We''ve got a number of different entries for elog in CAN/list. Without CAN numbers for the first two, it is hard to tell if they are perhaps duplicates with each other? Additionally, can either of these be mapped to any of the actual CAN numbers? CAN-2005-XXXX [Buffer overflow in elog header_buffer] - elog 2.5.9+r1674-1 CAN-2005-XXXX [Buffer overflow in elog] - elog 2.5.7+r1558-3 CAN-2005-0440 (ELOG before 2.5.7 allows remote attackers to bypass authentication and ...) - elog 2.5.7+r1558-1 CAN-2005-0439 (Buffer overflow in the decode_post function in ELOG before 2.5.7 ...) - elog 2.5.7+r1558-1 -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: Digital signature Url : http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20050530/4130ff50/attachment.pgp