Author: micah Date: 2006-04-08 18:27:57 +0000 (Sat, 08 Apr 2006) New Revision: 3776 Modified: data/DSA/list Log: Added DSA-1031-1 cacti Added DSA-1030-1 moodle Added DSA-1029-1 libphp-adodb Fixed incorrect dates on DSAs Updated sudo DSA to -2 Modified: data/DSA/list ==================================================================--- data/DSA/list 2006-04-08 18:19:30 UTC (rev 3775) +++ data/DSA/list 2006-04-08 18:27:57 UTC (rev 3776) @@ -1,19 +1,29 @@ -[07 Mar 2006] DSA-1028-1 libimager-perl - denial of service +[08 Apr 2006] DSA-1031-1 cacti - several + {CVE-2006-0146 CVE-2006-0147 CVE-2006-0410 CVE-2006-0806} + [sarge] - cacti 0.8.6c-7sarge3 +[08 Apr 2006] DSA-1030-1 moodle - several + {CVE-2006-0146 CVE-2006-0147 CVE-2006-0410 CVE-2006-0806} + [sarge] - moodle - 1.4.4.dfsg.1-3sarge1 +[08 Apr 2006] DSA-1029-1 libphp-adodb - several + {CVE-2006-0146 CVE-2006-0147 CVE-2006-0410 CVE-2006-0806} + [woody] - libphp-adodb 1.51-1.2 + [sarge] - libphp-adodb 4.52-1sarge1 +[07 Apr 2006] DSA-1028-1 libimager-perl - denial of service {CVE-2006-0053} [sarge] - libimager-perl 0.44-1sarge1 -[06 Jan 2006] DSA-1027-1 mailman - programming error +[06 Apr 2006] DSA-1027-1 mailman - programming error {CVE-2006-0052} [woody] - mailman <not-affected> (Vulnerable code not present) [sarge] - mailman 2.1.5-8sarge2 -[06 Jan 2006] DSA-1026-1 sash - buffer overflows +[06 Apr 2006] DSA-1026-1 sash - buffer overflows {CVE-2005-1849 CVE-2005-2096} [woody] - sash <not-affected> (Older zlib not vulnerable) [sarge] - sash 3.7-5sarge1 -[06 Jan 2006] DSA-1025-1 dia - programming error +[06 Apr 2006] DSA-1025-1 dia - programming error {CVE-2006-1550} [woody] - dia 0.88.1-3woody1 [sarge] - dia 0.94.0-7sarge3 -[05 Jan 2006] DSA-1024-1 clamav - heap overflow +[05 Apr 2006] DSA-1024-1 clamav - heap overflow {CVE-2006-1614 CVE-2006-1615 CVE-2006-1630} [sarge] - clamav 0.84-2.sarge.8 [05 Apr 2006] DSA-1023-1 kaffeine - buffer overflow @@ -346,10 +356,10 @@ {CVE-2006-0162 CVE-2005-3587} [sarge] - clamav 0.84-2.sarge.7 NOTE: fixed in testing at time of DSA -[20 Jan 2006] DSA-946-1 sudo - missing input sanitising +[08 Apr 2006] DSA-946-2 sudo - missing input sanitising {CVE-2005-4158 CVE-2006-0151} - [woody] - sudo 1.6.6-1.5 - [sarge] - sudo 1.6.8p7-1.3 + [woody] - sudo 1.6.6-1.6 + [sarge] - sudo 1.6.8p7-1.4 NOTE: fixed in testing at time of DSA NOTE: The fix for stable and oldstable switched from a black list NOTE: of dangerous env vars to a white list of known-to-be-safe env vars