[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Preparation of the next stable Debian GNU/Linux update (I)



Preparation of the next stable Debian GNU/Linux update
======================================================

An up-to-date version is at <http://people.debian.org/~joey/3.0r5/>.

I am preparing the next revision of the current stable Debian
distribution (woody) and will infrequently send reports so people can
actually comment on it and intervene whenever this is required.  It is
scheduled for the end of February / beginning of March.

If you disagree with one bit or another, please reply to this mail and
explain why these things should be handled differently.  There is
still time to reconsider.

The plan is to release this revision roughly two months after the last
update.  However, it may be required that this happens before the
release of sarge or it won't happen at all.  It may be the last update
if no updates to 3.0 are possible after sarge has been released.

An ftpmaster still has to give the final approval for each package
since ftpmasters are responsible for the archive.  However, I'm trying
to make their work as easy as possible in the hope to get the next
revision out properly and without too much hassle.

The regulations for updates to the stable Debian release are quite
conservative.

The requirements for packages to get updated in stable are:

 1. The package fixes a security problem.  An advisory by our own
    Security Team is required.  Updates need to be approved by the
    Security Team.

 2. The package fixes a critical bug which can lead into data loss,
    data corruption, or an overly broken system, or the package is
    broken or not usable (anymore).

 3. The stable version of the package is not installable at all due to
    broken or unmet dependencies or broken installation scripts.

 4. All released architectures have to be in sync.

 5. The package gets all released architectures back in sync.

It is (or (and (or 1 2 3) 4) 5)

Regular bugs and upgrade problems don't get fixed in new revisions for
the stable distribution.  They should instead be documented in the
Release Notes which are maintained by Rob Bradford
<mailto:robster@debian.org> and are found at
<http://www.debian.org/releases/woody/releasenotes>.

Packages, which will most probably be rejected:

  . Packages that fix non-critical bugs.

  . Misplaced uploads, i.e. packages that were uploaded to 'stable
    unstable' or `frozen unstable' or similar.

  . Packages for which its binary packages are out of sync with regard
    to all supported architectures in the stable distribution.

  . Binary packages for which the source got lost somehow.

  . Packages that fix an unusable minor part of a package.

If you would like to get a package updated in the stable release, you
are advised to talk to the stable release manager first (see
<http://www.debian.org/intro/organization>).

Changelog
---------

2005/01/28 11:53 MET

 * Accepted chbg
 * Accepted enscript
 * Accepted f2c
 * Accepted gallery
 * Accepted gatos
 * Accepted imagemagick
 * Accepted kdebase
 * Accepted libdbi-perl
 * Accepted mc
 * Accepted mysql
 * Accepted playmidi
 * Accepted queue
 * Accepted squid
 * Accepted sword
 * Accepted unarj
 * Accepted vdr
 * Moved wmaker from further to accept
 * Accepted xine-lib
 * Accepted xtrlock
 * Accepted zhcon
 * Updated xpdf

2005/01/14 15:55 MET

 * Accepted bmv
 * Accepted cacti
 * Moved catdoc from further to reject
 * Accepted exim
 * Accepted glibc
 * Accepted gopher
 * Accepted hylafax
 * Accepted kdelibs
 * Accepted linpopup
 * Accepted lintian
 * Investigation of wmaker

2005/01/09 12:27 MET

 * Investigation of acorn-fdisk
 * Investigation of catdoc
 * Investigation of console-common
 * Accepted cupsys
 * Investigation of gcc-2.95
 * Accepted htmlheadline
 * Accepted imlib2
 * Investigation of kernel-image-2.2.20-reiserfs-i386
 * Investigation of kernel-image-2.4.18-1-alpha
 * Investigation of kernel-image-2.4.18-1-i386
 * Investigation of kernel-image-2.4.18-i386bf
 * Investigation of kernel-image-2.4.19-ia64
 * Investigation of kernel-patch-2.4-grsecurity
 * Accepted krb5
 * Investigation of lha
 * Accepted libgd1
 * Investigation of libpam-radius-auth
 * Investigation of lsb
 * Accepted mm
 * Accepted namazu2
 * Accepted nasm
 * Investigation of parted
 * Accepted pcal
 * Accepted perl
 * Investigation of qpopper
 * Investigation of slocate
 * Investigation of spellcast
 * Investigation of spellcast-doc
 * Investigation of ssed
 * Investigation of syslog-ng
 * Accepted tiff
 * Accepted xpdf
 * Investigation of yaboot
 * Accepted zip

Accepted Packages
-----------------

These packages will be installed into the stable Debian distribution
and will be part of the next revision.

bmv         stable    1.2-14      i386 source
bmv         updates   1.2-14.2    i386 source

	DSA 633 bmv - insecure temporary file

cacti       stable    0.6.7-2     all source
cacti       updates   0.6.7-2.2   all source

	DSA 164 cacti - arbitrary code execution

chbg        stable    1.5-1        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
chbg        updates   1.5-1woody1  alpha arm i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 644 chbg - buffer overflow

	HPPA: Cannot be updated due to compiler error.

cupsys-bsd         stable    1.1.14-5woody10  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
cupsys-bsd         updates   1.1.14-5woody12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
cupsys-client      stable    1.1.14-5woody10  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
cupsys-client      updates   1.1.14-5woody12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
cupsys-pstoraster  stable    1.1.14-5woody10  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
cupsys-pstoraster  updates   1.1.14-5woody12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
cupsys             stable    1.1.14-5woody10  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
cupsys             updates   1.1.14-5woody12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
libcupsys2-dev     stable    1.1.14-5woody10  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libcupsys2-dev     updates   1.1.14-5woody12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libcupsys2         stable    1.1.14-5woody10  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libcupsys2         updates   1.1.14-5woody12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc

	DSA 645 cupsys - buffer overflow

	DSA 621 cupsys - buffer overflow

enscript    stable    1.6.3-1.1   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
enscript    updates   1.6.3-1.3   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 654 enscript - several vulnerabilities

eximon      stable    3.35-1woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
eximon      updates   3.35-1woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
exim        stable    3.35-1woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
exim        updates   3.35-1woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 635 exim - buffer overflow

f2c         stable    20010821-3    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
f2c         updates   20010821-3.1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 661 f2c - insecure temporary files

gallery     stable    1.2.5-8woody2  all source
gallery     updates   1.2.5-8woody3  all source

	DSA 642 gallery - several vulnerabilities

gatos       stable    0.0.5-6woody1  i386 source
gatos       updates   0.0.5-6woody3  i386 source

	DSA 640 gatos - buffer overflow

glibc-doc          stable    2.2.5-11.5  all
glibc-doc          updates   2.2.5-11.8  all
glibc              stable    2.2.5-11.5  source
glibc              updates   2.2.5-11.8  source
libc6-dbg          stable    2.2.5-11.5  arm hppa i386 m68k mips mipsel powerpc s390 sparc
libc6-dbg          updates   2.2.5-11.8  arm hppa i386 m68k mips mipsel powerpc s390 sparc
libc6-dev-sparc64  stable    2.2.5-11.5  sparc
libc6-dev-sparc64  updates   2.2.5-11.8  sparc
libc6-dev          stable    2.2.5-11.5  arm hppa i386 m68k mips mipsel powerpc s390 sparc
libc6-dev          updates   2.2.5-11.8  arm hppa i386 m68k mips mipsel powerpc s390 sparc
libc6-pic          stable    2.2.5-11.5  arm hppa i386 m68k mips mipsel powerpc s390 sparc
libc6-pic          updates   2.2.5-11.8  arm hppa i386 m68k mips mipsel powerpc s390 sparc
libc6-prof         stable    2.2.5-11.5  arm hppa i386 m68k mips mipsel powerpc s390 sparc
libc6-prof         updates   2.2.5-11.8  arm hppa i386 m68k mips mipsel powerpc s390 sparc
libc6-sparc64      stable    2.2.5-11.5  sparc
libc6-sparc64      updates   2.2.5-11.8  sparc
libc6.1-dbg        stable    2.2.5-11.5  alpha ia64
libc6.1-dbg        updates   2.2.5-11.8  alpha ia64
libc6.1-dev        stable    2.2.5-11.5  alpha ia64
libc6.1-dev        updates   2.2.5-11.8  alpha ia64
libc6.1-pic        stable    2.2.5-11.5  alpha ia64
libc6.1-pic        updates   2.2.5-11.8  alpha ia64
libc6.1-prof       stable    2.2.5-11.5  alpha ia64
libc6.1-prof       updates   2.2.5-11.8  alpha ia64
libc6.1            stable    2.2.5-11.5  alpha ia64
libc6.1            updates   2.2.5-11.8  alpha ia64
libc6              stable    2.2.5-11.5  arm hppa i386 m68k mips mipsel powerpc s390 sparc
libc6              updates   2.2.5-11.8  arm hppa i386 m68k mips mipsel powerpc s390 sparc
locales            stable    2.2.5-11.5  all
locales            updates   2.2.5-11.8  all
nscd               stable    2.2.5-11.5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
nscd               updates   2.2.5-11.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc

	DSA 636 glibc - insecure temporary files

gopherd     stable    3.0.3woody1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
gopherd     updates   3.0.3woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
gopher      stable    3.0.3woody1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
gopher      updates   3.0.3woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 638 gopher - several vulnerabilities

htmlheadline  stable    21.8-2      all source
htmlheadline  updates   21.8-3      all source

	DSA 622 htmlheadline - insecure temporary files

hylafax-client  stable    1:4.1.1-3    alpha arm hppa i386 ia64 m68k powerpc s390 sparc
hylafax-client  updates   1:4.1.1-3.1  alpha arm hppa i386 ia64 m68k powerpc s390 sparc
hylafax-doc     stable    1:4.1.1-3    all
hylafax-doc     updates   1:4.1.1-3.1  all
hylafax-server  stable    1:4.1.1-3    alpha arm hppa i386 ia64 m68k powerpc s390 sparc
hylafax-server  updates   1:4.1.1-3.1  alpha arm hppa i386 ia64 m68k powerpc s390 sparc
hylafax         stable    1:4.1.1-3    source
hylafax         updates   1:4.1.1-3.1  source

	DSA 634 hylafax - weak hostname and username validation

imagemagick       stable    4:5.4.4.5-1woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
imagemagick       updates   4:5.4.4.5-1woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
libmagick++5-dev  stable    4:5.4.4.5-1woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmagick++5-dev  updates   4:5.4.4.5-1woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmagick++5      stable    4:5.4.4.5-1woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmagick++5      updates   4:5.4.4.5-1woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmagick5-dev    stable    4:5.4.4.5-1woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmagick5-dev    updates   4:5.4.4.5-1woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmagick5        stable    4:5.4.4.5-1woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmagick5        updates   4:5.4.4.5-1woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
perlmagick        stable    4:5.4.4.5-1woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
perlmagick        updates   4:5.4.4.5-1woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc

	DSA 646 imagemagick - buffer overflow

imlib2         stable    1.0.5-2woody1  source
imlib2         updates   1.0.5-2woody2  source
libimlib2-dev  stable    1.0.5-2woody1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libimlib2-dev  updates   1.0.5-2woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libimlib2      stable    1.0.5-2woody1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libimlib2      updates   1.0.5-2woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc

	DSA 628 imlib2 - integer overflows

kate               stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kate               updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdebase-audiolibs  stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdebase-audiolibs  updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdebase-dev        stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdebase-dev        updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdebase-doc        stable    4:2.2.2-14.8  all
kdebase-doc        updates   4:2.2.2-14.9  all
kdebase-libs       stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdebase-libs       updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdebase            stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
kdebase            updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
kdewallpapers      stable    4:2.2.2-14.8  all
kdewallpapers      updates   4:2.2.2-14.9  all
kdm                stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdm                updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
konqueror          stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
konqueror          updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
konsole            stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
konsole            updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kscreensaver       stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kscreensaver       updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkonq-dev        stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkonq-dev        updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkonq3           stable    4:2.2.2-14.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkonq3           updates   4:2.2.2-14.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc

	DSA 660 kdebase - missing return value check

kdelibs-dev    stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdelibs-dev    updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdelibs3-bin   stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdelibs3-bin   updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdelibs3-cups  stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdelibs3-cups  updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdelibs3-doc   stable    4:2.2.2-13.woody.12  all
kdelibs3-doc   updates   4:2.2.2-13.woody.13  all
kdelibs3       stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdelibs3       updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
kdelibs        stable    4:2.2.2-13.woody.12  source
kdelibs        updates   4:2.2.2-13.woody.13  source
libarts-alsa   stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libarts-alsa   updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libarts-dev    stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libarts-dev    updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libarts        stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libarts        updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkmid-alsa   stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkmid-alsa   updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkmid-dev    stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkmid-dev    updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkmid        stable    4:2.2.2-13.woody.12  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkmid        updates   4:2.2.2-13.woody.13  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc

	DSA 631 kdelibs - unsanitised input

krb5-admin-server  stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-admin-server  updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-clients       stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-clients       updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-doc           stable    1.2.4-5woody6  all
krb5-doc           updates   1.2.4-5woody7  all
krb5-ftpd          stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-ftpd          updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-kdc           stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-kdc           updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-rsh-server    stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-rsh-server    updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-telnetd       stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-telnetd       updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-user          stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5-user          updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
krb5               stable    1.2.4-5woody6  source
krb5               updates   1.2.4-5woody7  source
libkadm55          stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkadm55          updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkrb5-dev        stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkrb5-dev        updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkrb53           stable    1.2.4-5woody6  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libkrb53           updates   1.2.4-5woody7  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc

	DSA 629 krb5 - buffer overflow

libdbi-perl  stable    1.21-2        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
libdbi-perl  updates   1.21-2woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 658 libdbi-perl - insecure temporary file

libgd-dev        stable    1.8.4-17.woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libgd-dev        updates   1.8.4-17.woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libgd-noxpm-dev  stable    1.8.4-17.woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libgd-noxpm-dev  updates   1.8.4-17.woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libgd1-noxpm     stable    1.8.4-17.woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libgd1-noxpm     updates   1.8.4-17.woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libgd1           stable    1.8.4-17.woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libgd1           updates   1.8.4-17.woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libgd            stable    1.8.4-17.woody2  source
libgd            updates   1.8.4-17.woody4  source

	DSA 589 libgd1 - integer overflows

	DSA 601 libgd1 - integer overflow

libpam-radius-auth  stable    1.3.14-1    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
libpam-radius-auth  updates   1.3.14-1.3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 659 libpam-radius-auth - information leak, integer underflow

linpopup    stable    1.2.0-2        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
linpopup    updates   1.2.0-2woody1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 632 linpopup - buffer overflow

lintian     stable    1.20.17     all source
lintian     updates   1.20.17.1   all source

	DSA 630 lintian - insecure temporary directory

gmc         stable    4.5.55-1.2woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
gmc         updates   4.5.55-1.2woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
mc-common   stable    4.5.55-1.2woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
mc-common   updates   4.5.55-1.2woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
mc          stable    4.5.55-1.2woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
mc          updates   4.5.55-1.2woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 639 mc - several vulnerabilities

libmm11-dev  stable    1.1.3-6.2   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmm11-dev  updates   1.1.3-6.3   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmm11      stable    1.1.3-6.2   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmm11      updates   1.1.3-6.3   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
mm           stable    1.1.3-6.2   source
mm           updates   1.1.3-6.3   source

	Fix Bug#280871 which caused Apache to crash.

libmysqlclient10-dev  stable    3.23.49-8.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmysqlclient10-dev  updates   3.23.49-8.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmysqlclient10      stable    3.23.49-8.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libmysqlclient10      updates   3.23.49-8.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
mysql-client          stable    3.23.49-8.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
mysql-client          updates   3.23.49-8.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
mysql-common          stable    3.23.49-8.8  all
mysql-common          updates   3.23.49-8.9  all
mysql-server          stable    3.23.49-8.8  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
mysql-server          updates   3.23.49-8.9  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc

	DSA 647 mysql - insecure temporary files

namazu2     stable    2.0.10-1        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
namazu2     updates   2.0.10-1woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 627 namazu2 - unsanitised input

nasm        stable    0.98.28cvs-1        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
nasm        updates   0.98.28cvs-1woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 623 nasm - buffer overflow

pcal        stable    4.7-8        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
pcal        updates   4.7-8woody1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 625 pcal - buffer overflows

libcgi-fast-perl  stable    5.6.1-8.7   all
libcgi-fast-perl  updates   5.6.1-8.8   all
libperl-dev       stable    5.6.1-8.7   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libperl-dev       updates   5.6.1-8.8   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libperl5.6        stable    5.6.1-8.7   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libperl5.6        updates   5.6.1-8.8   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
perl-base         stable    5.6.1-8.7   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
perl-base         updates   5.6.1-8.8   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
perl-debug        stable    5.6.1-8.7   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
perl-debug        updates   5.6.1-8.8   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
perl-doc          stable    5.6.1-8.7   all
perl-doc          updates   5.6.1-8.8   all
perl-modules      stable    5.6.1-8.7   all
perl-modules      updates   5.6.1-8.8   all
perl-suid         stable    5.6.1-8.7   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
perl-suid         updates   5.6.1-8.8   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
perl              stable    5.6.1-8.7   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
perl              updates   5.6.1-8.8   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 620 perl - insecure temporary files / directories

playmidi    stable    2.4-4        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
playmidi    updates   2.4-4woody1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 641 playmidi - buffer overflow

queue       stable    1.30.1-4        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
queue       updates   1.30.1-4woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 643 queue - buffer overflows

squid-cgi    stable    2.4.6-2woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
squid-cgi    updates   2.4.6-2woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
squidclient  stable    2.4.6-2woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
squidclient  updates   2.4.6-2woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
squid        stable    2.4.6-2woody4  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
squid        updates   2.4.6-2woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 651 squid - buffer overflow, integer overflow

diatheke          stable    1.5.3-3        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
diatheke          updates   1.5.3-3woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libsword-dev      stable    1.5.3-3        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libsword-dev      updates   1.5.3-3woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libsword-runtime  stable    1.5.3-3        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libsword-runtime  updates   1.5.3-3woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libsword1         stable    1.5.3-3        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libsword1         updates   1.5.3-3woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
sword             stable    1.5.3-3        source
sword             updates   1.5.3-3woody2  source

	DSA 650 sword - missing input sanitising

libtiff-tools  stable    3.5.5-6.woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libtiff-tools  updates   3.5.5-6.woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libtiff3g-dev  stable    3.5.5-6.woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libtiff3g-dev  updates   3.5.5-6.woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libtiff3g      stable    3.5.5-6.woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libtiff3g      updates   3.5.5-6.woody5  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
tiff           stable    3.5.5-6.woody3  source
tiff           updates   3.5.5-6.woody5  source

	DSA 626 tiff - unsanitised input

unarj       stable    2.43-3        alpha arm hppa i386 ia64 m68k powerpc s390 sparc source
unarj       updates   2.43-3woody1  alpha arm hppa i386 ia64 m68k powerpc s390 sparc source

	DSA 652 unarj - several vulnerabilities

vdr-daemon  stable    1.0.0-1        i386
vdr-daemon  updates   1.0.0-1woody2  i386
vdr-kbd     stable    1.0.0-1        i386
vdr-kbd     updates   1.0.0-1woody2  i386
vdr-lirc    stable    1.0.0-1        i386
vdr-lirc    updates   1.0.0-1woody2  i386
vdr-rcu     stable    1.0.0-1        i386
vdr-rcu     updates   1.0.0-1woody2  i386
vdr         stable    1.0.0-1        i386 source
vdr         updates   1.0.0-1woody2  i386 source

	DSA 656 vdr - insecure file access

libwings-dev     stable    0.80.0-4    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libwings-dev     updates   0.80.0-4.2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libwmaker0-dev   stable    0.80.0-4    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libwmaker0-dev   updates   0.80.0-4.2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libwraster2-dev  stable    0.80.0-4    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libwraster2-dev  updates   0.80.0-4.2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libwraster2      stable    0.80.0-4    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libwraster2      updates   0.80.0-4.2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
wmaker           stable    0.80.0-4    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
wmaker           updates   0.80.0-4.2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 190 wmaker - buffer overflow

libxine-dev  stable    0.9.8-2        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libxine-dev  updates   0.9.8-2woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libxine0     stable    0.9.8-2        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libxine0     updates   0.9.8-2woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
xine-lib     stable    0.9.8-2        source
xine-lib     updates   0.9.8-2woody3  source

	DSA 657 xine-lib - buffer overflow

xpdf-common  stable    1.00-3.2    all
xpdf-common  updates   1.00-3.4    all
xpdf-reader  stable    1.00-3.2    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
xpdf-reader  updates   1.00-3.4    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
xpdf-utils   stable    1.00-3.2    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
xpdf-utils   updates   1.00-3.4    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
xpdf         stable    1.00-3.2    all source
xpdf         updates   1.00-3.4    all source

	DSA 648 xpdf - buffer overflow

	DSA 619 xpdf - buffer overflow

xtrlock     stable    2.0-6        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
xtrlock     updates   2.0-6woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 649 xtrlock - buffer overflow

zhcon       stable    1:0.2-4        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
zhcon       updates   1:0.2-4woody3  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 655 zhcon - missing privilege release

zip         stable    2.30-5        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
zip         updates   2.30-5woody2  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	DSA 624 zip - buffer overflow

Requires further Investigation
------------------------------

These packages need further investigation.  One reason the package is
listed here could be that I'm not yet convinced this package should go
into stable, but don't want to reject it entirely at the moment.

Another reason could be that released and updated architectures are
not yet in sync.

acorn-fdisk  stable    3.0.6-4        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
acorn-fdisk  updates   3.0.6-4woody1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	Rebuilt for stable since required for working boot-floppies;
	otherwise identical to 3.0.6-5.

	Probably only required for updated boot-floppies

console-common  stable    0.7.14        all source
console-common  updates   0.7.14woody1  all source
dh-consoledata  stable    0.7.14        all
dh-consoledata  updates   0.7.14woody1  all

	Support the Acorn RiscStation architecture.

	Alastair McKinstry: The console-common change for Acorn
	RiscStation is included in the current boot-floppies since
	2002/08/12; it is in kbdconfig.c 1.68; boot-floppies 3.0.23
	shipped with kbdconfig.c 1.66. As I understand it, this is not
	the current shipping woody, but these machines only boot with
	this updated, modified boot-floppies and console-common.

	Hence, only needed for updated boot-floppies, probably for r3
	then.

chill-2.95              stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
chill-2.95              stable    1:2.95.4-7            mips mipsel sparc
chill-2.95              updates   1:2.95.4-11woody1     mips mipsel
cpp-2.95-doc            stable    1:2.95.4-11woody1     all
cpp-2.95                stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
cpp-2.95                stable    1:2.95.4-7            mips mipsel sparc
cpp-2.95                updates   1:2.95.4-11woody1     mips mipsel
g++-2.95                stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
g++-2.95                stable    1:2.95.4-7            mips mipsel sparc
g++-2.95                updates   1:2.95.4-11woody1     mips mipsel
g77-2.95-doc            stable    1:2.95.4-11woody1     all
g77-2.95                stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
g77-2.95                stable    1:2.95.4-7            mips mipsel sparc
g77-2.95                updates   1:2.95.4-11woody1     mips mipsel
gcc-2.95-doc            stable    1:2.95.4-11woody1     all
gcc-2.95                stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
gcc-2.95                stable    1:2.95.4-7            mips mipsel sparc
gcc-2.95                stable    2.95.4.ds13-11woody1  source
gcc-2.95                updates   1:2.95.4-11woody1     mips mipsel
gobjc-2.95              stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
gobjc-2.95              stable    1:2.95.4-7            mips mipsel sparc
gobjc-2.95              updates   1:2.95.4-11woody1     mips mipsel
gpc-2.95-doc            stable    1:2.95.4-11woody1     all
gpc-2.95                stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
gpc-2.95                stable    1:2.95.4-7            mips mipsel sparc
gpc-2.95                updates   1:2.95.4-11woody1     mips mipsel
libg++2.8.1.3-dbg       stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
libg++2.8.1.3-dbg       stable    1:2.95.4-7            mips mipsel sparc
libg++2.8.1.3-dbg       updates   1:2.95.4-11woody1     mips mipsel
libg++2.8.1.3-dev       stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
libg++2.8.1.3-dev       stable    1:2.95.4-7            mips mipsel sparc
libg++2.8.1.3-dev       updates   1:2.95.4-11woody1     mips mipsel
libg++2.8.1.3-glibc2.2  stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
libg++2.8.1.3-glibc2.2  stable    1:2.95.4-7            mips mipsel sparc
libg++2.8.1.3-glibc2.2  updates   1:2.95.4-11woody1     mips mipsel
libstdc++2.10-dbg       stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
libstdc++2.10-dbg       stable    1:2.95.4-7            mips mipsel sparc
libstdc++2.10-dbg       stable    1:2.96-8              ia64
libstdc++2.10-dbg       updates   1:2.95.4-11woody1     mips mipsel
libstdc++2.10-dev       stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
libstdc++2.10-dev       stable    1:2.95.4-7            mips mipsel sparc
libstdc++2.10-dev       stable    1:2.96-8              ia64
libstdc++2.10-dev       updates   1:2.95.4-11woody1     mips mipsel
libstdc++2.10-glibc2.2  stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
libstdc++2.10-glibc2.2  stable    1:2.95.4-7            mips mipsel sparc
libstdc++2.10-glibc2.2  stable    1:2.96-8              ia64
libstdc++2.10-glibc2.2  updates   1:2.95.4-11woody1     mips mipsel
protoize-2.95           stable    1:2.95.4-11woody1     alpha arm i386 m68k powerpc s390
protoize-2.95           stable    1:2.95.4-7            mips mipsel sparc
protoize-2.95           updates   1:2.95.4-11woody1     mips mipsel

	Bring architectures back in sync

	MISSING sparc

kernel-headers-2.2.20-reiserfs     stable    2.2.20-4        i386
kernel-headers-2.2.20-reiserfs     updates   2.2.20-4woody1  i386
kernel-image-2.2.20-reiserfs-i386  stable    2.2.20-4        source
kernel-image-2.2.20-reiserfs-i386  updates   2.2.20-4woody1  source
kernel-image-2.2.20-reiserfs       stable    2.2.20-4        i386
kernel-image-2.2.20-reiserfs       updates   2.2.20-4woody1  i386

	DSA 453 linux-kernel-2.2.20 - failing function and TLB flush

	pcmcia-modules-2.2.20-reiserfs: Depends: kernel-image-2.2.20-reiserfs (= 2.2.20-4)

	*Bummer*

kernel-headers-2.4.18-1-generic  updates   2.4.18-15    alpha
kernel-headers-2.4.18-1-smp      updates   2.4.18-15    alpha
kernel-headers-2.4.18-1          updates   2.4.18-15    alpha
kernel-image-2.4.18-1-alpha      updates   2.4.18-15    source
kernel-image-2.4.18-1-generic    updates   2.4.18-15    alpha
kernel-image-2.4.18-1-smp        updates   2.4.18-15    alpha

	DSA 479 linux-kernel-2.4.18 - several vulnerabilities

	DSA 438 linux-kernel-2.4.18 - missing function return value check

	DSA 417 linux-kernel-2.4.18 - missing boundary check

	New package + incompatible ABI = *Bummer*

kernel-headers-2.4.18-1-386             updates   2.4.18-13.1  i386
kernel-headers-2.4.18-1-586tsc          updates   2.4.18-13.1  i386
kernel-headers-2.4.18-1-686-smp         updates   2.4.18-13.1  i386
kernel-headers-2.4.18-1-686             updates   2.4.18-13.1  i386
kernel-headers-2.4.18-1-k6              updates   2.4.18-13.1  i386
kernel-headers-2.4.18-1-k7              updates   2.4.18-13.1  i386
kernel-headers-2.4.18-1                 updates   2.4.18-13.1  i386
kernel-image-2.4.18-1-386               updates   2.4.18-13.1  i386
kernel-image-2.4.18-1-586tsc            updates   2.4.18-13.1  i386
kernel-image-2.4.18-1-686-smp           updates   2.4.18-13.1  i386
kernel-image-2.4.18-1-686               updates   2.4.18-13.1  i386
kernel-image-2.4.18-1-i386              updates   2.4.18-13.1  source
kernel-image-2.4.18-1-k6                updates   2.4.18-13.1  i386
kernel-image-2.4.18-1-k7                updates   2.4.18-13.1  i386
kernel-pcmcia-modules-2.4.18-1-386      updates   2.4.18-13.1  i386
kernel-pcmcia-modules-2.4.18-1-586tsc   updates   2.4.18-13.1  i386
kernel-pcmcia-modules-2.4.18-1-686-smp  updates   2.4.18-13.1  i386
kernel-pcmcia-modules-2.4.18-1-686      updates   2.4.18-13.1  i386
kernel-pcmcia-modules-2.4.18-1-k6       updates   2.4.18-13.1  i386
kernel-pcmcia-modules-2.4.18-1-k7       updates   2.4.18-13.1  i386

	DSA 479 linux-kernel-2.4.18 - several vulnerabilities

	DSA 438 linux-kernel-2.4.18 - missing function return value check

	New package + incompatible ABI = *Bummer*

kernel-headers-2.4.18-bf2.4  stable    2.4.18-5        i386
kernel-headers-2.4.18-bf2.4  updates   2.4.18-5woody8  i386
kernel-image-2.4.18-bf2.4    stable    2.4.18-5        i386
kernel-image-2.4.18-bf2.4    updates   2.4.18-5woody8  i386
kernel-image-2.4.18-i386bf   stable    2.4.18-5        source
kernel-image-2.4.18-i386bf   updates   2.4.18-5woody8  source

	DSA 479 linux-kernel-2.4.18 - several vulnerabilities

	DSA 403 - kernel-image-2.4.18-1 - local root exploit

	But: pcmcia-modules-2.4.18-bf2.4

	Depends: kernel-image-2.4.18-bf2.4 (= 2.4.18-5)

	*Bummer*

kernel-headers-2.4.17-ia64        stable    011226.13   ia64
kernel-image-2.4.17-ia64          stable    011226.13   source
kernel-image-2.4.17-itanium-smp   stable    011226.13   ia64
kernel-image-2.4.17-itanium       stable    011226.13   ia64
kernel-image-2.4.17-mckinley-smp  stable    011226.13   ia64
kernel-image-2.4.17-mckinley      stable    011226.13   ia64
kernel-source-2.4.17-ia64         stable    011226.13   all
kernel-headers-2.4.19-ia64        updates   020821.1    ia64
kernel-image-2.4.19-ia64          updates   020821.1    source
kernel-image-2.4.19-itanium-smp   updates   020821.1    ia64
kernel-image-2.4.19-itanium       updates   020821.1    ia64
kernel-image-2.4.19-mckinley-smp  updates   020821.1    ia64
kernel-image-2.4.19-mckinley      updates   020821.1    ia64
kernel-source-2.4.19-ia64         updates   020821.1    all

	* initial release of kernel image packages for ia64 based on 2.4.19

	* turn off broadcom gigE driver, change tg3 from module to built-in

	* lose several patches from previous kernel builds now merged upstream

	* update config files for 2.4.19

	New packages, rationale still:

	The 2.4.17 bits which were used to generate the original woody boot floppies
	have some ugly bugs, are not being updated, and generally are not useful
	any more.  Every problem reported on debian-ia64 starts with a request that
	the user move to at least 2.4.19.

	HP has shipped products using the 2.4.19 and 2.4.20 kernel images currently
	in Debian's mirror network, which means they've been through serious testing
	and meet HP product quality standards.  The same is not true of the 2.4.17
	images, as woody was released before HP shipped our first Itanium 2 products.

	Some newer systems cannot even be installed with 2.4.17 based boot floppies,
	we work around that by making alternate installation media available from HP
	based on fresher kernels.  Even on the systems where 2.4.17 is ok for
	install, I don't recommend anyone run a 2.4.17 kernel on any real system.

	When new boot-floppies are uploaded, they'll use this kernel,
	then the kernel will be updated as well.

	TODO: New boot-floppies, contact Bdale

	TODO: Apply security fixes

	TODO: remove actual kernel source and use a kernel-patch instead

	TODO: Build now boot-floppies

kernel-patch-2.4-grsecurity  stable    1.9.4-1     all source
kernel-patch-2.4-grsecurity  updates   1.9.4-3     all source

	-3:

	* Removed patch bit that sets EXTRAVERSION. (closes: Bug#182183)

	* Fix to work with ptrace fixed 2.4.18 (otherwise the patch fails to
	  apply rendering it useless, hence medium urgency). (closes: Bug#194523)

	-4:

	* Fixed around some security patches in 2.4.18 kernel
	  (otherwise the patch fails to apply rendering it useless,
	  hence medium urgency). (refer to Bug#231858).

	-5:

	* Fixed a stupid cut'n'paste bug in the patch for the 2.4.18
	  kernel, which renders the patch unappliable.

	ptrace/2.4 can't go into stable due to binary-incompatibility.

lha         stable    1.14i-2         alpha arm i386 ia64 m68k powerpc s390 sparc source
lha         stable    1.14i-2.0.1     hppa
lha         updates   1.14i-2.woody4  alpha arm hppa i386 ia64 m68k powerpc s390 sparc source

	DSA 515 lha - several vulnerabilities

	Security update for non-free

	debian/patch.CAN-2004-0234_0235: Add to fix CAN-2004-0234
	(buffer overflows), CAN-2004-0235 (directory traversal).  See:
	http://marc.theaimsgroup.com/?l=full-disclosure&m=108345064008698&w=2
	* debian/control: Change my mail address.

	1.14i-2.woody4: said security update, too many changes

libpam-radius-auth  stable    1.3.14-1    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
libpam-radius-auth  updates   1.3.14-1.1  i386 source

	SECURITY: fix /etc/pam_radius_auth.conf permissions

	Several non-important yada fixes

	MISSING alpha
	MISSING arm
	MISSING hppa
	MISSING ia64
	MISSING m68k
	MISSING mips
	MISSING mipsel
	MISSING powerpc
	MISSING s390
	MISSING sparc

lsb         stable    1.1.0-11       all source
lsb         updates   1.2-5.woody.1  all source

	Support LSB 1.2 in woody.  Includes all changes through 1.2-6 in sid.

	This package is not sufficient to make Debian stable LSB 1.3
	compliant.  The only approved LSB version is 1.3.  According
	to Anthony also required: alien, kernel-(headers|source|image)
	2.4.19 and glibc, pax.  According to Tobias Burnus
	start-stop-daemon needs to be altered as well.  lsb.deb needs
	another backport.

	Matt Taggart wrote: The separate OpenI18N standard was merged
	into the LSB at 1.3 so there are additional requirements that
	are being tested for now.  These are mostly requirements on
	the commands provided by the LSB and _will_ require patches to
	fix.  I do not know if the patches have been accepted upstream
	yet.  There's a rumor that they affect performance.  there may
	need to be additional changes to glibc for the new test
	suites.

	I don't think that we can meet the LSB 1.3 with Debian stable
	without too many changes, hence LSB updates will be rejected.

	Newsflash: Maybe it's still possible to meet the LSB
	testsuite.  To be discussed after 3.0r2.

libparted1.4-dbg   stable    1.4.24-4          alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libparted1.4-dbg   updates   1.4.24-4.woody.1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libparted1.4-dev   stable    1.4.24-4          alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libparted1.4-dev   updates   1.4.24-4.woody.1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libparted1.4-i18n  stable    1.4.24-4          all
libparted1.4-i18n  updates   1.4.24-4.woody.1  all
libparted1.4       stable    1.4.24-4          alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
libparted1.4       updates   1.4.24-4.woody.1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
parted-bf          stable    1.4.24-4          alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
parted-bf          updates   1.4.24-4.woody.1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
parted-doc         stable    1.4.24-4          all
parted-doc         updates   1.4.24-4.woody.1  all
parted             stable    1.4.24-4          alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
parted             updates   1.4.24-4.woody.1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	TODO: Why should this be added to Debian stable?

qpopper-drac  stable    4.0.4-2.woody.1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc
qpopper-drac  updates   4.0.4-2.woody.4  mipsel
qpopper       stable    4.0.4-2.woody.1  alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
qpopper       updates   4.0.4-2.woody.4  mipsel source

	DSA 259 qpopper - mail user privilege escalation

	MISSING alpha
	MISSING arm
	MISSING hppa
	MISSING ia64
	MISSING i386
	MISSING m68k
	MISSING mips
	MISSING powerpc
	MISSING s390
	MISSING sparc

slocate     stable    2.6-1.3.1   alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
slocate     updates   2.6-1.3.3   mipsel source

	DSA 428 slocate - buffer overflow

	MISSING alpha
	MISSING arm
	MISSING hppa
	MISSING ia64
	MISSING i386
	MISSING m68k
	MISSING mips
	MISSING powerpc
	MISSING s390
	MISSING sparc

spellcast   stable    1.0-12      alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
spellcast   updates   1.0-12.1    i386 source

	* Moved to non-free due to licensing which was incorrectly
	  considered free by the previous maintainer. See
	  http://lists.debian.org/debian-legal/2003/debian-legal-200310/msg00136.html

	* Added a rant on why spellcast is not GPL describing the
	  issue in the README.Debian file with more detail than the
	  information available in the copyright file.

	MISSING alpha
	MISSING arm
	MISSING hppa
	MISSING ia64
	MISSING m68k
	MISSING mips
	MISSING mipsel
	MISSING powerpc
	MISSING s390
	MISSING sparc

spellcast-doc  stable    1.0         alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
spellcast-doc  updates   1.0.1       i386 source

	* Moved to non-free due to licensing which was incorrectly
	  considered free by the previous maintainer. See
	  http://lists.debian.org/debian-legal/2003/debian-legal-200310/msg00136.html

	* Added a rant on why spellcast is not GPL describing the
	  issue in the README.Debian file with more detail than the
	  information available in the copyright file.

	MISSING alpha
	MISSING arm
	MISSING hppa
	MISSING ia64
	MISSING m68k
	MISSING mips
	MISSING mipsel
	MISSING powerpc
	MISSING s390
	MISSING sparc

ssed        stable    3.57a-1        alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
ssed        updates   3.57a-2woody   alpha i386 m68k mips powerpc
ssed        updates   3.57a-2woody1  hppa mipsel source
 
delay-install-u ssed_3.57a-2woody_alpha.changes
delay-install-u ssed_3.57a-2woody_i386.changes
delay-install-u ssed_3.57a-2woody_m68k.changes
delay-install-u ssed_3.57a-2woody_mips.changes
delay-install-u ssed_3.57a-2woody_powerpc.changes
delay-install ssed_3.57a-2woody1_hppa.changes
delay-install ssed_3.57a-2woody1_mipsel.changes

	MISSING alpha
	MISSING arm
	MISSING hppa
	MISSING ia64
	MISSING m68k
	MISSING mips
	MISSING powerpc
	MISSING s390
	MISSING sparc

syslog-ng   stable    1.5.15-1    alpha arm hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
syslog-ng   updates   1.5.15-1.2  hppa mipsel

	1.5.15-1.2 would be DSA 175 syslog-ng - buffer overflow

	1.5.15-2 was a bogus fix and removes the DSA, congratulations.

	And since it has had a newer source, there is no source
	anymore.  Congratulations.  I love it when maintainers think
	properly.


yaboot      stable    1.3.6-1         powerpc source
yaboot      updates   1.3.10-0woody1  powerpc source

	* Backport yaboot 1.3.10 to stable (See bug #190439).

	  - This is necessary to boot/install on recent Apple hardware.

	  - Ethan reports that the one line change between 1.3.9 and 1.3.10 is
	    critical.

	Unly required for new boot-floppies

Rejected Packages
-----------------

These packages don't meet the requirements and will be rejected (if
katie supports that, otherwise we'll just carry them with us until the
end of time).

catdoc      stable    0.91.5-1         arm
catdoc      stable    0.91.5-1.woody3  alpha hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source
catdoc      updates   0.91.5-1.woody4  alpha hppa i386 ia64 m68k mips mipsel powerpc s390 sparc source

	Spurious update:

	* Rebuilt to contain a version number higher than 0.91.5-1woody1 and
	  0.91.5-1.99woody.1 which prevents the security update to be accepted.

	* Fix msxlsview to create its temporary file securely using tempfile(1)
	  [src/msxlsview.sh, CAN-2003-0193]

	* Adjusted dependency to wish to tk8.3, because with tk8.2 (0.91.5-1.woody3)
	  builds broke on arm

	Maintainer can't read comment on stable updates that said:

	FTBFS on arm due to broken tk (Bug#278658)

	MISSING arm

Removed Packages
----------------

These packages will be removed from the stable Debian distribution.
This normally only a result of license problems when the license
prohibits their distribution.

Disclaimer
----------

This list intends to help the ftp-masters releasing 3.0r5.  They have the
final power to accept a package or not.  If you want to comment on
this list, please send a mail to Martin Schulze <joey@debian.org>.

Last updated 2005/01/28 11:53 MET

-- 
Testing? What's that? If it compiles, it is good, if it boots up, it is perfect.



Reply to: