Debian Package Version system

Hi All,

After performing some vulnerability scans on some our systems one of the outcomes was that some software packages were out of date.
We`re using the package management system of Debian and all packages were updated (apt-get update & apt-get (dist-)upgrade) prior to the scan.
The vulnerability scanner most likely compares the version against that of the source code, which differs.
How can I tell which version in the debian package repository system corresponds to which version of the source code.
That way I can whitelist these software packages in our vulnerability scans.


