[Secure-testing-commits] r721 - sarge-checks/CAN
Joey Hess
joeyh@costa.debian.org
Fri, 01 Apr 2005 21:14:32 +0000
Author: joeyh
Date: 2005-04-01 21:14:26 +0000 (Fri, 01 Apr 2005)
New Revision: 721
Modified:
sarge-checks/CAN/list
Log:
automatic CAN database update
Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list 2005-04-01 19:45:19 UTC (rev 720)
+++ sarge-checks/CAN/list 2005-04-01 21:14:26 UTC (rev 721)
@@ -500,14 +500,17 @@
CAN-2005-0763 (Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may ...)
{DSA-698-1}
CAN-2005-0762 [imagemagick SGI heap overflow allows arbitrary code execution]
+ {DSA-702-1}
- imagemagick 5:6.0.0-1
NOTE: Does only affect imagemagick releases prior to 6
CAN-2005-0761 [imagemagick crafted PSD DoS]
- imagemagick 5:6.0.2.5
CAN-2005-0760 [imagemagick malformed TIFF crash DoS]
+ {DSA-702-1}
- imagemagick 5:6.0.0-1
NOTE: Does only affect imagemagick releases prior to 6
CAN-2005-0759 [imagemagick invalid TIFF tag DoS]
+ {DSA-702-1}
- imagemagick 5:6.0.0-1
NOTE: Does only affect imagemagick releases prior to 6
CAN-2005-0758
@@ -1741,11 +1744,12 @@
CAN-2005-0470 (Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers ...)
- wpasupplicant 0.3.8-1
CAN-2005-0469 (Buffer overflow in the slc_add_reply function in various BSD-based ...)
- {DSA-699-1 DSA-697-1}
+ {DSA-703-1 DSA-699-1 DSA-697-1}
TODO: krb4 contains a BSD derived telnet client as well, check whether it's vulnerable
- krb5 1.3.6-1
- heimdal (unfixed)
CAN-2005-0468 (Heap-based buffer overflow in the env_opt_add function in telnet.c for ...)
+ {DSA-703-1}
- krb5 1.3.6-1
TODO: check heimdal, krb4, netkit-telnet, netkit-telnet, netkit-telnet-ssl
CAN-2005-0467 (Multiple integer overflows in the (1) sftp_pkt_getstring and (2) ...)
@@ -2013,6 +2017,7 @@
CAN-2005-0398 (The KAME racoon daemon in ipsec-tools before 0.5 allows remote ...)
- racoon 1:0.5-5
CAN-2005-0397 (Format string vulnerability in ImageMagick before 6.0.2.5 allows ...)
+ {DSA-702-1}
- imagemagick 6:6.0.6.2-2.2
CAN-2005-0396 (Desktop Communication Protocol (DCOP) daemon, aka dcopserver, in KDE ...)
- kdelibs 3.3.2-4