LWN.net Logo

The full 2003 vulnerability and alerts table

The following table is a list of vulnerabilities and alerts for a chosen subset of major distributions in 2003.

Vulnerability Conectiva Debian Fedora Gentoo Mandrake Red Hat SuSE
apache X X X X
apache X X X X X
apache X X X X X
apache X
apache X X
apache X X X X X X X
apcupsd X X X X
at X X X X X X
atari800 X X
atftp X X
autorespond X
balsa X X X
bind X X X X X X X
bind X X X X
bind X
bitchx X X X
bitchx X
bladeenc X
bonsai X
bugzilla X
bugzilla X
bugzilla X
bugzilla X
canna X X X
cdrecord X X X
cfengine X
conquest X
courier X
cups X X X X X X
cups X X X X X X
cups X X X
cvs X X X X X X X
cvs X X X
cvs X
cyrus-imapd X X
cyrus-sasl X X
ddskk X
delegate
dhcp X X X X X X
dhcp3 X X X
dhcpcd X X X X
dvips X X X X X X
ecartis X
eldav X
eog X X
epic X
epic4 X
epic4 X X X
eroaster X X X
eterm X X
ethereal X
ethereal X X X X X X
ethereal X X X
ethereal X X X X
ethereal X X X X X
ethereal X X
evolution X X X X X X
exim X X X X
fdclone X
fetchmail X X X X X
fetchmail X
file X X X X X X X
fileutils X X X
fileutils X X X X
fnord X
freeradius X
freesweep X
fuzz X
gallery X X
gdm X X X
gdm X X
geneweb X
ghostscript X X X
gkrellm X
gkrellm-newsticker X
glibc X X X X X X X X X X
glibc X X
glibc X X X X X X X X X X
glibc X X X X
glibc X
gnocatan X X
gnupg X X X X
gnupg X
gnupg X X X X X X X
gopher X
gps X
gs-common X
gtkhtml X X X X X
gtksee X X
gzip X X X
hanterm X
helix
horde X X
http-fetcher X
hylafax X X X X X
hypermail X X
hztty X
im X X X
imagemagick X
imp X X X
inetd
ipmasq X
iproute X
ircd X
ircii X X
irssi X
kde X X X X X X X X X X X X X X X
kde X X X X X X X X X X
kde X
kde X X X X
kde X X X X X X
kdelibs X X X
kerberos X X X X X X X X X
kernel X X X X
kernel X
kernel X X X X X X X X X X X X X X X
kernel X X X X X X X X X X
kernel X X X X X X X X
kernel X X X X X X X X X
kernel-utils X
kon2 X X X
kopete X X X
krb5 X X X X X X X X
krb5 X X
lcdproc X
leafnode X X
leksbot X
lftp X X X X X X X
libmcrypt X X X X
libnids X X
libpam-smb X X X X X
libpng X X X X X
lprng X X X X
lprold X X X X X
lsh X
lv X X X
lxr X
lynx X X X X
lyskom-server X
mah-jong X
mailman X
mailtools X X X X X
man X X X X
man X
man-db X X X
marbles X
metrics X
mgetty X X X
mhc X
mhonarc X X X
micq X X
mikmod X X
mime-support X X X
mindi X X
minimalist X
mnogosearch X
mod_auth_any X
mod_dav
mod_php X X X
mod_php X
mod_php4 X
monkeyd X
monopd X
mozilla X X
mozilla X X
mpg123 X X X
mpg123 X
mplayer X X X
mutt X X X X X X X X X
mysql X X X X X X
mysql X
mysql X X X X X
mysql X X X X X X
mysqlcc X
nessus X
net-snmp X X
net-snmp X X
nethack X X X X X
netpbm X X X X
netris X
netscape-flash X X
nfs-utils X X X X X X
node X
noffle X
noweb X X
omega-rpg X
openldap2 X X X X X X
openslp X
openssh X X X
openssh X X X X X X X X X X X X X X
openssh X
openssl X X X X X X
openssl X X X X X X X X X
openssl X X X X X X X X X
opera X
orville-write X
osh X
pam-pgsql X
pam_ldap X
pam_xauth X X X
pan X X
perl X X X X X
php X X X
php X
php X X X X X
phpbb X
phpgroupware X X X X
phpsysinfo X
phpwebsite X
pine X X X X
pine X X X X
postfix X X X X X
postgresql X X X X X X X
postgresql X X
postgresql X X X
pptpd X X X
printer-drivers X X
proftpd X
proftpd X X X X
pstack X
python X X X X X X X X
qpopper X X X
qt-dcgui X
radiusd-cistron X X X X
rinetd X
rsync X X X X X X X X
rxvt X X X
samba X X X X X X X X
samba X X X X X X X
sane-backends X X X X X
screen X X
semi X X X
sendmail X X X X X X X
sendmail X X X X X X X X X
sendmail X
sendmail X X X X
sendmail X X X X X X
shadow-utils X X
slocate X X X X
snort X X X
snort X X X X
squirrelmail X X X X X
squirrelmail X
squirrelmail X
stunnel X X X
stunnel X
sup X
susehelp X
syslinux X
tcp/ip
tcpdump X X X X X X X
tcptraceroute X X
teapop X X
thttpd X X X
tomcat X X X X X
tomcat X
tomcat X
traceroute-nanog X
traceroute-nanog/nkitb X X
typespeed X X
ucd-snmp X
unzip X X X X X X X X X
usermin X X X
usermode X X
util-linux X
uw-imapd X
vim X X X
vixie-cron X X X
vmware-workstation X X
vnc X X X X X
vsftpd X
vte X X X
w3m X X X X X
webalizer X X
webfs X
webfs X
webmin X
webmin X
wget X X X X X
wget X X
wmaker X X X X
wordtrans X
wu-ftpd X X X X X
wu-ftpd X X
wuftpd X X X X
wwwoffle X X
xaos X
xbl X X
xchat X
xconq X
xfree86 X X X X
xfree86 X X X X X
xfsdump X X
xfstt X
xftp X
xgalaga X
xinetd X X X X
xpcd X
xpdf X X X X X
xpdf X X X X X X
xtokkaetama X X
ypserv X X X
zblast X
zebra X X
zlib X X X X

(Log in to post comments)

The full 2003 vulnerability and alerts table

Posted Jan 15, 2004 11:18 UTC (Thu) by arcticwolf (guest, #8341) [Link]

Interesting. So, do the empty fields mean "this distribution does not have this particular vulnerability" or "this distribution didn't do anything about this particular vulnerability"?

The full 2003 vulnerability and alerts table

Posted Jan 15, 2004 11:49 UTC (Thu) by Dabuk (guest, #1507) [Link]

The ticks indicate fixes, which is why some have 2 ticks as there have been multiple attempts at a fix. If you click on a tick, you'll go the page containing the alert for that distribution.

The full 2003 vulnerability and alerts table

Posted Jan 15, 2004 15:55 UTC (Thu) by PhracturedBlue (subscriber, #4193) [Link]

Good question. I think the answer is 'Yes'. For instance there are no ticks for Debian for apache. In this case, I believe it is because these vulnerabilities are all apache2, and Debian hasn't released a distro with apache2 yet (so there are no packages to fix...testing and sid don't get SA notices). However, it may be that there are other cases where a distro just didn't fix an issue (or didn't release a security alert)

The full 2003 vulnerability and alerts table

Posted Jan 16, 2004 1:06 UTC (Fri) by bignose (subscriber, #40) [Link]

> Interesting. So, do the empty fields mean "this distribution does not have
> this particular vulnerability" or "this distribution didn't do anything
> about this particular vulnerability"?

Neither; an empty field means "this distribution did not issue an alert relating to this vulnerability".

Without an alert, of course, the LWN vulnerability database can't know *why* there's no alert. In each case, it could be one of the reasons you specify, or something else.

The full 2003 vulnerability and alerts table

Posted Jan 16, 2004 1:13 UTC (Fri) by corbet (editor, #1) [Link]

Adding a "not vulnerable" note to the database has been on my list from the beginning. The hacking is easy; actually verifying that a distribution is not vulnerable is hard, and can only be done with a fair amount of people time. If we ever get to where we could invest the time to properly set a "not vulnerable" flag, it will go in.

The full 2003 vulnerability and alerts table

Posted Jan 19, 2004 8:47 UTC (Mon) by aglet (guest, #1334) [Link]

Do all the distributions contain all the packages listed in the table? I'm wondering whether the long list of ticks against Debian is partially due to the distribution being large....

The full 2003 vulnerability and alerts table

Posted Jan 22, 2004 16:03 UTC (Thu) by drathos (guest, #6454) [Link]

Nope. I can't see any other distribution including susehelp, for example. :)

I also think the reason Fedora was relatively lacking in alerts is because it was not until the fall that it took over the end-user version of Red Hat.

That said, SuSE is quite a large distro as well, but it didn't have near as many alerts as Debian. Also, it seems that Debian tends to have to "fix" problems multiple times a lot (like one of the KDE problems - 10 times!). That is rather disturbing to me..

Also, I'm not sure about the other distros, but SuSE had actually fixed some of the problems well before the security alert was issued. The kernel brk() issue had been fixed in a release in November (and if I remember the changelog correctly, the issue itself had been fixed a month or two before that), yet the issue didn't rear it's ugly head until December.

The full 2003 vulnerability and alerts table

Posted Jan 22, 2004 19:24 UTC (Thu) by razholio (subscriber, #5706) [Link]

>That said, SuSE is quite a large distro as well, but it didn't have near as >many alerts as Debian. Also, it seems that Debian tends to have to "fix" >problems multiple times a lot (like one of the KDE problems - 10 times!). >That is rather disturbing to me..

um, no. Please check the actual alerts. Debian released 10 separate alerts for 10 separate KDE packages all of which resulted from the single alert from KDE. I think you'll find the majority of the cases where debian releases more than one alert for a single upstream alert, result from there being more than one package affected by the upstream alert.

Also note that there have been numerous upstream alerts in the past that did not affect debian specifically because of the way debian packaged that particular app.

Copyright © 2004, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds