Package: passwd Version: 1:4.0.3-31sarge5 Severity: grave I just checked the source. From there it seems that the Debian passwd is affected by CVE-2006-3378 (USN-308-1 in Ubuntu), too.