[Secure-testing-commits] r160 - sarge-checks/CAN
Joey Hess
joeyh@haydn.debian.org
Fri, 03 Dec 2004 12:49:40 -0700
Author: joeyh
Date: 2004-12-03 12:49:16 -0700 (Fri, 03 Dec 2004)
New Revision: 160
Modified:
sarge-checks/CAN/list
Log:
formatting
Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list 2004-12-03 19:38:54 UTC (rev 159)
+++ sarge-checks/CAN/list 2004-12-03 19:49:16 UTC (rev 160)
@@ -203,7 +203,8 @@
{DSA-603-1}
- openssl 0.9.7e-1
NOTE: also includes other security fixes than this CAN
-CAN-2004-0974 [local; low]
+CAN-2004-0974
+ NOTE: local; low
- netatalk 1.6.4a-1
CAN-2004-0973
NOTE: rejected
@@ -1878,7 +1879,8 @@
NOTE: fixed in 2.4.26-pre4
CAN-2004-0176
- ethereal 0.10.3-1
-CAN-2004-0175 [very low]
+CAN-2004-0175
+ NOTE: very low
- openssh (unfixed; bug #270770)
NOTE: this bug is old and known; see the bug discussion for further information.
NOTE: apparently the security team thinks this is a minor issue; nevertheless,
@@ -2530,7 +2532,8 @@
NOTE: not-for-us (Apple)
CAN-2003-0876
NOTE: not-for-us (Apple)
-CAN-2003-0875 [source package only]
+CAN-2003-0875
+ NOTE: source package only
NOTE: openslp: slpd.all_init symlink vuln
NOTE: this file is not used in Debian, so it's not a problem for us.
NOTE: source package still distributes the file, however.
@@ -4068,7 +4071,7 @@
NOTE: not-for-us (Nokia Serving GPRS support node)
CAN-2003-0136
{DSA-285}
-CAN-2003-0135
+CAN-2003-0135
NOTE: red-hat specific compilation problem of vsftpd
CAN-2003-0134
- apache2 2.0.46
@@ -4209,7 +4212,7 @@
NOTE: not-for-us (ml85p, as included in the printer-drivers package for Mandrake Linux)
CAN-2003-0035
NOTE: not-for-us (ml85p, as included in the printer-drivers package for Mandrake Linux)
-CAN-2003-0034a
+CAN-2003-0034
NOTE: HOME overflow was fixed in mainSrc/rcfile.c, but not in
NOTE: chooser/mtinkc.c's version, which goes into mtinkc
NOTE: it's not installed setuid or setgid, so this is not exploitable