[Secure-testing-commits] r581 - sarge-checks/CAN

Joey Hess joeyh@costa.debian.org
Fri, 18 Mar 2005 23:15:27 +0100


Author: joeyh
Date: 2005-03-18 23:15:24 +0100 (Fri, 18 Mar 2005)
New Revision: 581

Modified:
   sarge-checks/CAN/list
Log:
xli fixed
xpdf 64 incomplete fix affects at least tetex-bin


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-03-18 22:00:54 UTC (rev 580)
+++ sarge-checks/CAN/list	2005-03-18 22:15:24 UTC (rev 581)
@@ -366,9 +366,8 @@
 CAN-2005-0639 (Multiple vulnerabilities in xli before 1.17 may allow remote attackers ...)
 	- xloadimage 4.1-14.2
 	- xli 1.17.0-17
-	NOTE: Bug maintainer to mention CAN-id in changelog - jmm
 CAN-2005-0638 (xloadimage before 4.1-r2, and xli before 1.17, allows attackers to ...)
-	- xli (unfixed; bug #298039)
+	- xli 1.17.0-17
 	- xloadimage 4.1-14.1
 	NOTE: The bug closer for 289039 claims that fixed, but I can't find an obvious
 	NOTE: fix in the interdiff between -16 and -17, needs further evaluation - jmm
@@ -2128,7 +2127,8 @@
 	- kernel-source-2.6.8 2.6.8-14
 	- kernel-source-2.6.8 2.6.8-14
 CAN-2005-0206 (The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 ...)
-	TODO: check
+	- tetex-bin (unfixed; bug #300182)
+	TODO: check other packages
 CAN-2005-0205 (KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain ...)
 	{DSA-692-1}
 	- kppp 4:3.1.6