Советы по безопасности за 2005 год

[27.12.2005] DSA-928 dhis-tools-dns - insecure temporary file
[27.12.2005] DSA-927 tkdiff - insecure temporary file
[23.12.2005] DSA-926 ketm - buffer overflow
[22.12.2005] DSA-925 phpbb2 - several vulnerabilities
[21.12.2005] DSA-924 nbd - buffer overflow
[19.12.2005] DSA-923 dropbear - buffer overflow
[14.12.2005] DSA-922 kernel-source-2.6.8 - several vulnerabilities
[14.12.2005] DSA-921 kernel-source-2.4.27 - several vulnerabilities
[13.12.2005] DSA-920 ethereal - buffer overflow
[12.12.2005] DSA-919 curl - buffer overflow
[09.12.2005] DSA-918 osh - programming error
[08.12.2005] DSA-917 courier - programming error
[07.12.2005] DSA-916 inkscape - buffer overflow
[02.12.2005] DSA-915 helix-player - buffer overflow
[01.12.2005] DSA-914 horde2 - отсутствие очистки ввода
[01.12.2005] DSA-913 gdk-pixbuf - several vulnerabilities
[30.11.2005] DSA-912 centericq - denial of service
[29.11.2005] DSA-911 gtk+2.0 - several vulnerabilities
[24.11.2005] DSA-910 zope.2.7 - design error
[23.11.2005] DSA-909 horde3 - missing input sanitising
[23.11.2005] DSA-908 sylpheed-claws - buffer overflows
[23.11.2005] DSA-907 ipmenu - insecure temporary file
[22.11.2005] DSA-906 sylpheed - buffer overflows
[22.11.2005] DSA-905 mantis - several vulnerabilities
[21.11.2005] DSA-904 netpbm-free - buffer overflows
[21.11.2005] DSA-903 unzip - race condition
[21.11.2005] DSA-902 xmail - buffer overflow
[19.11.2005] DSA-901 gnump3d - programming error
[18.11.2005] DSA-900 fetchmail - programming error
[17.11.2005] DSA-899 egroupware - programming errors
[17.11.2005] DSA-898 phpgroupware - programming errors
[15.11.2005] DSA-897 phpsysinfo - programming errors
[15.11.2005] DSA-896 linux-ftpd-ssl - buffer overflow
[14.11.2005] DSA-895 uim - programming error
[14.11.2005] DSA-894 abiword - buffer overflows
[14.11.2005] DSA-893 acidlab - missing input sanitising
[10.11.2005] DSA-892 awstats - missing input sanitising
[09.11.2005] DSA-891 gpsdrive - форматная строка
[09.11.2005] DSA-890 libungif4 - several vulnerabilities
[08.11.2005] DSA-889 enigmail - programming error
[07.11.2005] DSA-888 openssl - cryptographic weakness
[07.11.2005] DSA-887 clamav - several vulnerabilities
[07.11.2005] DSA-886 chmlib - several vulnerabilities
[07.11.2005] DSA-885 openvpn - several vulnerabilities
[07.11.2005] DSA-884 horde3 - design error
[04.11.2005] DSA-883 thttpd - insecure temporary file
[04.11.2005] DSA-882 openssl095 - cryptographic weakness
[04.11.2005] DSA-881 openssl096 - cryptographic weakness
[02.11.2005] DSA-880 phpmyadmin - several vulnerabilities
[02.11.2005] DSA-879 gallery - ошибка программирования
[28.10.2005] DSA-878 netpbm-free - buffer overflow
[28.10.2005] DSA-877 gnump3d - cross-site scripting, directory traversal
[27.10.2005] DSA-876 lynx-ssl - buffer overflow
[27.10.2005] DSA-875 openssl094 - cryptographic weakness
[27.10.2005] DSA-874 lynx - buffer overflow
[26.10.2005] DSA-873 net-snmp - programming error
[26.10.2005] DSA-872 koffice - переполнение буфера
[25.10.2005] DSA-871 libgda2 - format string
[25.10.2005] DSA-870 sudo - missing input sanitising
[21.10.2005] DSA-869 eric - отсутствие очистки ввода
[20.10.2005] DSA-868 mozilla-thunderbird - several vulnerabilities
[20.10.2005] DSA-867 module-assistant - insecure temporary file
[20.10.2005] DSA-866 mozilla - several vulnerabilities
[13.10.2005] DSA-865 hylafax - insecure temporary files
[13.10.2005] DSA-864 ruby1.8 - programming error
[12.10.2005] DSA-863 xine-lib - format string vulnerability
[11.10.2005] DSA-862 ruby1.6 - programming error
[11.10.2005] DSA-861 uw-imap - buffer overflow
[11.10.2005] DSA-860 ruby - programming error
[10.10.2005] DSA-859 xli - buffer overflows
[10.10.2005] DSA-858 xloadimage - buffer overflows
[10.10.2005] DSA-857 graphviz - insecure temporary file
[10.10.2005] DSA-856 py2play - design error
[10.10.2005] DSA-855 weex - format string vulnerability
[09.10.2005] DSA-854 tcpdump - infinite loop
[09.10.2005] DSA-853 ethereal - several vulnerabilities
[09.10.2005] DSA-852 up-imapproxy - format string vulnerabilities
[09.10.2005] DSA-851 openvpn - programming errors
[09.10.2005] DSA-850 tcpdump - infinite loop
[08.10.2005] DSA-849 shorewall - programming error
[08.10.2005] DSA-848 masqmail - several vulnerabilities
[08.10.2005] DSA-847 dia - missing input sanitising
[07.10.2005] DSA-846 cpio - several vulnerabilities
[06.10.2005] DSA-845 mason - programming error
[05.10.2005] DSA-844 mod-auth-shadow - programming error
[05.10.2005] DSA-843 arc - insecure temporary file
[04.10.2005] DSA-842 egroupware - missing input sanitising
[04.10.2005] DSA-841 mailutils - format string vulnerability
[04.10.2005] DSA-840 drupal - missing input sanitising
[04.10.2005] DSA-839 apachetop - insecure temporary file
[02.10.2005] DSA-838 mozilla-firefox - multiple vulnerabilities
[02.10.2005] DSA-837 mozilla-firefox - buffer overflow
[01.10.2005] DSA-836 cfengine2 - insecure temporary files
[01.10.2005] DSA-835 cfengine - insecure temporary files
[01.10.2005] DSA-834 prozilla - переполнение буфера
[01.10.2005] DSA-833 mysql-dfsg-4.1 - buffer overflow
[30.09.2005] DSA-832 gopher - buffer overflows
[30.09.2005] DSA-831 mysql-dfsg - buffer overflow
[30.09.2005] DSA-830 ntlmaps - wrong permissions
[30.09.2005] DSA-829 mysql - buffer overflow
[30.09.2005] DSA-828 squid - authentication handling
[29.09.2005] DSA-827 backupninja - insecure temporary file
[29.09.2005] DSA-826 helix-player - multiple vulnerabilities
[29.09.2005] DSA-825 loop-aes-utils - privilege escalation
[29.09.2005] DSA-824 clamav - infinite loop, buffer overflow
[29.09.2005] DSA-823 util-linux - privilege escalation
[29.09.2005] DSA-822 gtkdiskfree - insecure temporary file creation
[28.09.2005] DSA-821 python2.3 - integer overflow
[24.09.2005] DSA-820 courier - missing input sanitising
[23.09.2005] DSA-819 python2.1 - integer overflow
[22.09.2005] DSA-818 kdeedu - insecure temporary files
[22.09.2005] DSA-817 python2.2 - integer overflow
[19.09.2005] DSA-816 xfree86 - integer overflow
[16.09.2005] DSA-815 kdebase - ошибка программирования
[15.09.2005] DSA-814 lm-sensors - insecure temporary file
[15.09.2005] DSA-813 centericq - several vulnerabilities
[15.09.2005] DSA-812 turqstat - buffer overflow
[14.09.2005] DSA-811 common-lisp-controller - design error
[13.09.2005] DSA-810 mozilla - several vulnerabilities
[13.09.2005] DSA-809 squid - several vulnerabilities
[12.09.2005] DSA-808 tdiary - design error
[12.09.2005] DSA-807 libapache-mod-ssl - acl restriction bypass
[09.09.2005] DSA-806 gcvs - insecure temporary files
[08.09.2005] DSA-805 apache2 - several vulnerabilities
[08.09.2005] DSA-804 kdelibs - insecure permissions
[08.09.2005] DSA-803 apache - programming error
[07.09.2005] DSA-802 cvs - insecure temporary files
[05.09.2005] DSA-801 ntp - programming error
[02.09.2005] DSA-800 pcre3 - integer overflow
[02.09.2005] DSA-799 webcalendar - remote code execution
[02.09.2005] DSA-798 phpgroupware - several vulnerabilities
[01.09.2005] DSA-797 zsync - denial of service
[01.09.2005] DSA-796 affix - remote command execution
[01.09.2005] DSA-795 proftpd - potential code execution
[01.09.2005] DSA-794 polygen - programming error
[01.09.2005] DSA-793 courier - missing input sanitising
[31.08.2005] DSA-792 pstotext - missing input sanitising
[30.08.2005] DSA-791 maildrop - missing privilege release
[30.08.2005] DSA-790 phpldapadmin - programming error
[29.08.2005] DSA-789 php4 - several vulnerabilities
[29.08.2005] DSA-788 kismet - several vulnerabilities
[26.08.2005] DSA-787 backup-manager - insecure permissions and tempfile
[26.08.2005] DSA-786 simpleproxy - format string vulnerability
[25.08.2005] DSA-785 libpam-ldap - authentication bypass
[25.08.2005] DSA-784 courier - programming error
[24.08.2005] DSA-783 mysql-dfsg-4.1 - insecure temporary file
[23.08.2005] DSA-782 bluez-utils - missing input sanitising
[23.08.2005] DSA-781 mozilla-thunderbird - several vulnerabilities
[22.08.2005] DSA-780 kdegraphics - wrong input sanitising
[20.08.2005] DSA-779 mozilla-firefox - several vulnerabilities
[19.08.2005] DSA-778 mantis - missing input sanitising
[17.08.2005] DSA-777 mozilla - frame injection spoofing
[16.08.2005] DSA-776 clamav - integer overflows, infinite loop
[15.08.2005] DSA-775 mozilla-firefox - frame injection spoofing
[12.08.2005] DSA-774 fetchmail - buffer overflow
[11.08.2005] DSA-773 amd64 - несколько уязвимостей
[03.08.2005] DSA-772 apt-cacher - missing input sanitising
[01.08.2005] DSA-771 pdns - several vulnerabilities
[29.07.2005] DSA-770 gopher - insecure tmpfile creating
[29.07.2005] DSA-769 gaim - memory alignment bug
[27.07.2005] DSA-768 phpbb2 - missing input validation
[27.07.2005] DSA-767 ekg - integer overflows
[26.07.2005] DSA-766 webcalendar - authorisation failure
[22.07.2005] DSA-765 heimdal - buffer overflow
[21.07.2005] DSA-764 cacti - several vulnerabilities
[20.07.2005] DSA-763 zlib - remote DoS
[19.07.2005] DSA-762 affix - several vulnerabilities
[19.07.2005] DSA-761 heartbeat - insecure temporary files
[18.07.2005] DSA-760 ekg - several vulnerabilities
[18.07.2005] DSA-759 phppgadmin - missing input sanitising
[18.07.2005] DSA-758 heimdal - buffer overflow
[17.07.2005] DSA-757 krb5 - buffer overflow, double-free memory
[13.07.2005] DSA-756 squirrelmail - several vulnerabilities
[13.07.2005] DSA-755 tiff - buffer overflow
[13.07.2005] DSA-754 centericq - insecure temporary file
[12.07.2005] DSA-753 gedit - format string
[11.07.2005] DSA-752 gzip - several vulnerabilities
[11.07.2005] DSA-751 squid - IP spoofing
[11.07.2005] DSA-750 dhcpcd - out-of-bound memory access
[10.07.2005] DSA-749 ettercap - ошибка форматной строки
[10.07.2005] DSA-748 ruby1.8 - плохое значение по умолчанию
[10.07.2005] DSA-747 egroupware - input validation error
[13.07.2005] DSA-746 phpgroupware - input validation error
[10.07.2005] DSA-745 drupal - input validation errors
[08.07.2005] DSA-744 fuse - programming error
[08.07.2005] DSA-743 ht - buffer overflows, integer overflows
[07.07.2005] DSA-742 cvs - buffer overflow
[07.07.2005] DSA-741 bzip2 - infinite loop
[06.07.2005] DSA-740 zlib - удалённый отказ в обслуживании
[06.07.2005] DSA-739 trac - missing input sanitising
[05.07.2005] DSA-738 razor - удалённый отказ в обслуживании
[05.07.2005] DSA-737 clamav - remote denial of service
[01.07.2005] DSA-736 spamassassin - remote denial of service
[01.07.2005] DSA-735 sudo - pathname validation race
[05.07.2005] DSA-734 gaim - denial of service
[30.06.2005] DSA-733 crip - небезопасные временные файлы
[03.06.2005] DSA-732 mailutils - several vulnerabilities
[02.06.2005] DSA-731 krb4 - buffer overflows
[27.05.2005] DSA-730 bzip2 - race condition
[26.05.2005] DSA-729 php4 - missing input sanitising
[26.05.2005] DSA-728 qpopper - missing privilege release
[20.05.2005] DSA-727 libconvert-uulib-perl - переполнение буфера
[20.05.2005] DSA-726 oops - уязвимость форматной строки
[19.05.2005] DSA-725 ppxp - missing privilege release
[18.05.2005] DSA-724 phpsysinfo - ошибка проектирования
[09.05.2005] DSA-723 xfree86 - buffer overflow
[09.05.2005] DSA-722 smail - переполнение буфера
[06.05.2005] DSA-721 squid - design flaw
[03.05.2005] DSA-720 smartlist - неправильная обработка ввода
[28.04.2005] DSA-719 prozilla - проблемы форматной строки
[28.04.2005] DSA-718 ethereal - buffer overflow
[27.04.2005] DSA-717 lsh-utils - buffer overflow, typo
[27.04.2005] DSA-716 gaim - denial of service
[27.04.2005] DSA-715 cvs - several vulnerabilities
[26.04.2005] DSA-714 kdelibs - several vulnerabilities
[21.04.2005] DSA-713 junkbuster - several vulnerabilities
[19.04.2005] DSA-712 geneweb - insecure file operations
[19.04.2005] DSA-711 info2www - missing input sanitising
[18.04.2005] DSA-710 gtkhtml - разыменование null-указателя
[15.04.2005] DSA-709 libexif - переполнение буфера
[15.04.2005] DSA-708 php3 - missing input sanitising
[13.04.2005] DSA-707 mysql - several vulnerabilities
[13.04.2005] DSA-706 axel - buffer overflow
[04.04.2005] DSA-705 wu-ftpd - missing input sanitising
[04.04.2005] DSA-704 remstats - tempfile, missing input sanitising
[01.04.2005] DSA-703 krb5 - buffer overflows
[01.04.2005] DSA-702 imagemagick - several vulnerabilities
[21.04.2005] DSA-701 samba - integer overflows
[30.03.2005] DSA-700 mailreader - missing input sanitising
[29.03.2005] DSA-699 netkit-telnet-ssl - переполнение буфера
[29.03.2005] DSA-698 mc - переполнение буфера
[29.03.2005] DSA-697 netkit-telnet - переполнение буфера
[22.03.2005] DSA-696 perl - design flaw
[21.03.2005] DSA-695 xli - buffer overflow, input sanitising, integer overflow
[21.03.2005] DSA-694 xloadimage - missing input sanitising, integer overflow
[14.03.2005] DSA-693 luxman - переполнение буфера
[08.03.2005] DSA-692 kdenetwork - design flaw
[07.03.2005] DSA-691 abuse - several vulnerabilities
[25.02.2005] DSA-690 bsmtpd - отсутствие очистки ввода
[23.02.2005] DSA-689 libapache-mod-python - missing input sanitizing
[23.02.2005] DSA-688 squid - отсутствие очистки ввода
[18.02.2005] DSA-687 bidwatcher - format string
[17.02.2005] DSA-686 gftp - missing input sanitising
[17.02.2005] DSA-685 emacs21 - форматная строка
[16.02.2005] DSA-684 typespeed - форматная строка
[15.02.2005] DSA-683 postgresql - переполнение буфера
[15.02.2005] DSA-682 awstats - missing input sanitizing
[14.02.2005] DSA-681 synaesthesia - privilege escalation
[14.02.2005] DSA-680 htdig - неочищеный ввод
[14.02.2005] DSA-679 toolchain-source - insecure temporary files
[11.02.2005] DSA-678 netkit-rwho - missing input validation
[11.02.2005] DSA-677 sympa - переполнение буфера
[11.02.2005] DSA-676 xpcd - buffer overflow
[10.02.2005] DSA-675 hztty - повышение привилегий
[21.02.2005] DSA-674 mailman - cross-site scripting, directory traversal
[10.02.2005] DSA-673 evolution - переполнение целых чисел
[09.02.2005] DSA-672 xview - buffer overflows
[08.02.2005] DSA-671 xemacs21 - форматная строка
[08.02.2005] DSA-670 emacs20 - форматная строка
[07.02.2005] DSA-669 php3 - several vulnerabilities
[04.02.2005] DSA-668 postgresql - повышение привилегий
[04.02.2005] DSA-667 squid - several vulnerabilities
[04.02.2005] DSA-666 python2.2 - design flaw
[04.02.2005] DSA-665 ncpfs - missing privilege release
[02.02.2005] DSA-664 cpio - неправильные права доступа к файлу
[01.02.2005] DSA-663 prozilla - buffer overflows
[14.03.2005] DSA-662 squirrelmail - several vulnerabilities
[20.04.2005] DSA-661 f2c - insecure temporary files
[26.01.2005] DSA-660 kdebase - missing return value check
[26.01.2005] DSA-659 libpam-radius-auth - information leak, integer underflow
[25.01.2005] DSA-658 libdbi-perl - insecure temporary file
[25.01.2005] DSA-657 xine-lib - buffer overflow
[25.01.2005] DSA-656 vdr - небезопасный доступ к файлам
[25.01.2005] DSA-655 zhcon - отсутствие сброса прав доступа
[21.01.2005] DSA-654 enscript - several vulnerabilities
[21.01.2005] DSA-653 ethereal - buffer overflow
[21.01.2005] DSA-652 unarj - several vulnerabilities
[20.01.2005] DSA-651 squid - buffer overflow, integer overflow
[20.01.2005] DSA-650 sword - отсутствие очистки ввода
[20.01.2005] DSA-649 xtrlock - переполнение буфера
[19.01.2005] DSA-648 xpdf - переполнение буфера
[19.01.2005] DSA-647 mysql - insecure temporary files
[19.01.2005] DSA-646 imagemagick - buffer overflow
[19.01.2005] DSA-645 cupsys - buffer overflow
[18.01.2005] DSA-644 chbg - переполнение буфера
[18.01.2005] DSA-643 queue - переполнение буфера
[17.01.2005] DSA-642 gallery - several vulnerabilities
[17.01.2005] DSA-641 playmidi - переполнение буфера
[17.01.2005] DSA-640 gatos - переполнение буфера
[14.01.2005] DSA-639 mc - several vulnerabilities
[13.01.2005] DSA-638 gopher - several vulnerabilities
[13.01.2005] DSA-637 exim-tls - переполнение буфера
[12.01.2005] DSA-636 glibc - insecure temporary files
[12.01.2005] DSA-635 exim - переполнение буфера
[11.01.2005] DSA-634 hylafax - weak hostname and username validation
[11.01.2005] DSA-633 bmv - небезопасные временные файлы
[10.01.2005] DSA-632 linpopup - переполнение буфера
[10.01.2005] DSA-631 kdelibs - неочищенный ввод
[10.01.2005] DSA-630 lintian - insecure temporary directory
[07.01.2005] DSA-629 krb5 - переполнение буфера
[06.01.2005] DSA-628 imlib2 - integer overflows
[06.01.2005] DSA-627 namazu2 - неочищенный ввод
[06.01.2005] DSA-626 tiff - неочищенный ввод
[05.01.2005] DSA-625 pcal - переполнения буфера
[05.01.2005] DSA-624 zip - buffer overflow
[04.01.2005] DSA-623 nasm - переполнение буфера
[03.01.2005] DSA-622 htmlheadline - небезопасные временные файлы

Вы можете получать последние анонсы о безопасности в Debian, подписавшись на список рассылки debian-security-announce. Архив списка рассылки доступен здесь.