsg 4.0.21-4          - mysql-dfsg 4.0.21-4
3345  CAN-2003-0456  CAN-2003-0456
3346          TODO: check          NOTE: not-for-us (visnetic website)
3347  CAN-2003-0455  CAN-2003-0455
3348          NOTE: covered by DSA-331          NOTE: covered by DSA-331
3349  CAN-2003-0454  CAN-2003-0454
# Line 3186  CAN-2003-0451 Line 3357  CAN-2003-0451
3357  CAN-2003-0450  CAN-2003-0450
3358          NOTE: covered by DSA-321          NOTE: covered by DSA-321
3359  CAN-2003-0449  CAN-2003-0449
3360          TODO: check          NOTE: not-for-us (progress database)
3361  CAN-2003-0448  CAN-2003-0448
3362          TODO: check          NOTE: not-for-us (portmon; not in debian)
3363  CAN-2003-0447  CAN-2003-0447
3364          TODO: check          NOTE: not-for-us (microsoft)
3365  CAN-2003-0446  CAN-2003-0446
3366          TODO: check          NOTE: not-for-us (microsoft)
3367  CAN-2003-0445  CAN-2003-0445
3368          NOTE: covered by DSA-328          NOTE: covered by DSA-328
3369  CAN-2003-0444  CAN-2003-0444
# Line 3210  CAN-2003-0439 Line 3381  CAN-2003-0439
3381  CAN-2003-0438  CAN-2003-0438
3382          NOTE: covered by DSA-325          NOTE: covered by DSA-325
3383  CAN-2003-0437  CAN-2003-0437
3384          TODO: check          - mnogosearch-common 3.2.11
3385  CAN-2003-0436  CAN-2003-0436
3386          TODO: check          - mnogosearch-common 3.2.11
3387  CAN-2003-0435  CAN-2003-0435
3388          NOTE: covered by DSA-322          NOTE: covered by DSA-322
3389  CAN-2003-0434  CAN-2003-0434
3390          TODO: check          NOTE: various pdf viewers
3391            NOTE: kpdf does not seem to support hyperlinks; so not vulnerable
3392            NOTE: gpdf 2.8.0 does not seem to be vulnerable
3393            - xpdf 2.02pl1-1
3394  CAN-2003-0433  CAN-2003-0433
3395          NOTE: covered by DSA-315          NOTE: covered by DSA-315
3396  CAN-2003-0432  CAN-2003-0432
# Line 3224  CAN-2003-0432 Line 3398  CAN-2003-0432
3398  CAN-2003-0431  CAN-2003-0431
3399          NOTE: covered by DSA-324          NOTE: covered by DSA-324
3400  CAN-2003-0430  CAN-2003-0430
3401          TODO: check          - ethereal 0.9.13
3402  CAN-2003-0429  CAN-2003-0429
3403          NOTE: covered by DSA-324          NOTE: covered by DSA-324
3404  CAN-2003-0428  CAN-2003-0428
# Line 3232  CAN-2003-0428 Line 3406  CAN-2003-0428
3406  CAN-2003-0427  CAN-2003-0427
3407          NOTE: covered by DSA-320          NOTE: covered by DSA-320
3408  CAN-2003-0426  CAN-2003-0426
3409          TODO: check          NOTE: not-for-us (Apple)
3410  CAN-2003-0425  CAN-2003-0425
3411          TODO: check          NOTE: not-for-us (Apple)
3412  CAN-2003-0424  CAN-2003-0424
3413          TODO: check          NOTE: not-for-us (Apple)
3414  CAN-2003-0423  CAN-2003-0423
3415          TODO: check          NOTE: not-for-us (Apple)
3416  CAN-2003-0422  CAN-2003-0422
3417          TODO: check          NOTE: not-for-us (Apple)
3418  CAN-2003-0421  CAN-2003-0421
3419          TODO: check          NOTE: not-for-us (Apple)
3420  CAN-2003-0420  CAN-2003-0420
3421          NOTE: reserved          NOTE: reserved
3422  CAN-2003-0419  CAN-2003-0419
3423          TODO: check          NOTE: not-for-us (SMC)
3424  CAN-2003-0418  CAN-2003-0418
3425          TODO: check          NOTE: only linux 2.0.x
3426  CAN-2003-0417  CAN-2003-0417
3427          TODO: check          NOTE: not-for-us (Son hServer)
3428  CAN-2003-0416  CAN-2003-0416
3429          TODO: check          NOTE: not-for-us (bandmin; not in Debian)
3430  CAN-2003-0415  CAN-2003-0415
3431          TODO: check          NOTE: not-for-us (Remote PC Access)
3432  CAN-2003-0414  CAN-2003-0414
3433          TODO: check          NOTE: not-for-us (Sun ONE)
3434  CAN-2003-0413  CAN-2003-0413
3435          TODO: check          NOTE: not-for-us (Sun ONE)
3436  CAN-2003-0412  CAN-2003-0412
3437          TODO: check          NOTE: not-for-us (Sun ONE)
3438  CAN-2003-0411  CAN-2003-0411
3439          TODO: check          NOTE: not-for-us (Sun ONE)
3440  CAN-2003-0410  CAN-2003-0410
3441          TODO: check          NOTE: not-for-us (AnalogX proxy)
3442  CAN-2003-0409  CAN-2003-0409
3443          TODO: check          NOTE: not-for-us (BRS WebWeaver)
3444  CAN-2003-0408  CAN-2003-0408
3445          TODO: check          NOTE: not-for-us (Uptimes Project upclient; not in Debian)
3446  CAN-2003-0407  CAN-2003-0407
3447          TODO: check          - gbatnav 1.0.4-4
3448  CAN-2003-0406  CAN-2003-0406
3449          TODO: check          NOTE: not-for-us (PalmVNC)
3450  CAN-2003-0405  CAN-2003-0405
3451          TODO: check          NOTE: not-for-us (Vignette)
3452  CAN-2003-0404  CAN-2003-0404
3453          TODO: check          NOTE: not-for-us (Vignette)
3454  CAN-2003-0403  CAN-2003-0403
3455          TODO: check          NOTE: not-for-us (Vignette)
3456  CAN-2003-0402  CAN-2003-0402
3457          TODO: check          NOTE: not-for-us (Vignette)
3458  CAN-2003-0401  CAN-2003-0401
3459          TODO: check          NOTE: not-for-us (Vignette)
3460  CAN-2003-0400  CAN-2003-0400
3461          TODO: check          NOTE: not-for-us (Vignette / AIX)
   
 end claimed by stef-guest  
   
3462  CAN-2003-0399  CAN-2003-0399
3463          TODO: check          NOTE: not-for-us (Vignette StoryServer)
3464  CAN-2003-0398  CAN-2003-0398
3465          TODO: check          NOTE: not-for-us (Vignette StoryServer)
3466  CAN-2003-0397  CAN-2003-0397
3467          TODO: check          NOTE: not-for-us (FastTrack network code (Kazaa))
3468  CAN-2003-0396  CAN-2003-0396
3469          TODO: check          - linux-arm 2.4.1
3470  CAN-2003-0395  CAN-2003-0395
3471          TODO: check          NOTE: not-for-us (Ultimate PHP Board)
3472  CAN-2003-0394  CAN-2003-0394
3473          TODO: check          NOTE: not-for-us (BLNews)
3474  CAN-2003-0393  CAN-2003-0393
3475          TODO: check          NOTE: not-for-us (Privacyware Privatefirewall)
3476  CAN-2003-0392  CAN-2003-0392
3477          TODO: check          NOTE: not-for-us (ST FTP Service (DOS))
3478  CAN-2003-0391  CAN-2003-0391
3479          TODO: check          NOTE: not-for-us (Magic WinMail Server)
3480  CAN-2003-0390  CAN-2003-0390
3481          TODO: check          - opt 3.19
3482  CAN-2003-0389  CAN-2003-0389
3483          TODO: check          NOTE: not-for-us (RSA ACE/Agent)
3484  CAN-2003-0388  CAN-2003-0388
3485          TODO: check          NOTE: pam is not vulnerable in default confuguration
3486            NOTE: pam is not vulnerable at all in sarge, according to maintainer
3487  CAN-2003-0387  CAN-2003-0387
3488          NOTE: reserved          NOTE: reserved
3489  CAN-2003-0386  CAN-2003-0386
3490          TODO: check          NOTE: fixed in current openssh, which always does reverse mapping now
3491  CAN-2003-0385  CAN-2003-0385
3492          NOTE: covered by DSA-310          NOTE: covered by DSA-310
3493            - xaos 3.1r-4
3494  CAN-2003-0384  CAN-2003-0384
3495          NOTE: reserved          NOTE: reserved
3496  CAN-2003-0382  CAN-2003-0382
# Line 3327  CAN-2003-0381 Line 3500  CAN-2003-0381
3500  CAN-2003-0380  CAN-2003-0380
3501          NOTE: covered by DSA-314          NOTE: covered by DSA-314
3502  CAN-2003-0379  CAN-2003-0379
3503          TODO: check          NOTE: not-for-us (MaxOS)
3504  CAN-2003-0378  CAN-2003-0378
3505          TODO: check          NOTE: not-for-us (MaxOS)
3506  CAN-2003-0377  CAN-2003-0377
3507          TODO: check          NOTE: not-for-us (iisPROTECT)
3508  CAN-2003-0376  CAN-2003-0376
3509          TODO: check          NOTE: not-for-us (Eudora)
3510  CAN-2003-0375  CAN-2003-0375
3511          TODO: check          NOTE: not-for-us (XMBforum aka Partagium))
3512  CAN-2003-0374  CAN-2003-0374
3513          TODO: check          - nessus 2.0.6
3514  CAN-2003-0373  CAN-2003-0373
3515          TODO: check          - nessus 2.0.6
3516  CAN-2003-0372  CAN-2003-0372
3517          TODO: check          - nessus 2.0.6
3518  CAN-2003-0371  CAN-2003-0371
3519          TODO: check          NOTE: not-for-us (Prishtina FTP client)
3520  CAN-2003-0370  CAN-2003-0370
3521          NOTE: covered by DSA-361          NOTE: covered by DSA-361
3522  CAN-2003-0369  CAN-2003-0369
3523          NOTE: reserved          NOTE: reserved
3524  CAN-2003-0368  CAN-2003-0368
3525          TODO: check          NOTE: not-for-us (Nokia Gateway GPRS)
3526  CAN-2003-0367  CAN-2003-0367
3527          TODO: check          NOTE: covered by DSA-308
3528  CAN-2003-0366  CAN-2003-0366
3529          NOTE: covered by DSA-318          NOTE: covered by DSA-318
3530  CAN-2003-0365  CAN-2003-0365
3531          TODO: check          NOTE: not-for-us (ICQLite)
3532  CAN-2003-0364  CAN-2003-0364
3533          NOTE: covered by DSA-336          NOTE: covered by DSA-336
3534  CAN-2003-0363  CAN-2003-0363
# Line 3375  CAN-2003-0357 Line 3548  CAN-2003-0357
3548  CAN-2003-0356  CAN-2003-0356
3549          NOTE: covered by DSA-313          NOTE: covered by DSA-313
3550  CAN-2003-0355  CAN-2003-0355
3551          TODO: check          NOTE: not-for-us (Safari)
3552  CAN-2003-0354  CAN-2003-0354
3553          TODO: check          - gs-gpl 7.07
3554  CAN-2003-0353  CAN-2003-0353
3555          TODO: check          NOTE: not-for-us (Microsoft)
3556  CAN-2003-0352  CAN-2003-0352
3557          TODO: check          NOTE: not-for-us (Microsoft)
3558  CAN-2003-0351  CAN-2003-0351
3559          NOTE: rejected          NOTE: rejected
3560  CAN-2003-0350  CAN-2003-0350
3561          TODO: check          NOTE: not-for-us (Microsoft)
3562  CAN-2003-0349  CAN-2003-0349
3563          TODO: check          NOTE: not-for-us (Microsoft)
3564  CAN-2003-0348  CAN-2003-0348
3565          TODO: check          NOTE: not-for-us (Microsoft)
3566  CAN-2003-0347  CAN-2003-0347
3567          TODO: check          NOTE: not-for-us (Microsoft)
3568  CAN-2003-0346  CAN-2003-0346
3569          TODO: check          NOTE: not-for-us (Microsoft)
3570  CAN-2003-0345  CAN-2003-0345
3571          TODO: check          NOTE: not-for-us (Microsoft)
3572  CAN-2003-0344  CAN-2003-0344
3573          TODO: check          NOTE: not-for-us (Microsoft)
3574  CAN-2003-0343  CAN-2003-0343
3575          TODO: check          NOTE: not-for-us (BlackMoon FTP Server)
3576  CAN-2003-0342  CAN-2003-0342
3577          TODO: check          NOTE: not-for-us (BlackMoon FTP Server)
3578  CAN-2003-0341  CAN-2003-0341
3579          TODO: check          NOTE: not-for-us (Owl Intranet Engine)
3580  CAN-2003-0340  CAN-2003-0340
3581          TODO: check          NOTE: not-for-us (Puresecure)
3582  CAN-2003-0339  CAN-2003-0339
3583          TODO: check          NOTE: not-for-us (WsMp3)
3584  CAN-2003-0338  CAN-2003-0338
3585          TODO: check          NOTE: not-for-us (WsMp3)
3586  CAN-2003-0337  CAN-2003-0337
3587          TODO: check          NOTE: not-for-us (lsadmin)
3588  CAN-2003-0336  CAN-2003-0336
3589          TODO: check          NOTE: not-for-us (Eudora)
3590  CAN-2003-0335  CAN-2003-0335
3591          TODO: check          NOTE: not-for-us (Slaskware specific)
3592  CAN-2003-0334  CAN-2003-0334
3593          TODO: check          - ircii-pana 1:1.0-0c19.20030512-1
3594  CAN-2003-0333  CAN-2003-0333
3595          TODO: check          NOTE: not-for-us (C-Kermit on HP-UX)
3596  CAN-2003-0332  CAN-2003-0332
3597          TODO: check          NOTE: not-for-us (BadBlue)
3598  CAN-2003-0331  CAN-2003-0331
3599          TODO: check          NOTE: not-for-us (ttForum)
3600  CAN-2003-0330  CAN-2003-0330
3601          TODO: check          NOTE: maelstrom in sarge tests not vulnerable to exploit. Unsure when fixed.
3602  CAN-2003-0329  CAN-2003-0329
3603          TODO: check          NOTE: not-for-us (CesarFTP)
3604  CAN-2003-0328  CAN-2003-0328
3605          NOTE: covered by DSA-306          NOTE: covered by DSA-306
3606  CAN-2003-0327  CAN-2003-0327
3607          TODO: check          NOTE: not-for-us (Sybase Adaptive Server Enterprise)
3608  CAN-2003-0326  CAN-2003-0326
3609          TODO: check          NOTE: bug does exist in slocate.
3610            NOTE: only impacts security if kernel has been recompiled to allow
3611            NOTE: an absurd 536870912 bytes of command line arguments. This is
3612            NOTE: very unlikely, and if you do exploit it, you get only slocate
3613            NOTE: gid.
3614  CAN-2003-0325  CAN-2003-0325
3615          TODO: check          NOTE: maelstrom in sarge tests not vulnerable to exploit. Unsure when fixed.
3616  CAN-2003-0324  CAN-2003-0324
3617          NOTE: covered by DSA-287          NOTE: covered by DSA-287
3618  CAN-2003-0323  CAN-2003-0323
# Line 3445  CAN-2003-0322 Line 3622  CAN-2003-0322
3622  CAN-2003-0320  CAN-2003-0320
3623          NOTE: covered by DSA-306          NOTE: covered by DSA-306
3624  CAN-2003-0320  CAN-2003-0320
3625          TODO: check          NOTE: not-for-us (ttCMS)
3626  CAN-2003-0319  CAN-2003-0319
3627          TODO: check          NOTE: not-for-us (SmartMax MailMax)
3628  CAN-2003-0318  CAN-2003-0318
3629          TODO: check          NOTE: not-for-us (PHP-Nuke)
3630  CAN-2003-0317  CAN-2003-0317
3631          TODO: check          NOTE: not-for-us (iisPROTECT)
3632  CAN-2003-0316  CAN-2003-0316
3633          TODO: check          NOTE: not-for-us (Venturi Client)
3634  CAN-2003-0315  CAN-2003-0315
3635          TODO: check          NOTE: not-for-us (Snowblind Web Server)
3636  CAN-2003-0314  CAN-2003-0314
3637          TODO: check          NOTE: not-for-us (Snowblind Web Server)
3638  CAN-2003-0313  CAN-2003-0313
3639          TODO: check          NOTE: not-for-us (Snowblind Web Server)
3640  CAN-2003-0312  CAN-2003-0312
3641          TODO: check          NOTE: not-for-us (Snowblind Web Server)
3642  CAN-2003-0311  CAN-2003-0311
3643          NOTE: reserved          NOTE: reserved
3644  CAN-2003-0310  CAN-2003-0310
3645          TODO: check          NOTE: author apparently fixed hole by time vuln was reported,
3646            NOTE: and I guess that fix made it into new upstream versions,
3647            NOTE: but I did not check in detail
3648  CAN-2003-0309  CAN-2003-0309
3649          TODO: check          NOTE: not-for-us (MSIE)
3650  CAN-2003-0308  CAN-2003-0308
3651          NOTE: covered by DSA-305          NOTE: covered by DSA-305
3652  CAN-2003-0307  CAN-2003-0307
3653          TODO: check          NOTE: not-for-us (Poster version.two)
3654  CAN-2003-0306  CAN-2003-0306
3655          TODO: check          NOTE: not-for-us (Windows)
3656  CAN-2003-0305  CAN-2003-0305
3657          TODO: check          NOTE: not-for-us (Cisco)
3658  CAN-2003-0304  CAN-2003-0304
3659          TODO: check          NOTE: not-for-us (one||zero (aka One or Zero) Helpdesk)
3660  CAN-2003-0303  CAN-2003-0303
3661          TODO: check          NOTE: not-for-us (one||zero (aka One or Zero) Helpdesk)
3662  CAN-2003-0302  CAN-2003-0302
3663          TODO: check          NOTE: not-for-us (Eudora)
3664  CAN-2003-0301  CAN-2003-0301
3665          TODO: check          NOTE: not-for-us (Microsort)
3666  CAN-2003-0300  CAN-2003-0300
3667          TODO: check          NOTE: sylpheed and sylpheed-claws might still be vulnerable
3668            NOTE: but it's only a crasher
3669  CAN-2003-0299  CAN-2003-0299
3670          TODO: check          NOTE: mutt and balse might still be vulnerable
3671            NOTE: but it's only a crasher
3672  CAN-2003-0298  CAN-2003-0298
3673          TODO: check          - mozilla 1.4b
3674  CAN-2003-0297  CAN-2003-0297
3675          TODO: check          - uw-imap 7:2002c
3676            NOTE: did not check pine
3677  CAN-2003-0296  CAN-2003-0296
3678          TODO: check          - evolution 1.3.2
3679  CAN-2003-0295  CAN-2003-0295
3680          TODO: check          NOTE: not-for-us (vBulletin)
3681  CAN-2003-0294  CAN-2003-0294
3682          TODO: check          NOTE: not-for-us (php-proxima)
3683  CAN-2003-0293  CAN-2003-0293
3684          TODO: check          NOTE: not-for-us (PalmOS)
3685  CAN-2003-0292  CAN-2003-0292
3686          TODO: check          NOTE: not-for-us (Inktomi)
3687  CAN-2003-0291  CAN-2003-0291
3688          TODO: check          NOTE: not-for-us (3com OfficeConnect Remote 812 ADSL Router)
3689  CAN-2003-0290  CAN-2003-0290
3690          TODO: check          NOTE: not-for-us (eServ)
3691  CAN-2003-0289  CAN-2003-0289
3692          TODO: check          - cdrtools 4:2.0+a14-1
3693  CAN-2003-0288  CAN-2003-0288
3694          TODO: check          NOTE: not-for-us (IP Messenger for Win)
3695  CAN-2003-0287  CAN-2003-0287
3696          TODO: check          NOTE: not-for-us (Movable Type)
3697  CAN-2003-0286  CAN-2003-0286
3698          TODO: check          NOTE: not-for-us (Snitz Forums)
3699  CAN-2003-0285  CAN-2003-0285
3700          TODO: check          NOTE: not-for-us (bad sendmail config on AIX)
3701  CAN-2003-0284  CAN-2003-0284
3702          TODO: check          NOTE: not-for-us (Adobe Acrobat)
3703  CAN-2003-0283  CAN-2003-0283
3704          TODO: check          NOTE: not-for-us (Phorum)
3705  CAN-2003-0282  CAN-2003-0282
3706          TODO: check          NOTE: covered by DSA-344
3707  CAN-2003-0281  CAN-2003-0281
3708          TODO: check          - firebird2 1.5.1-1
3709            NOTE: firebird (1) in debian is very insecure and vulnerable, but
3710            NOTE: the server is not included, just the libraries. See bug #251458
3711  CAN-2003-0280  CAN-2003-0280
3712          TODO: check          NOTE: not-for-us (SMTP Service for ESMTP CMailServer )
3713  CAN-2003-0279  CAN-2003-0279
3714          TODO: check          NOTE: not-for-us (PHP-Nuke)
3715  CAN-2003-0278  CAN-2003-0278
3716          TODO: check          NOTE: not-for-us (HappyMail)
3717  CAN-2003-0277  CAN-2003-0277
3718          TODO: check          NOTE: not-for-us (HappyMail)
3719  CAN-2003-0276  CAN-2003-0276
3720          TODO: check          NOTE: not-for-us (Pi3Web)
3721  CAN-2003-0275  CAN-2003-0275
3722          TODO: check          NOTE: not-for-us (YaBB SE)
3723  CAN-2003-0274  CAN-2003-0274
3724          TODO: check          NOTE: not-for-us (ListProc)
3725  CAN-2003-0273  CAN-2003-0273
3726          TODO: check          NOTE: old version of Request Tracker not in debian.
3727  CAN-2003-0272  CAN-2003-0272
3728          TODO: check          NOTE: not-for-us (miniPortail)
3729  CAN-2003-0271  CAN-2003-0271
3730          TODO: check          NOTE: not-for-us (Personal FTP Server)
3731  CAN-2003-0270  CAN-2003-0270
3732          TODO: check          NOTE: not-for-us (Apple Airport)
3733  CAN-2003-0269  CAN-2003-0269
3734          TODO: check          NOTE: not-for-us (youbin)
3735  CAN-2003-0268  CAN-2003-0268
3736          TODO: check          NOTE: not-for-us (SLWebMail on Windows)
3737  CAN-2003-0267  CAN-2003-0267
3738          TODO: check          NOTE: not-for-us (SLWebMail on Windows)
3739  CAN-2003-0266  CAN-2003-0266
3740          TODO: check          NOTE: not-for-us (SLWebMail on Windows)
3741  CAN-2003-0265  CAN-2003-0265
3742          TODO: check          NOTE: not-for-us (SDBINST for SAP database)
3743  CAN-2003-0264  CAN-2003-0264
3744          TODO: check          NOTE: not-for-us (SLMail)
3745  CAN-2003-0263  CAN-2003-0263
3746          TODO: check          NOTE: not-for-us (FTGatePro)
3747  CAN-2003-0262  CAN-2003-0262
3748          NOTE: covered by DSA-299          NOTE: covered by DSA-299
3749  CAN-2003-0261  CAN-2003-0261
3750          NOTE: covered by DSA-302          NOTE: covered by DSA-302
3751  CAN-2003-0260  CAN-2003-0260
3752          TODO: check          NOTE: not-for-us (Cisco)
3753  CAN-2003-0259  CAN-2003-0259
3754          TODO: check          NOTE: not-for-us (Cisco)
3755  CAN-2003-0258  CAN-2003-0258
3756          TODO: check          NOTE: not-for-us (Cisco)
3757  CAN-2003-0257  CAN-2003-0257
3758          TODO: check          NOTE: not-for-us (AIX)
3759  CAN-2003-0256  CAN-2003-0256
3760          TODO: check          - kopete 3.2.0
3761  CAN-2003-0255  CAN-2003-0255
3762          TODO: check          - gnupg 1.2.2
3763  CAN-2003-0254  CAN-2003-0254
3764          - apache2 2.0.47          - apache2 2.0.47
3765  CAN-2003-0253  CAN-2003-0253
# Line 3583  CAN-2003-0253 Line 3767  CAN-2003-0253
3767  CAN-2003-0252  CAN-2003-0252
3768          NOTE: covered by DSA-349          NOTE: covered by DSA-349
3769  CAN-2003-0251  CAN-2003-0251
3770          TODO: check          NOTE: actually, we need ypserv 2.7, nis 3.11 has ypserv 2.13
3771            - nis 3.11
3772  CAN-2003-0250  CAN-2003-0250
3773          NOTE: reserved          NOTE: reserved
3774  CAN-2003-0249  CAN-2003-0249
# Line 3599  CAN-2003-0245 Line 3784  CAN-2003-0245
3784  CAN-2003-0244  CAN-2003-0244
3785          NOTE: covered by DSA-336          NOTE: covered by DSA-336
3786  CAN-2003-0243  CAN-2003-0243
3787          TODO: check          NOTE: not-for-us (Happycgi.com Happymall)
3788  CAN-2003-0242  CAN-2003-0242
3789          TODO: check          NOTE: not-for-us (MacOS)
3790  CAN-2003-0241  CAN-2003-0241
3791          TODO: check          NOTE: not-for-us (FrontRange GoldMine / win)
3792  CAN-2003-0240  CAN-2003-0240
3793          TODO: check          NOTE: not-for-us (Axis Network Camera)
3794  CAN-2003-0239  CAN-2003-0239
3795          TODO: check          NOTE: not-for-us (Mirabilis ICQ / windows)
3796  CAN-2003-0238  CAN-2003-0238
3797          TODO: check          NOTE: not-for-us (Mirabilis ICQ / windows)
3798  CAN-2003-0237  CAN-2003-0237
3799          TODO: check          NOTE: not-for-us (Mirabilis ICQ / windows)
3800  CAN-2003-0236  CAN-2003-0236
3801          TODO: check          NOTE: not-for-us (Mirabilis ICQ / windows)
3802  CAN-2003-0235  CAN-2003-0235
3803          TODO: check          NOTE: not-for-us (Mirabilis ICQ / windows)
3804  CAN-2003-0234  CAN-2003-0234
3805          NOTE: reserved          NOTE: reserved
3806  CAN-2003-0233  CAN-2003-0233
3807          TODO: check          NOTE: not-for-us (microsoft)
3808  CAN-2003-0232  CAN-2003-0232
3809          TODO: check          NOTE: not-for-us (microsoft)
3810  CAN-2003-0231  CAN-2003-0231
3811          TODO: check          NOTE: not-for-us (microsoft)
3812  CAN-2003-0230  CAN-2003-0230
3813          TODO: check          NOTE: not-for-us (microsoft)
3814  CAN-2003-0229  CAN-2003-0229
3815          NOTE: reserved          NOTE: reserved
3816  CAN-2003-0228  CAN-2003-0228
3817          TODO: check          NOTE: not-for-us (microsoft)
3818  CAN-2003-0227  CAN-2003-0227
3819          TODO: check          NOTE: not-for-us (microsoft)
3820  CAN-2003-0226  CAN-2003-0226
3821          TODO: check          NOTE: not-for-us (microsoft)
3822  CAN-2003-0225  CAN-2003-0225
3823          TODO: check          NOTE: not-for-us (microsoft)
3824  CAN-2003-0224  CAN-2003-0224
3825          TODO: check          NOTE: not-for-us (microsoft)
3826  CAN-2003-0223  CAN-2003-0223
3827          TODO: check          NOTE: not-for-us (microsoft)
3828  CAN-2003-0222  CAN-2003-0222
3829          TODO: check          NOTE: not-for-us (oracle)
3830  CAN-2003-0221  CAN-2003-0221
3831          TODO: check          NOTE: not-for-us (HP tru64)
3832  CAN-2003-0220  CAN-2003-0220
3833          TODO: check          NOTE: not-for-us (Kerio Personal Firewall)
3834  CAN-2003-0219  CAN-2003-0219
3835          TODO: check          NOTE: not-for-us (Kerio Personal Firewall)
3836  CAN-2003-0218  CAN-2003-0218
3837          TODO: check          NOTE: not-for-us (Monkey http daemon; not in debian)
3838  CAN-2003-0217  CAN-2003-0217
3839          TODO: check          NOTE: not-for-us (Neoteris Instant Virtual Extranet)
3840  CAN-2003-0216  CAN-2003-0216
3841          TODO: check          NOTE: not-for-us (cisco)
3842  CAN-2003-0215  CAN-2003-0215
3843          TODO: check          NOTE: not-for-us (bttlxeForum / win)
3844  CAN-2003-0214  CAN-2003-0214
3845          NOTE: covered by DSA-292          NOTE: covered by DSA-292
3846  CAN-2003-0213  CAN-2003-0213
# Line 3663  CAN-2003-0213 Line 3848  CAN-2003-0213
3848  CAN-2003-0212  CAN-2003-0212
3849          NOTE: covered by DSA-289          NOTE: covered by DSA-289
3850  CAN-2003-0211  CAN-2003-0211
3851          TODO: check          - xinetd 2.3.11
3852  CAN-2003-0210  CAN-2003-0210
3853          TODO: check          NOTE: not-for-us (cisco)
3854  CAN-2003-0209  CAN-2003-0209
3855          NOTE: covered by DSA-297          NOTE: covered by DSA-297
3856  CAN-2003-0208  CAN-2003-0208
3857          TODO: check          NOTE: not-for-us (macromedia flash)
3858  CAN-2003-0207  CAN-2003-0207
3859          NOTE: covered by DSA-286          NOTE: covered by DSA-286
3860  CAN-2003-0206  CAN-2003-0206
# Line 3689  CAN-2003-0200 Line 3874  CAN-2003-0200
3874  CAN-2003-0199  CAN-2003-0199
3875          NOTE: reserved          NOTE: reserved
3876  CAN-2003-0198  CAN-2003-0198
3877          TODO: check          NOTE: not-for-us (MacOS)
3878  CAN-2003-0197  CAN-2003-0197
3879          TODO: check          NOTE: not-for-us (Interbase Database)
3880  CAN-2003-0196  CAN-2003-0196
3881          NOTE: covered by DSA-280          NOTE: covered by DSA-280
3882  CAN-2003-0195  CAN-2003-0195
3883          NOTE: covered by DSA-317          NOTE: covered by DSA-317
3884  CAN-2003-0194  CAN-2003-0194
3885          TODO: check          NOTE: apparently a redhat specific compilation prolem of tcpdump
3886  CAN-2003-0193  CAN-2003-0193
3887          NOTE: covered by DSA-576-1          NOTE: covered by DSA-576-1
3888          - catdoc 0.91.5-2          - catdoc 0.91.5-2
3889  CAN-2003-0192  CAN-2003-0192
3890          - apache2 2.0.47          - apache2 2.0.47
3891  CAN-2003-0190  CAN-2003-0190
3892          TODO: check          - ssh (unfixed; bug filed)
3893  CAN-2003-0189  CAN-2003-0189
3894          - apache2 2.0.46          - apache2 2.0.46
3895  CAN-2003-0188  CAN-2003-0188
3896          NOTE: covered by DSA-304          NOTE: covered by DSA-304
3897  CAN-2003-0187  CAN-2003-0187
3898          TODO: check          NOTE: only affects kernel 2.4.19, 2.4.20.
3899  CAN-2003-0186  CAN-2003-0186
3900          NOTE: reserved          NOTE: reserved
3901  CAN-2003-0185  CAN-2003-0185
# Line 3722  CAN-2003-0183 Line 3907  CAN-2003-0183
3907  CAN-2003-0182  CAN-2003-0182
3908          NOTE: reserved          NOTE: reserved
3909  CAN-2003-0181  CAN-2003-0181
3910          TODO: check          NOTE: not-for-us (Lotus Domino Web Server)
3911  CAN-2003-0180  CAN-2003-0180
3912          TODO: check          NOTE: not-for-us (Lotus Domino Web Server)
3913  CAN-2003-0179  CAN-2003-0179
3914          TODO: check          NOTE: not-for-us (Lotus Domino Web Server)
3915  CAN-2003-0178  CAN-2003-0178
3916          TODO: check          NOTE: not-for-us (Lotus Domino Web Server)
3917  CAN-2003-0177  CAN-2003-0177
3918          TODO: check          NOTE: not-for-us (IRIX)
3919  CAN-2003-0176  CAN-2003-0176
3920          TODO: check          NOTE: not-for-us (IRIX)
3921  CAN-2003-0175  CAN-2003-0175
3922          TODO: check          NOTE: not-for-us (IRIX)
3923  CAN-2003-0174  CAN-2003-0174
3924          - apache2 2.0.49          NOTE: not-for-us (IRIX)
3925  CAN-2003-0173  CAN-2003-0173
3926          NOTE: covered by DSA-283          NOTE: covered by DSA-283
3927  CAN-2003-0172  CAN-2003-0172
3928          TODO: check          NOTE: not belived to be vulnerable (http://marc.theaimsgroup.com/?l=bugtraq&m=104931415307111&w=2)
3929  CAN-2003-0171  CAN-2003-0171
3930          TODO: check          NOTE: not-for-us (MacOS)
3931  CAN-2003-0170  CAN-2003-0170
3932          TODO: check          NOTE: not-for-us (AIX)
3933  CAN-2003-0169  CAN-2003-0169
3934          TODO: check          NOTE: not-for-us (HP Instant TopTools)
3935  CAN-2003-0168  CAN-2003-0168
3936          TODO: check          NOTE: not-for-us (Apple QuickTime Player)
3937  CAN-2003-0167  CAN-2003-0167
3938          NOTE: covered by DSA-274          NOTE: covered by DSA-274
3939  CAN-2003-0166  CAN-2003-0166
3940          TODO: check          NOTE: not belived to be vulnerable (http://marc.theaimsgroup.com/?l=bugtraq&m=104931415307111&w=2)
3941  CAN-2003-0165  CAN-2003-0165
3942          TODO: check          - eog 2.2.1
3943  CAN-2003-0164  CAN-2003-0164
3944          NOTE: reserved          NOTE: reserved
3945  CAN-2003-0163  CAN-2003-0163
3946          TODO: check          NOTE: Gaim-Encryption Plugin not in debian
3947  CAN-2003-0162  CAN-2003-0162
3948          NOTE: covered by DSA-271          NOTE: covered by DSA-271
3949  CAN-2003-0161  CAN-2003-0161
3950          NOTE: covered by DSA-278          NOTE: covered by DSA-278
3951  CAN-2003-0160  CAN-2003-0160
3952          TODO: check          - squirrelmail 1:1.2.11
3953  CAN-2003-0159  CAN-2003-0159
3954          TODO: check          - ethereal 0.9.10
3955  CAN-2003-0158  CAN-2003-0158
3956          NOTE: rejected          NOTE: rejected
3957  CAN-2003-0157  CAN-2003-0157
# Line 3782  CAN-2003-0153 Line 3967  CAN-2003-0153
3967  CAN-2003-0152  CAN-2003-0152
3968          NOTE: covered by DSA-265          NOTE: covered by DSA-265
3969  CAN-2003-0151  CAN-2003-0151
3970          TODO: check          NOTE: not-for-us (BEA WebLogic Server)
3971  CAN-2003-0150  CAN-2003-0150
3972          NOTE: covered by DSA-303          NOTE: covered by DSA-303
3973  CAN-2003-0149  CAN-2003-0149
3974          TODO: check          NOTE: not-for-us (McAfee ePolicy Orchestrator)
3975  CAN-2003-0148  CAN-2003-0148
3976          TODO: check          NOTE: not-for-us (McAfee ePolicy Orchestrator)
3977  CAN-2003-0147  CAN-2003-0147
3978          NOTE: covered by DSA-288          NOTE: covered by DSA-288
3979  CAN-2003-0146  CAN-2003-0146
# Line 3800  CAN-2003-0144 Line 3985  CAN-2003-0144
3985  CAN-2003-0143  CAN-2003-0143
3986          NOTE: covered by DSA-259          NOTE: covered by DSA-259
3987  CAN-2003-0142  CAN-2003-0142
3988          TODO: check          NOTE: not-for-us (acroread)
3989  CAN-2003-0141  CAN-2003-0141
3990          TODO: check          NOTE: not-for-us (Real)
3991  CAN-2003-0140  CAN-2003-0140
3992          NOTE: covered by DSA-268          NOTE: covered by DSA-268
3993  CAN-2003-0139  CAN-2003-0139
# Line 3810  CAN-2003-0139 Line 3995  CAN-2003-0139
3995  CAN-2003-0138  CAN-2003-0138
3996          NOTE: covered by DSA-266          NOTE: covered by DSA-266
3997  CAN-2003-0137  CAN-2003-0137
3998          TODO: check          NOTE: not-for-us (Nokia Serving GPRS support node)
3999  CAN-2003-0136  CAN-2003-0136
4000          NOTE: covered by DSA-285          NOTE: covered by DSA-285
4001  CAN-2003-0135  CAN-2003-0135
4002          TODO: check          NOTE: red-hat specific compilation problem of vsftpd
4003  CAN-2003-0134  CAN-2003-0134
4004          - apache2 2.0.46          - apache2 2.0.46
4005  CAN-2003-0133  CAN-2003-0133
4006          TODO: check          - evolution 1.2.4
4007  CAN-2003-0132  CAN-2003-0132
4008          - apache2 2.0.45          - apache2 2.0.45
4009  CAN-2003-0131  CAN-2003-0131
4010          NOTE: covered by DSA-288          NOTE: covered by DSA-288
4011  CAN-2003-0130  CAN-2003-0130
4012          TODO: check          - evolution 1.2.3
4013  CAN-2003-0129  CAN-2003-0129
4014          TODO: check          - evolution 1.2.3
4015  CAN-2003-0128  CAN-2003-0128
4016          TODO: check          - evolution 1.2.3
4017  CAN-2003-0127  CAN-2003-0127
4018          NOTE: covered by DSA-270          NOTE: covered by DSA-270
4019  CAN-2003-0126  CAN-2003-0126
4020          TODO: check          NOTE: not-for-us (SOHO Routefinder 550 firmware)
4021  CAN-2003-0121  CAN-2003-0121
4022          TODO: check          NOTE: not-for-us (Clearswift MAILsweeper)
4023  CAN-2003-0120  CAN-2003-0120
4024          NOTE: covered by DSA-256          NOTE: covered by DSA-256
4025  CAN-2003-0119  CAN-2003-0119
4026          TODO: check          NOTE: not-for-us (AIX)
4027  CAN-2003-0118  CAN-2003-0118
4028          TODO: check          NOTE: not-for-us (Microsoft)
4029  CAN-2003-0117  CAN-2003-0117
4030          TODO: check          NOTE: not-for-us (Microsoft)
4031  CAN-2003-0116  CAN-2003-0116
4032          TODO: check          NOTE: not-for-us (Microsoft)
4033  CAN-2003-0115  CAN-2003-0115
4034          TODO: check          NOTE: not-for-us (Microsoft)
4035  CAN-2003-0114  CAN-2003-0114
4036          TODO: check          NOTE: not-for-us (Microsoft)
4037  CAN-2003-0113  CAN-2003-0113
4038          - apache2 2.0.49          NOTE: not-for-us (Microsoft)
4039  CAN-2003-0112  CAN-2003-0112
4040          TODO: check          NOTE: not-for-us (Microsoft)
4041  CAN-2003-0111  CAN-2003-0111
4042          TODO: check          NOTE: not-for-us (Microsoft)
4043  CAN-2003-0110  CAN-2003-0110
4044          TODO: check          NOTE: not-for-us (Microsoft)
4045  CAN-2003-0109  CAN-2003-0109
4046          TODO: check          NOTE: not-for-us (Microsoft)
4047  CAN-2003-0108  CAN-2003-0108
4048          NOTE: covered by DSA-255          NOTE: covered by DSA-255
4049            - tcpdump 3.7.1-1.2
4050  CAN-2003-0106  CAN-2003-0106
4051          TODO: check          NOTE: not-for-us (Symantec Enterprise Firewall)
4052  CAN-2003-0105  CAN-2003-0105
4053          TODO: check          NOTE: not-for-us (ServerMask)
4054  CAN-2003-0102  CAN-2003-0102
4055          NOTE: covered by DSA-260          NOTE: covered by DSA-260
4056  CAN-2003-0101  CAN-2003-0101
# Line 3874  CAN-2003-0099 Line 4060  CAN-2003-0099
4060  CAN-2003-0098  CAN-2003-0098
4061          NOTE: covered by DSA-277          NOTE: covered by DSA-277
4062  CAN-2003-0096  CAN-2003-0096
4063          TODO: check          NOTE: not-for-us (Oracle)
4064  CAN-2003-0093  CAN-2003-0093
4065          NOTE: covered by DSA-261          NOTE: covered by DSA-261
4066  CAN-2003-0092  CAN-2003-0092
4067          TODO: check          NOTE: not-for-us (Solaris)
4068  CAN-2003-0091  CAN-2003-0091
4069          TODO: check          NOTE: not-for-us (Solaris)
4070  CAN-2003-0090  CAN-2003-0090
4071          NOTE: rejected          NOTE: rejected
4072  CAN-2003-0089  CAN-2003-0089
4073          TODO: check          NOTE: not-for-us (HP-UX)
4074  CAN-2003-0086  CAN-2003-0086
4075          NOTE: covered by DSA-262          NOTE: covered by DSA-262
4076  CAN-2003-0085  CAN-2003-0085
4077          NOTE: covered by DSA-262          NOTE: covered by DSA-262
4078  CAN-2003-0084  CAN-2003-0084
4079          TODO: check          NOTE: mod_auth_any not in Debian
4080  CAN-2003-0083  CAN-2003-0083
4081          - apache2 2.0.46          - apache2 2.0.46
4082            - apache 1.3.25
4083  CAN-2003-0082  CAN-2003-0082
4084          NOTE: covered by DSA-266          NOTE: covered by DSA-266
4085  CAN-2003-0081  CAN-2003-0081
4086          NOTE: covered by DSA-258          NOTE: covered by DSA-258
4087  CAN-2003-0080  CAN-2003-0080
4088          TODO: check          - gnome-lokkit 0.50.22-4
4089  CAN-2003-0078  CAN-2003-0078
4090          NOTE: covered by DSA-253          NOTE: covered by DSA-253
4091  CAN-2003-0076  CAN-2003-0076
4092          TODO: check          - dcgui 0.2.2
4093  CAN-2003-0074  CAN-2003-0074
4094          TODO: check          - plptools 0.12-0
4095  CAN-2003-0073  CAN-2003-0073
4096          NOTE: covered by DSA-303          NOTE: covered by DSA-303
4097  CAN-2003-0072  CAN-2003-0072
# Line 3999  CAN-2003-0005 Line 4186  CAN-2003-0005
4186          NOTE: reserved          NOTE: reserved
4187  CAN-2003-0001  CAN-2003-0001
4188          NOTE: covered by DSA-336          NOTE: covered by DSA-336
4189    
4190    begin claimed by pdwerryh-guest
4191    
4192  CAN-2002-1583  CAN-2002-1583
4193            NOTE: not-for-us (IBM DB2)
4194  CAN-2002-1582  CAN-2002-1582
4195            NOTE: mailreader. not clear if this was fixed.
4196            TODO: check
4197  CAN-2002-1581  CAN-2002-1581
4198          NOTE: covered by DSA-534          NOTE: covered by DSA-534
4199            - mailreader 2.3.29-9
4200  CAN-2002-1580  CAN-2002-1580
4201          NOTE: covered by DSA-215          NOTE: covered by DSA-215
4202            - cyrus-imapd 1.5.19-9.10
4203  CAN-2002-1579  CAN-2002-1579
4204            NOTE: not for us (SAP)
4205  CAN-2002-1578  CAN-2002-1578
4206            NOTE: not for us (SAP)
4207  CAN-2002-1577  CAN-2002-1577
4208            NOTE: not for us (SAP)
4209  CAN-2002-1576  CAN-2002-1576
4210            NOTE: not for us (SAP)
4211  CAN-2002-1575  CAN-2002-1575
4212          NOTE: covered by DSA-437          NOTE: covered by DSA-437
4213            - cgiemail 1.6-20
4214  CAN-2002-1573  CAN-2002-1573
4215          NOTE: reserved          NOTE: reserved
4216  CAN-2002-1572  CAN-2002-1572
# Line 4018  CAN-2002-1572 Line 4218  CAN-2002-1572
4218  CAN-2002-1571  CAN-2002-1571
4219          NOTE: reserved          NOTE: reserved
4220  CAN-2002-1570  CAN-2002-1570
4221            - ucd-snmp 4.2.3-2
4222  CAN-2002-1569  CAN-2002-1569
4223            - gv 1:3.5.8-27
4224  CAN-2002-1568  CAN-2002-1568
4225            - openssl 0.9.6g-1
4226  CAN-2002-1567  CAN-2002-1567
4227            NOTE: tomcat4 cross-site vuln
4228            TODO: check
4229  CAN-2002-1566  CAN-2002-1566
4230            - netris 0.52-1
4231  CAN-2002-1565  CAN-2002-1565
4232            NOTE: covered by DSA-209
4233            - wget 1.8.1-6.1
4234  CAN-2002-1564  CAN-2002-1564
4235            NOTE: not-for-us (microsoft)
4236  CAN-2002-1563  CAN-2002-1563
4237            - stunnel4 4.04-1
4238            - stunnel 2:3.24-1
4239  CAN-2002-1562  CAN-2002-1562
4240          NOTE: covered by DSA-396          NOTE: covered by DSA-396
4241            - thttpd 2.23beta1-2.3
4242  CAN-2002-1561  CAN-2002-1561
4243            NOTE: not-for-us (microsoft)
4244  CAN-2002-1559  CAN-2002-1559
4245            NOTE: not-for-us (ion-p)
4246  CAN-2002-1558  CAN-2002-1558
4247            NOTE: not-for-us (cisco)
4248  CAN-2002-1557  CAN-2002-1557
4249            NOTE: not-for-us (cisco)
4250  CAN-2002-1556  CAN-2002-1556
4251            NOTE: not-for-us (cisco)
4252  CAN-2002-1555  CAN-2002-1555
4253            NOTE: not-for-us (cisco)
4254  CAN-2002-1554  CAN-2002-1554
4255            NOTE: not-for-us (cisco)
4256  CAN-2002-1553  CAN-2002-1553
4257            NOTE: not-for-us (cisco)
4258  CAN-2002-1551  CAN-2002-1551
4259            NOTE: not-for-us (AIX)
4260  CAN-2002-1546  CAN-2002-1546
4261            NOTE: not-for-us (Webweaver)
4262  CAN-2002-1545  CAN-2002-1545
4263            NOTE: not-for-us (Coolsoft)
4264  CAN-2002-1544  CAN-2002-1544
4265            NOTE: not-for-us (Coolsoft)
4266  CAN-2002-1542  CAN-2002-1542
4267            NOTE: not-for-us (SolarWinds)
4268  CAN-2002-1539  CAN-2002-1539
4269            NOTE: not-for-us (MDaemon)
4270  CAN-2002-1536  CAN-2002-1536
4271            NOTE: not-for-us (Molly)
4272  CAN-2002-1535  CAN-2002-1535
4273            NOTE: not-for-us (Symantec)
4274  CAN-2002-1533  CAN-2002-1533
4275            NOTE: problem in jetty 4.1.0, Debian started with 4.2
4276  CAN-2002-1527  CAN-2002-1527
4277            NOTE: not-for-us (EMU Webmail)
4278  CAN-2002-1526  CAN-2002-1526
4279            NOTE: not-for-us (EMU Webmail)
4280  CAN-2002-1525  CAN-2002-1525
4281            NOTE: not-for-us (Sun)
4282  CAN-2002-1523  CAN-2002-1523
4283            NOTE: not-for-us (Miniserver)
4284  CAN-2002-1522  CAN-2002-1522
4285            NOTE: not-for-us (PowerFTP)
4286  CAN-2002-1515  CAN-2002-1515
4287            NOTE: not-for-us (Coolforum)
4288  CAN-2002-1512  CAN-2002-1512
4289            NOTE: not-for-us (BRU)
4290  CAN-2002-1508  CAN-2002-1508
4291          NOTE: covered by DSA-227          NOTE: covered by DSA-227
4292            - openldap2 2.0.27-3
4293  CAN-2002-1507  CAN-2002-1507
4294            NOTE: not-for-us (Unreal)
4295  CAN-2002-1506  CAN-2002-1506
4296            NOTE: linuxconf not in unstable or testing
4297  CAN-2002-1504  CAN-2002-1504
4298            NOTE: not-for-us (webserver-4everyone)
4299  CAN-2002-1503  CAN-2002-1503
4300            NOTE: AFD not in debian
4301  CAN-2002-1500  CAN-2002-1500
4302            NOTE: not-for-us (NetBSD)
4303  CAN-2002-1499  CAN-2002-1499
4304            NOTE: not-for-us (FactoSystem)
4305  CAN-2002-1498  CAN-2002-1498
4306            NOTE: not-for-us (SWServer)
4307  CAN-2002-1495  CAN-2002-1495
4308            NOTE: not-for-us (Jawmail)
4309  CAN-2002-1492  CAN-2002-1492
4310            NOTE: not-for-us (Cisco)
4311  CAN-2002-1489  CAN-2002-1489
4312            NOTE: not-for-us (PlanetDNS)
4313  CAN-2002-1488  CAN-2002-1488
4314            NOTE: not-for-us (Trillian)
4315  CAN-2002-1487  CAN-2002-1487
4316            NOTE: not-for-us (Trillian)
4317  CAN-2002-1486  CAN-2002-1486
4318            NOTE: not-for-us (Trillian)
4319  CAN-2002-1485  CAN-2002-1485
4320            NOTE: not-for-us (Trillian)
4321  CAN-2002-1484  CAN-2002-1484
4322            NOTE: not-for-us (db4web)
4323  CAN-2002-1483  CAN-2002-1483
4324            NOTE: not-for-us (db4web)
4325  CAN-2002-1482  CAN-2002-1482
4326            NOTE: phpGB not in Debian
4327  CAN-2002-1481  CAN-2002-1481
4328            NOTE: phpGB not in Debian
4329  CAN-2002-1480  CAN-2002-1480
4330            NOTE: phpGB not in Debian
4331  CAN-2002-1478  CAN-2002-1478
4332          NOTE: covered by DSA-164          NOTE: covered by DSA-164
4333  CAN-2002-1477  CAN-2002-1477
# Line 4285  CAN-2002-1301 Line 4541  CAN-2002-1301
4541          NOTE: reserved          NOTE: reserved
4542  CAN-2002-1300  CAN-2002-1300
4543          NOTE: reserved          NOTE: reserved
4544    
4545    end claimed by pdwerryh-guest
4546    
4547  CAN-2002-1299  CAN-2002-1299
4548          NOTE: reserved          NOTE: reserved
4549  CAN-2002-1298  CAN-2002-1298
# Line 4661  CAN-2002-0852 Line 4920  CAN-2002-0852
4920  CAN-2002-0849  CAN-2002-0849
4921  CAN-2002-0843  CAN-2002-0843
4922          NOTE: covered by DSA-187          NOTE: covered by DSA-187
4923            - apache 1.3.27-0.1
4924  CAN-2002-0841  CAN-2002-0841
4925          NOTE: rejected          NOTE: rejected
4926  CAN-2002-0840  CAN-2002-0840
4927          NOTE: covered by DSA-187          NOTE: covered by DSA-187
4928          - apache2 2.0.43-1          - apache2 2.0.43-1
4929            - apache 1.3.27-0.1
4930  CAN-2002-0839  CAN-2002-0839
4931          NOTE: covered by DSA-187          NOTE: covered by DSA-187
4932            - apache 1.3.27-0.1
4933  CAN-2002-0838  CAN-2002-0838
4934          NOTE: covered by DSA-176          NOTE: covered by DSA-176
4935  CAN-2002-0837  CAN-2002-0837
# Line 4784  CAN-2002-0656 Line 5046  CAN-2002-0656
5046          NOTE: covered by DSA-136          NOTE: covered by DSA-136
5047  CAN-2002-0655  CAN-2002-0655
5048          NOTE: covered by DSA-136          NOTE: covered by DSA-136
5049    
5050    NOTE: this is approximatly the release of woody, so we can stop here
5051    
5052  CAN-2002-0654  CAN-2002-0654
5053          - apache2 2.0.40          - apache2 2.0.40
5054  CAN-2002-0652  CAN-2002-0652
# Line 5202  CAN-2002-0010 Line 5467  CAN-2002-0010
5467  CAN-2002-0008  CAN-2002-0008
5468  CAN-2002-0001  CAN-2002-0001
5469  CAN-2001-1413  CAN-2001-1413
5470            NOTE: not vulnerable according to http://www.debian.org/security/nonvulns-sarge
5471  CAN-2001-1412  CAN-2001-1412
5472  CAN-2001-1411  CAN-2001-1411
5473  CAN-2001-1410  CAN-2001-1410

Legend:
Removed from v.75  
changed lines
  Added in v.127

  ViewVC Help
Powered by ViewVC 1.1.5