thijs at alioth.debian.org
2007-Dec-15 15:49 UTC
[Secure-testing-commits] r7626 - in data: CVE DSA DTSA
Author: thijs Date: 2007-12-15 15:49:11 +0000 (Sat, 15 Dec 2007) New Revision: 7626 Modified: data/CVE/list data/DSA/list data/DTSA/list Log: add some missing epochs (mainly to DSAs) Modified: data/CVE/list ==================================================================--- data/CVE/list 2007-12-15 15:20:39 UTC (rev 7625) +++ data/CVE/list 2007-12-15 15:49:11 UTC (rev 7626) @@ -352,7 +352,7 @@ - claws-mail 3.1.0-2 (low; bug #454089) CVE-2007-6210 (zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" ...) {DSA-1420-1 DTSA-93-1} - - zabbix 1.4.2-4 (bug #452682) + - zabbix 1:1.4.2-4 (bug #452682) CVE-2007-6202 (SQL injection vulnerability in plugins/search/search.php in Neocrome ...) NOT-FOR-US: Neocrome Seditio CMS CVE-2007-6211 (Send ICMP Nasty Garbage (sing) on Debian GNU/Linux allows local users ...) @@ -3708,7 +3708,7 @@ CVE-2007-5207 (guilt 0.27 allows local users to overwrite arbitrary files via a ...) - guilt 0.27-1.2 (medium; bug #445308) CVE-2007-5193 (The default configuration for twiki 4.1.2 on Debian GNU/Linux, and ...) - - twiki 4.1.2-3 (bug #444982; low) + - twiki 1:4.1.2-3 (bug #444982; low) [etch] - twiki <no-dsa> (Minor packaging flaw, doesn''t warrant an update) CVE-2007-5172 (Quicksilver Forums before 1.4.1 allows remote attackers to obtain ...) NOT-FOR-US: Quicksilver Forums @@ -4184,7 +4184,7 @@ NOT-FOR-US: b1gMail CVE-2007-4974 (Heap-based buffer overflow in the flac_buffer_copy function in ...) - libsndfile 1.0.17-4 (bug #443386; medium) - - ardour 2.1-1.1 (medium; bug #445889) + - ardour 1:2.1-1.1 (medium; bug #445889) CVE-2007-4973 RESERVED CVE-2007-4972 (RegMon 7.04 does not properly validate certain parameters to System ...) @@ -10967,7 +10967,7 @@ [etch] - mixmaster 3.0b2-4.etch1 [sarge] - mixmaster <not-affected> (Code generation in Sarge pads over this) CVE-2007-XXXX [heap-based buffer overflow in git-blame with long file names] - - git-core 1.5.1.2-1 (low) + - git-core 1:1.5.1.2-1 (low) NOTE: http://git.kernel.org/?p=git/git.git;a=commit;h=1bb88be99e4fdedcd5cc5292c11b566a00028deb CVE-2007-2138 (Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x ...) {DSA-1311-1 DSA-1309-1} @@ -13114,7 +13114,7 @@ CVE-2006-7109 (Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal ...) NOT-FOR-US: Drupal module IMCE CVE-2007-XXXX [buffer overruns in GIT''s http-push.c, fixed in 1.5.0.3] - - git-core 1.5.0.3-1 (bug #413629; low) + - git-core 1:1.5.0.3-1 (bug #413629; low) [etch] - git-core 1:1.4.4.4-2 (bug #413629; low) CVE-2007-1273 (Integer overflow in the ktruser function in NetBSD-current before ...) NOT-FOR-US: NetBSD Kernel Modified: data/DSA/list ==================================================================--- data/DSA/list 2007-12-15 15:20:39 UTC (rev 7625) +++ data/DSA/list 2007-12-15 15:49:11 UTC (rev 7626) @@ -241,7 +241,7 @@ [etch] - kdebase 4:3.5.5a.dfsg.1-6etch1 [19 Sep 2007] DSA-1364-2 vim - several vulnerabilities {CVE-2007-2438 CVE-2007-2953} - [etch] - vim 7.0-122+1etch3 + [etch] - vim 1:7.0-122+1etch3 [17 Sep 2007] DSA-1375-1 openoffice.org - buffer overflow {CVE-2007-2834} [etch] - openoffice.org 2.0.4.dfsg.2-7etch2 @@ -310,8 +310,8 @@ [etch] - dovecot 1.0.rc15-2etch1 [26 Aug 2007] DSA-1358-1 asterisk {CVE-2007-1306 CVE-2007-1561 CVE-2007-2294 CVE-2007-2297 CVE-2007-2488 CVE-2007-3762 CVE-2007-3763 CVE-2007-3764} - [etch] - asterisk 1.2.13~dfsg-2etch1 - [sarge] - asterisk 1.0.7.dfsg.1-2sarge5 + [etch] - asterisk 1:1.2.13~dfsg-2etch1 + [sarge] - asterisk 1:1.0.7.dfsg.1-2sarge5 [19 Aug 2007] DSA-1357-1 koffice - integer overflow {CVE-2007-3387} [etch] - koffice 1:1.6.1-2etch1 @@ -365,7 +365,7 @@ [etch] - file 4.17-5etch2 [30 Jul 2007] DSA-1342-1 xfs {CVE-2007-3103} - [etch] - xfs 1.0.1-6 + [etch] - xfs 1:1.0.1-6 [25 Jul 2007] DSA-1341-2 bind9 - DNS cache poisoning vulnerability {CVE-2007-2926} [etch] - bind9 1:9.3.4-2etch1 @@ -464,11 +464,11 @@ [etch] - mplayer 1.0~rc1-12etch1 [18 Jun 2007] DSA-1312-1 libapache-mod-jk {CVE-2007-1860} - [etch] - libapache-mod-jk 1.2.18-3etch1 - [sarge] - libapache-mod-jk 1.2.5-2sarge1 + [etch] - libapache-mod-jk 1:1.2.18-3etch1 + [sarge] - libapache-mod-jk 1:1.2.5-2sarge1 [17 Jun 2007] DSA-1311-1 postgresql-7.4 {CVE-2007-2138} - [etch] - postgresql-7.4 7.4.17-0etch1 + [etch] - postgresql-7.4 1:7.4.17-0etch1 [sarge] - postgresql 7.4.7-6sarge5 [16 Jun 2007] DSA-1310-1 libexif {CVE-2006-4168} @@ -517,8 +517,8 @@ [etch] - gforge-plugin-scmcvs 4.5.14-5etch1 [21 May 2007] DSA-1296-1 php4 {CVE-2007-2509} - [etch] - php4 4.4.4-8+etch3 - [sarge] - php4 4.3.10-21 + [etch] - php4 6:4.4.4-8+etch3 + [sarge] - php4 4:4.3.10-21 [19 May 2007] DSA-1295-1 php5 {CVE-2007-2509 CVE-2007-2510} [etch] - php5 5.2.0-8+etch4 @@ -621,7 +621,7 @@ [sarge] - gnupg 1.4.1-1.sarge7 [10 Dec 2006] DSA-1265-1 mozilla {CVE-2006-6497 CVE-2006-6498 CVE-2006-6499 CVE-2006-6501 CVE-2006-6502 CVE-2006-6503 CVE-2006-6505} - [sarge] - mozilla 1.7.8-1sarge10 + [sarge] - mozilla 2:1.7.8-1sarge10 [07 Mar 2007] DSA-1264-1 php4 {CVE-2007-0906 CVE-2007-0907 CVE-2006-0908 CVE-2007-0909 CVE-2007-0910 CVE-2007-0988} [sarge] - php4 4:4.3.10-19 @@ -655,7 +655,7 @@ [sarge] - libgtop2 2.6.0-4sarge1 [27 Jan 2007] DSA-1254-1 bind9 {CVE-2007-0494} - [sarge] - bind9 9.2.4-1sarge2 + [sarge] - bind9 1:9.2.4-1sarge2 [27 Jan 2007] DSA-1253-1 mozilla-firefox {CVE-2006-6497 CVE-2006-6498 CVE-2006-6499 CVE-2006-6501 CVE-2006-6502 CVE-2006-6503} [sarge] - mozilla-firefox 1.0.4-2sarge15 @@ -695,7 +695,7 @@ [sarge] - elog 2.5.7+r1558-4+sarge3 [25 Dec 2006] DSA-1241-1 squirrelmail {CVE-2006-6142} - [sarge] - squirrelmail 1.4.4-10 + [sarge] - squirrelmail 2:1.4.4-10 [21 Dec 2006] DSA-1240-1 links2 {CVE-2006-5925} [sarge] - links2 2.1pre16-1sarge1 @@ -731,7 +731,7 @@ [sarge] - l2tpns 2.0.14-1sarge1 [06 Dec 2006] DSA-1229-1 asterisk {CVE-2006-5444} - [sarge] - asterisk 1.0.7.dfsg.1-2sarge4 + [sarge] - asterisk 1:1.0.7.dfsg.1-2sarge4 [05 Dec 2006] DSA-1228-1 elinks {CVE-2006-5925} [sarge] - elinks 0.10.4-7.1 @@ -746,7 +746,7 @@ [sarge] - mozilla-firefox 1.0.4-2sarge13 [03 Dec 2006] DSA-1224-1 mozilla {CVE-2006-4310 CVE-2006-5462 CVE-2006-5463 CVE-2006-5464 CVE-2006-5748} - [sarge] - mozilla 1.7.8-1sarge8 + [sarge] - mozilla 2:1.7.8-1sarge8 [01 Dec 2006] DSA-1223-1 tar {CVE-2006-6097} [sarge] - tar 1.14-2.3 @@ -776,7 +776,7 @@ [sarge] - xine-lib 1.0.1-1sarge4 [20 Nov 2006] DSA-1214 gv {CVE-2006-5864} - [sarge] - gv 3.6.1-10sarge2 + [sarge] - gv 1:3.6.1-10sarge2 [19 Nov 2006] DSA-1213 imagemagick {CVE-2006-0082 CVE-2006-4144 CVE-2006-5456 CVE-2006-5868} [sarge] - imagemagick 6:6.0.6.2-2.8 @@ -842,7 +842,7 @@ [sarge] - xfree86 4.3.0.dfsg.1-14sarge2 [06 Oct 2006] DSA-1192-1 mozilla {CVE-2006-2788 CVE-2006-4340 CVE-2006-4565 CVE-2006-4566 CVE-2006-4568 CVE-2006-4570 CVE-2006-4571} - [sarge] - mozilla 1.7.8-1sarge7.3.1 + [sarge] - mozilla 2:1.7.8-1sarge7.3.1 [05 Oct 2006] DSA-1191-1 mozilla-thunderbird {CVE-2006-2788 CVE-2006-4340 CVE-2006-4565 CVE-2006-4566 CVE-2006-4568 CVE-2006-4570 CVE-2006-4571} [sarge] - mozilla-thunderbird 1.0.2-2.sarge1.0.8c.1 @@ -897,7 +897,7 @@ [sarge] - openssl 0.9.7e-3sarge2 [09 Sep 2006] DSA-1172-1 bind9 - programming error {CVE-2006-4095 CVE-2006-4096} - [sarge] - bind9 9.2.4-1sarge1 + [sarge] - bind9 1:9.2.4-1sarge1 [07 Sep 2006] DSA-1171 ethereal - several {CVE-2006-4333 CVE-2005-3241 CVE-2005-3242 CVE-2005-3243 CVE-2005-3244 CVE-2005-3246 CVE-2005-3248 CVE-2005-3249} [sarge] - ethereal 0.10.10-2sarge8 @@ -946,13 +946,13 @@ [sarge] - ruby1.8 1.8.2-7sarge4 [27 Aug 2006] DSA-1156 kdebase {CVE-2006-2449} - [sarge] - kdebase 3.3.2-1sarge3 + [sarge] - kdebase 4:3.3.2-1sarge3 [24 Aug 2006] DSA-1155 sendmail - programming error {CVE-2006-1173} [sarge] - sendmail 8.13.4-3sarge2 [20 Aug 2006] DSA-1154 squirrelmail - variable overwriting {CVE-2006-4019} - [sarge] - squirrelmail 1.4.4-9 + [sarge] - squirrelmail 2:1.4.4-9 [18 Aug 2006] DSA-1153 clamav - buffer overflow {CVE-2006-4018} [sarge] - clamav 0.84-2.sarge.10 @@ -1036,7 +1036,7 @@ [sarge] - ethereal 0.10.10-2sarge6 [27 Jul 2006] DSA-1126 asterisk - several {CVE-2006-2898} - [sarge] - asterisk 1.0.7.dfsg.1-2sarge3 + [sarge] - asterisk 1:1.0.7.dfsg.1-2sarge3 [26 Jul 2006] DSA-1125 drupal - several {CVE-2006-2742 CVE-2006-2743 CVE-2006-2831 CVE-2006-2832 CVE-2006-2833} [sarge] - drupal 4.5.3-6.1sarge1 @@ -1045,7 +1045,7 @@ [sarge] - fbi 2.01-1.2sarge2 [24 Jul 2006] DSA-1123 libdumb - buffer overflow {CVE-2006-3668} - [sarge] - libdumb 0.9.2-6 + [sarge] - libdumb 1:0.9.2-6 [24 Jul 2006] DSA-1122 libnet-server-perl - format string {CVE-2005-1127} [sarge] - libnet-server-perl 0.87-3sarge1 @@ -1061,7 +1061,7 @@ [sarge] - hiki 0.6.5-2 [22 Jul 2006] DSA-1118 mozilla - several {CVE-2006-1942 CVE-2006-2775 CVE-2006-2776 CVE-2006-2777 CVE-2006-2778 CVE-2006-2779 CVE-2006-2780 CVE-2006-2781 CVE-2006-2782 CVE-2006-2783 CVE-2006-2784 CVE-2006-2785 CVE-2006-2786 CVE-2006-2787} - [sarge] - mozilla 1.7.8-1sarge7.1 + [sarge] - mozilla 2:1.7.8-1sarge7.1 [21 Jul 2006] DSA-1117 libgd2 - insufficient input sanitising {CVE-2006-2906} [sarge] - libgd2 2.0.33-1.1sarge1 @@ -1245,7 +1245,7 @@ [sarge] - phpgroupware 0.9.16.005-3.sarge5 [19 May 2006] DSA-1062-1 kphone - insecure file creation {CVE-2006-2442} - [sarge] - kphone 4.1.0-2sarge1 + [sarge] - kphone 1:4.1.0-2sarge1 [19 May 2006] DSA-1061-1 popfile - missing input sanitising {CVE-2006-0876} [sarge] - popfile 0.22.2-2sarge1 @@ -1297,7 +1297,7 @@ [sarge] - resmgr 1.0-2sarge2 [27 Apr 2006] DSA-1046-1 mozilla - several {CVE-2006-1732 CVE-2005-2353 CVE-2005-4134 CVE-2006-0292 CVE-2006-0293 CVE-2006-0748 CVE-2006-0749 CVE-2006-0884 CVE-2006-1045 CVE-2006-1529 CVE-2006-1530 CVE-2006-1531 CVE-2006-1723 CVE-2006-1724 CVE-2006-1727 CVE-2006-1728 CVE-2006-1729 CVE-2006-1730 CVE-2006-1731 CVE-2006-1733 CVE-2006-1734 CVE-2006-1735 CVE-2006-1736 CVE-2006-1737 CVE-2006-1738 CVE-2006-1739 CVE-2006-1740 CVE-2006-1741 CVE-2006-1742 CVE-2006-1790 CVE-2006-0296} - [sarge] - mozilla 1.7.8-1sarge5 + [sarge] - mozilla 2:1.7.8-1sarge5 [27 Apr 2006] DSA-1045-1 openvpn - design error {CVE-2006-1629} [sarge] - openvpn 2.0-1sarge3 @@ -1435,7 +1435,7 @@ NOTE: fixed in testing at the time of DSA [17 Mar 2006] DSA-1008-1 kpdf - buffer overflow {CVE-2006-0746} - [sarge] - kdegraphics 3.3.2-2sarge4 + [sarge] - kdegraphics 4:3.3.2-2sarge4 NOTE: Sid is not affected according to DSA [17 Mar 2006] DSA-1007-1 drupal - several {CVE-2006-1225 CVE-2006-1226 CVE-2006-1227 CVE-2006-1228} @@ -1694,12 +1694,12 @@ NOTE: fixed in testing at time of DSA [20 Jan 2006] DSA-949-1 crawl - insecure program execution {CVE-2006-0045} - [woody] - crawl 4.0.0beta23-2woody2 - [sarge] - crawl 4.0.0beta26-4sarge0 + [woody] - crawl 1:4.0.0beta23-2woody2 + [sarge] - crawl 1:4.0.0beta26-4sarge0 NOTE: not fixed in testing at time of DSA (unfixed in sid) [20 Jan 2006] DSA-948-1 kdelibs - heap overflow {CVE-2006-0019} - [sarge] - kdelibs 3.3.2-6.4 + [sarge] - kdelibs 4:3.3.2-6.4 NOTE: not fixed in testing at time of DSA (unfixed in sid) [20 Jan 2006] DSA-947-1 clamav - heap overflow {CVE-2006-0162 CVE-2005-3587} @@ -1737,7 +1737,7 @@ NOTE: Fixed in testing at time of DSA [16 Jan 2006] DSA-941-1 tuxpaint - insecure temporary file {CVE-2005-3340} - [sarge] - tuxpaint 0.9.14-2sarge0 + [sarge] - tuxpaint 1:0.9.14-2sarge0 NOTE: Not fixed in testing at time of DSA (only 2/2 days old) [13 Jan 2006] DSA-940-1 gpdf - buffer overflows {CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628} @@ -1750,7 +1750,7 @@ NOTE: Not fixed in testing at time of DSA (unfixed in sid) [12 Jan 2006] DSA-938-1 koffice - buffer overflows {CVE-2005-3191 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628} - [sarge] - koffice 1.3.5-4.sarge.2 + [sarge] - koffice 1:1.3.5-4.sarge.2 NOTE: Not fixed in testing at time of DSA (too new) [12 Jan 2006] DSA-937-1 tetex-bin - buffer overflows {CVE-2005-3191 CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628} @@ -1772,11 +1772,11 @@ [09 Jan 2006] DSA-933-1 hylafax - arbitrary command execution {CVE-2005-3539} [woody] - hylafax 4.1.1-4woody1 - [sarge] - hylafax 4.2.1-5sarge3 + [sarge] - hylafax 1:4.2.1-5sarge3 NOTE: Not fixed in testing at time of DSA (Valid candidate should sync today) [09 Jan 2006] DSA-932-1 kdegraphics - buffer overflows {CVE-2005-3191 CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628} - [sarge] - kdegraphics 3.3.2-2sarge3 + [sarge] - kdegraphics 4:3.3.2-2sarge3 [09 Jan 2006] DSA-931-1 xpdf - buffer overflows {CVE-2005-3191 CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628} [woody] - xpdf 1.00-3.8 @@ -1812,7 +1812,7 @@ [21 Dec 2005] DSA-924-1 nbd - buffer overflow {CVE-2005-3534} [woody] - nbd 1.2cvs20020320-3.woody.3 - [sarge] - nbd 2.7.3-3sarge1 + [sarge] - nbd 1:2.7.3-3sarge1 NOTE: not fixed in testing at time of DSA (unfixed in sid) [19 Dec 2005] DSA-923-1 dropbear - buffer overflow {CVE-2005-4178} @@ -3451,7 +3451,7 @@ [woody] - mysql 3.23.49-8.7 [18 Aug 2004] DSA-539 kdelibs - denial of service {CVE-2004-0689} - [woody] - kdelibs 2.2.2-13.woody.12 + [woody] - kdelibs 4:2.2.2-13.woody.12 [17 Aug 2004] DSA-538 rsync - unauthorised directory traversal and file access {CVE-2004-0792} [woody] - rsync 2.5.5-0.6 @@ -3516,7 +3516,7 @@ [woody] - cvs 1.11.1p1debian-9woody7 [14 Jun 2004] DSA-518 kdelibs - unsanitised input {CVE-2004-0411} - [woody] - kdelibs 2.2.2-13.woody.10 + [woody] - kdelibs 4:2.2.2-13.woody.10 [10 Jun 2004] DSA-517 cvs - buffer overflow {CVE-2004-0414} [woody] - cvs 1.11.1p1debian-9woody6 @@ -4033,8 +4033,8 @@ [woody] - mindi 0.58.r5-1woody1 [01 Aug 2003] DSA-361 kdelibs, kdelibs-crypto - several vulnerabilities {CVE-2003-0459 CVE-2003-0370} - [woody] - kdelibs 2.2.2-13.woody.8 - [woody] - kdelibs-crypto 2.2.2-6woody2 + [woody] - kdelibs 4:2.2.2-13.woody.8 + [woody] - kdelibs-crypto 4:2.2.2-6woody2 [01 Aug 2003] DSA-360 xfstt - several vulnerabilities {CVE-2003-0581 CVE-2003-0625} [woody] - xfstt 1.2.1-3 @@ -4248,7 +4248,7 @@ [woody] - gkrellm-newsticker 0.3-3.1 [23 Apr 2003] DSA-293 kdelibs - insecure execution {CVE-2003-0204} - [woody] - kdebase 2.2.2-13.woody.7 + [woody] - kdebase 4:2.2.2-13.woody.7 [22 Apr 2003] DSA-292 mime-support - insecure temporary file creation {CVE-2003-0214} [woody] - mime-support 3.18-1.3 @@ -4683,7 +4683,7 @@ [woody] - l2tpd 0.67-1.1 [13 Aug 2002] DSA-151 xinetd - pipe exposure {CVE-2002-0871} - [woody] - xinetd 2.3.4-1.2 + [woody] - xinetd 1:2.3.4-1.2 [13 Aug 2002] DSA-150 interchange - illegal file exposition {CVE-2002-0874} [woody] - interchange 4.8.3.20020306-1.woody.1 @@ -4692,7 +4692,7 @@ [woody] - glibc 2.2.5-11.1 [12 Aug 2002] DSA-148 hylafax - buffer overflows and format string vulnerabilities {CVE-2002-1049 CVE-2002-1050 CVE-2001-1034} - [woody] - hylafax 4.1.1-1.1 + [woody] - hylafax 1:4.1.1-1.1 [08 Aug 2002] DSA-147 mailman - cross-site scripting {CVE-2002-0388 CVE-2002-0855} [woody] - mailman 2.0.11-1woody4 Modified: data/DTSA/list ==================================================================--- data/DTSA/list 2007-12-15 15:20:39 UTC (rev 7625) +++ data/DTSA/list 2007-12-15 15:49:11 UTC (rev 7626) @@ -136,10 +136,10 @@ [lenny] - gnash 0.7.2-1lenny1 [August 7th, 2007] DTSA-49-1 kdegraphics - arbitrary code execution {CVE-2007-3387} - [lenny] - kdegraphics 3.5.7-2lenny1 + [lenny] - kdegraphics 4:3.5.7-2lenny1 [August 7th, 2007] DTSA-50-1 koffice - arbitrary code execution {CVE-2007-3387} - [lenny] - koffice 1.6.3-1lenny1 + [lenny] - koffice 1:1.6.3-1lenny1 [August 12th, 2007] DTSA-51-1 xulrunner - several vulnerabilities {CVE-2007-1116 CVE-2007-1362 CVE-2007-2867 CVE-2007-2868 CVE-2007-2869 CVE-2007-2870 CVE-2007-2871 CVE-2007-3089 CVE-2007-3656 CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3738 CVE-2007-3844 CVE-2007-3845 CVE-2007-4041} [lenny] - xulrunner 1.8.0.13~pre070720-0etch3+lenny1