Author: fw Date: 2005-10-20 12:14:18 +0000 (Thu, 20 Oct 2005) New Revision: 2505 Modified: data/CVE/list Log: Note that ruby was removed (post-woody). Replace a couple of binary package references with source packages, to avoid conflicts with data from DSA/list. Modified: data/CVE/list ==================================================================--- data/CVE/list 2005-10-20 12:07:10 UTC (rev 2504) +++ data/CVE/list 2005-10-20 12:14:18 UTC (rev 2505) @@ -2804,6 +2804,7 @@ RESERVED CVE-2005-2337 (Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to ...) {DSA-864-1 DSA-862-1 DSA-860-1} + - ruby <removed> - ruby1.6 1.6.8-13 (medium) - ruby1.8 1.8.3-1 (medium) - ruby1.9 1.9.0+20050921-1 (medium) @@ -12769,7 +12770,7 @@ - groff 1.18.1.1-2 CVE-2004-0968 (The catchsegv script in glibc 2.3.2 and earlier allows local users to ...) {DSA-636-1} - - libc6 2.3.2.ds1-19 + - glibc 2.3.2.ds1-19 CVE-2004-0967 (The (1) pj-gs.sh, (2) ps2epsi , (3) pv.sh, and (4) sysvlp.sh scripts ...) - gs-common 0.3.6-0.1 - gs-gpl <unfixed> (bug #291373; low) @@ -15147,7 +15148,7 @@ NOTE: affects openssl 0.9.6. Testing uses 0.9.7. CVE-2003-0850 (The TCP reassembly functionality in libnids before 1.18 allows remote ...) {DSA-410} - - libnids1 1.18-1 + - libnids 1.18-1 CVE-2003-0849 (Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote ...) - cfengine2 2.0.9+2.1.0b3-1 CVE-2003-0848 (Heap-based buffer overflow in main.c of slocate 2.6, and possibly ...) @@ -15482,7 +15483,7 @@ CVE-2003-0690 (KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred ...) {DSA-443 DSA-388} CVE-2003-0689 (The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows ...) - - libc6 2.2.5 + - glibc 2.2.5 CVE-2003-0688 (The DNS map code in Sendmail 8.12.8 and earlier, when using the ...) - sendmail 8.12.9 CVE-2003-0687 @@ -18706,7 +18707,7 @@ CVE-2002-1146 (The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries ...) NOTE: see http://www.kb.cert.org/vuls/id/AAMN-5D28K6 (glibc) NOTE: see http://www.kb.cert.org/vuls/id/AAMN-5D287U (bind) - - libc6 2.3 + - glibc 2.3 - bind 1:8.3.3 CVE-2002-1142 (Heap-based buffer overflow in the Remote Data Services (RDS) component ...) NOTE: not-for-us (Microsoft)