ArchSheriff
A script to match NetBSD vulnerability database against Arch Linux packages
VULNERABILITIES (213)
| rxvt | 2.6.4 | rxvt<2.7.10 | remote-code-execution |
| ssh2 | 2.0.13 | ssh2<3.2.5 | weak-authentication |
| metamail | 2.7 | metamail<2.7nb2 | remote-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc3nb2 | remote-code-execution |
| mplayer | 1.0rc2 | gmplayer<1.0rc3nb2 | remote-code-execution |
| mplayer | 1.0rc2 | mencoder<1.0rc3nb2 | remote-code-execution |
| mplayer | 1.0rc2 | mplayer>=1.0rc0<1.0rc4 | remote-code-execution |
| lha | 1.17 | lha<114.9nb2 | remote-code-execution |
| mplayer | 1.0rc2 | gmplayer<1.0rc4nb2 | remote-code-execution |
| libxml | 1.8.17 | libxml<1.8.17nb3 | remote-code-execution |
| imlib | 1.9.15 | imlib<1.9.15nb1 | remote-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc5pl2 | remote-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc5pl2 | remote-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc5pl2 | remote-code-execution |
| a2ps | 4.13c | a2ps<4.13.0.2nb5 | unsafe-shell-escape |
| a2ps | 4.13c | a2ps<4.13.0.2nb7 | local-symlink-race |
| unarj | 2.63a | unarj<2.65nb1 | remote-code-execution |
| unarj | 2.63a | unarj<2.65nb1 | local-file-write |
| xli | 1.17.0 | xli<1.17.0nb2 | local-code-execution |
| xli | 1.17.0 | xli<1.17.0nb2 | buffer-overflow |
| xli | 1.17.0 | xli<1.17.0nb4 | buffer-overflow |
| gdk-pixbuf | 0.22.0 | gdk-pixbuf<0.22.0nb5 | denial-of-service |
| libcdaudio | 0.99.12 | libcdaudio<0.99.12nb1 | remote-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc6nb2 | remote-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc6nb2 | remote-code-execution |
| mplayer | 1.0rc2 | gmplayer<1.0rc6nb3 | remote-code-execution |
| mplayer | 1.0rc2 | gmplayer<1.0rc6nb3 | remote-code-execution |
| qmail | 1.03 | qmail<=1.03 | 64bit-remote-code-execution |
| unzip | 5.52 | unzip<5.52nb2 | local-symlink-race |
| mplayer | 1.0rc2 | mplayer<1.0rc7nb2 | remote-code-execution |
| mplayer | 1.0rc2 | gmplayer<1.0rc7nb1 | remote-code-execution |
| arc | 5.21o | arc<5.21enb2 | insecure-temp-files |
| zebedee | 2.4.1A | zebedee<2.5.3 | denial-of-service |
| xli | 1.17.0 | xli<1.17.0nb5 | arbitrary-code-execution |
| libwww | 5.4.0 | libwww<5.4.0nb4 | denial-of-service |
| gdk-pixbuf | 0.22.0 | gdk-pixbuf<0.22.0nb6 | denial-of-service |
| gdk-pixbuf | 0.22.0 | gdk-pixbuf<0.22.0nb6 | arbitrary-code-execution |
| gdk-pixbuf | 0.22.0 | gdk-pixbuf<0.22.0nb6 | arbitrary-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc7nb6 | buffer-overflow |
| mplayer | 1.0rc2 | gmplayer<1.0rc7nb4 | buffer-overflow |
| mplayer | 1.0rc2 | mencoder<1.0rc7nb2 | buffer-overflow |
| antiword | 0.37 | antiword<0.37nb1 | insecure-temp-files |
| honeyd | 1.5c | honeyd>=1.1<1.5 | remote-information-exposure |
| mplayer | 1.0rc2 | mplayer<1.0rc7nb10 | heap-overflow |
| mplayer | 1.0rc2 | gmplayer<1.0rc7nb6 | heap-overflow |
| mplayer | 1.0rc2 | mencoder<1.0rc7nb4 | heap-overflow |
| libtiff | 3.8.2 | tiff<3.8.2nb2 | arbitrary-code-execution |
| 0verkill | 0.16 | 0verkill-[0-9]* | denial-of-service |
| kadu | 0.6.0.2 | kadu-[0-9]* | denial-of-service |
| php | 5.2.6 | php-curl-[45].[0-9]* | security-bypass |
| libtiff | 3.8.2 | tiff<3.8.2nb3 | multiple-vulnerabilities |
| libwmf | 0.2.8.4 | libwmf<0.2.8.4nb4 | arbitrary-code-execution |
| honeyd | 1.5c | honeyd<1.5b | denial-of-service |
| mplayer | 1.0rc2 | mplayer<1.0rc8 | heap-overflow |
| mplayer | 1.0rc2 | gmplayer<1.0rc8 | heap-overflow |
| mplayer | 1.0rc2 | mencoder<1.0rc8 | heap-overflow |
| gdb | 6.8 | gdb>6 | arbitrary-code-execution |
| lha | 1.17 | lha<114.9nb3 | denial-of-service |
| lha | 1.17 | lha<114.9nb3 | code-execution |
| lha | 1.17 | lha<114.9nb3 | code-execution |
| lha | 1.17 | lha<114.9nb3 | denial-of-service |
| mplayer | 1.0rc2 | mplayer<1.0rc8 | remote-code-execution |
| mplayer | 1.0rc2 | gmplayer<1.0rc8 | remote-code-execution |
| mplayer | 1.0rc2 | mencoder<1.0rc8 | remote-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc9nb3 | buffer-overflow |
| mplayer | 1.0rc2 | gmplayer<1.0rc9nb1 | buffer-overflow |
| mplayer | 1.0rc2 | mencoder<1.0rc9nb2 | buffer-overflow |
| qt3 | 3.3.8 | qt3-libs<3.3.8nb2 | cross-site-scripting |
| mplayer | 1.0rc2 | mplayer<1.0rc9nb7 | remote-user-shell |
| mplayer | 1.0rc2 | gmplayer<1.0rc9nb2 | remote-user-shell |
| qt3 | 3.3.8 | qt3-libs<3.3.8nb3 | remote-user-shell |
| koffice | 1.6.3 | koffice<1.6.3nb1 | arbitrary-code-execution |
| denyhosts | 2.6 | py{23,24}-denyhosts<2.6nb1 | denial-of-service |
| denyhosts | 2.6 | py{23,24}-denyhosts<2.6nb1 | denial-of-service |
| squidguard | 1.2.0 | squidGuard<1.2.1 | acl-bypass |
| qt3 | 3.3.8 | qt3-libs<3.3.8nb5 | remote-user-shell |
| fetchmail | 6.3.8 | fetchmail<6.3.8nb1 | denial-of-service |
| koffice | 1.6.3 | koffice<1.6.3nb4 | arbitrary-code-execution |
| ircservices | 5.0.62 | ircservices<5.0.63 | denial-of-service |
| libsndfile | 1.0.17 | libsndfile<1.0.17nb2 | arbitrary-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc10nb2 | buffer-overflow |
| mplayer | 1.0rc2 | mencoder<1.0rc10nb1 | buffer-overflow |
| mplayer | 1.0rc2 | gmplayer<1.0rc10nb3 | buffer-overflow |
| sdl_image | 1.2.6 | SDL_image<1.2.6nb1 | buffer |
| sdl_image | 1.2.6 | SDL_image<1.2.6nb2 | buffer |
| splitvt | 1.6.5 | splitvt<1.6.6 | privilege-escalation |
| silc-toolkit | 1.0.2 | silc-toolkit<1.1.6 | buffer-overflow |
| synce-dccm | 0.9.1 | synce-dccm<0.9.2 | arbitrary-script-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc10nb2 | remote-system-access |
| mplayer | 1.0rc2 | mplayer<1.0rc10nb2 | remote-system-access |
| mplayer | 1.0rc2 | mencoder<1.0rc10nb1 | remote-system-access |
| mplayer | 1.0rc2 | mencoder<1.0rc10nb1 | remote-system-access |
| mplayer | 1.0rc2 | gmplayer<1.0rc10nb3 | remote-system-access |
| mplayer | 1.0rc2 | gmplayer<1.0rc10nb3 | remote-system-access |
| perl-net-dns | 0.62 | p5-Net-DNS<0.63 | remote-denial-of-service |
| jasper | 1.900.1 | jasper<1.900.1nb2 | denial-of-service |
| nss_ldap | 257 | nss_ldap<259 | data-manipulation |
| silc-toolkit | 1.0.2 | silc-toolkit<1.1.2 | buffer-overflow |
| unzip | 5.52 | unzip<5.52nb4 | arbitrary-code-execution |
| qemu | 0.9.1 | qemu<=0.9.1 | information-disclosure |
| freetype1 | 1.3.1 | freetype<2.3.4 | denial-of-service |
| silc-toolkit | 1.0.2 | silc-toolkit<1.1.7 | buffer-overflow |
| rxvt | 2.6.4 | rxvt<2.7.10nb6 | privilege-escalation |
| wterm | 6.2.9 | wterm<6.2.9nb8 | privilege-escalation |
| mrxvt | 0.5.3 | mrxvt<0.5.3nb3 | privilege-escalation |
| perl-archive-tar | 1.34 | p5-Archive-Tar<1.37 | directory-traversal |
| xpdf | 3.02_pl2 | xpdf<3.02pl2nb1 | remote-system-access |
| konversation | 1.0.1 | konversation<1.0.1nb8 | arbitrary-command-execution |
| id3lib | 3.8.3 | id3lib<3.8.3nb4 | privilege-escalation |
| vorbis-tools | 1.2.0 | vorbis-tools<1.2.0nb1 | arbitrary-code-execution |
| sdl_sound | 1.0.1 | SDL_sound<1.0.2 | arbitrary-code-execution |
| qemu | 0.9.1 | qemu-[0-9]* | security-bypass |
| xmp | 2.5.1 | xmp-[0-9]* | arbitrary-code-execution |
| realplayer | 11.0.0.4028 | RealPlayerGold-[0-9]* | arbitrary-code-execution |
| mplayer | 1.0rc2 | mplayer<1.0rc10nb7 | arbitrary-code-execution |
| mplayer | 1.0rc2 | gmplayer<1.0rc10nb5 | arbitrary-code-execution |
| quake3 | 1.32c | quake3arena-[0-9]* | arbitrary-code-execution |
| sarg | 2.2.5 | sarg-[0-9]* | unspecified |
| libvorbis | 1.2.0 | libvorbis<1.2.0nb1 | arbitrary-code-execution |
| libvorbis | 1.2.0 | libvorbis<1.2.0nb1 | arbitrary-code-execution |
| libvorbis | 1.2.0 | libvorbis<1.2.0nb1 | arbitrary-code-execution |
| uudeview | 0.5.20 | uudeview<0.5.20nb2 | insecure-temporary-files |
| uudeview | 0.5.20 | uulib<0.5.20nb4 | insecure-temporary-files |
| wordnet | 3.0 | WordNet<3.0nb1 | arbitrary-code-execution |
| xemacs | 21.5.28 | xemacs{,-nox11}-[0-9]* | arbitrary-code-execution |
| xemacs | 21.5.28 | xemacs{,-nox11}-[0-9]* | arbitrary-code-execution |
| openssl | 0.9.8i | openssl<0.9.8gnb1 | denial-of-service |
| freetype1 | 1.3.1 | freetype<2.3.6 | arbitrary-code-execution |
| fetchmail | 6.3.8 | fetchmail<6.3.8nb3 | denial-of-service |
| acroread | 8.1.2 | acroread8<8.1.2nb1 | arbitrary-code-execution |
| openldap-clients | 2.3.43 | openldap-client<2.4.9nb1 | denial-of-service |
| vte | 0.17.4 | vte-[0-9]* | utmp-entry-spoofing |
| libzvt | 2.0.1 | libzvt-[0-9]* | utmp-entry-spoofing |
| realplayer | 11.0.0.4028 | RealPlayerGold-[0-9]* | arbitrary-code-execution |
| pan | 0.133 | pan-[0-9]* | denial-of-service |
| python24 | 2.4.5 | python24<2.4.5nb2 | denial-of-service |
| python24 | 2.4.5 | python24<2.4.5nb2 | arbitrary-code-execution |
| tomcat | 5.5.27 | apache-tomcat55-[0-9]* | cross-site-scripting |
| tomcat | 5.5.27 | apache-tomcat55-[0-9]* | cross-site-scripting |
| tomcat | 5.5.27 | jakarta-tomcat5-[0-9]* | directory-traversal |
| libxslt | 1.1.24 | libxslt<1.1.24nb1 | arbitrary-code-execution |
| pdns | 2.9.21 | powerdns<2.9.21nb2 | data-manipulation |
| ipsec-tools | 0.7.1 | ipsec-tools-[0-9]* | denial-of-service |
| postfix | 2.5.3 | postfix<2.5.4 | privilege-escalation |
| postfix | 2.5.3 | postfix<2.5.4 | information-exposure |
| bitlbee | 1.0.4 | bitlbee<1.2.2 | security-bypass |
| libtiff | 3.8.2 | tiff<3.8.2nb4 | arbitrary-code-execution |
| ruby | 1.8.7_p72 | ruby18-base<1.8.7.72nb1 | denial-of-service |
| gpsdrive | 2.10pre4 | gpsdrive-[0-9]* | privilege-escalation |
| libxml2 | 2.6.32 | libxml2<2.7.0 | denial-of-service |
| postfix | 2.5.3 | postfix<2.5.5 | denial-of-service |
| proftpd | 1.3.1 | proftpd<1.3.2rc2 | arbitrary-command-execution |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.17 | arbitrary-code-execution |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.17 | privilege-escalation |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.17 | privilege-escalation |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.17 | memory-corruption |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.17 | cross-site-scripting |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.17 | cross-site-scripting |
| faad2 | 2.6.1 | faad2<2.6.1nb1 | arbitrary-code-execution |
| mplayer | 1.0rc2 | gmplayer<1.0rc10nb6 | remote-user-shell |
| mplayer | 1.0rc2 | mencoder<1.0rc10nb3 | remote-user-shell |
| mplayer | 1.0rc2 | mplayer<1.0rc10nb8 | remote-user-shell |
| xerces-c | 2.8.0 | xerces-c<3.0.0 | denial-of-service |
| libxml2 | 2.6.32 | libxml2<2.7.1nb1 | denial-of-service |
| xen | 3.3.0 | xentools33<3.3.0nb2 | security-bypass |
| xen | 3.3.0 | xentools3-[0-9]* | security-bypass |
| jhead | 2.82 | jhead<2.84 | privilege-escalation |
| tomcat | 5.5.27 | jakarta-tomcat5-[0-9]* | security-bypass |
| enscript | 1.6.4 | enscript-[0-9]* | arbitrary-code-execution |
| gpsd | 2.37 | gpsd<2.37nb1 | remote-information-exposure |
| libspf2 | 1.2.5 | libspf2<1.2.8 | arbitrary-code-execution |
| jhead | 2.82 | jhead<=2.84 | privilege-escalation |
| lynx | 2.8.6 | lynx<2.8.6.4 | privilege-escalation |
| acroread | 8.1.2 | acroread8<8.1.3 | multiple-vulnerabilities |
| gnutls | 2.4.2 | gnutls<2.6.1 | remote-security-bypass |
| moinmoin | 1.7.2 | py{24,25}-moin-[0-9]* | remote-information-exposure |
| moinmoin | 1.7.2 | py{24,25}-moin-[0-9]* | remote-information-exposure |
| clamav | 0.94 | clamav<0.94.1 | remote-system-access |
| nagios | 3.0.5 | nagios-base-[0-9]* | cross-site-scripting |
| fwbuilder | 3.0.1 | fwbuilder{,21}-[0-9]* | privilege-escalation |
| fwbuilder | 3.0.1 | fwbuilder{,21}-[0-9]* | privilege-escalation |
| streamripper | 1.63.5 | streamripper-[0-9]* | arbitrary-code-execution |
| libxml2 | 2.6.32 | libxml2<2.7.2nb2 | arbitrary-code-execution |
| libxml2 | 2.6.32 | libxml2<2.7.2nb2 | denial-of-service |
| imlib2 | 1.4.2 | imlib2<1.4.2nb1 | arbitrary-code-execution |
| opera | 9.62 | opera-[0-9]* | arbitrary-code-execution |
| blender | 2.48a | blender-[0-9]* | arbitrary-code-execution |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.18 | information-disclosure |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | information-disclosure |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | information-disclosure |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | information-disclosure |
| thunderbird | 2.0.0.17 | thunderbird{,-gtk1}<2.0.0.18 | information-disclosure |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.18 | arbitrary-code-execution |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | arbitrary-code-execution |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | arbitrary-code-execution |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | arbitrary-code-execution |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.18 | arbitrary-code-execution |
| thunderbird | 2.0.0.17 | thunderbird{,-gtk1}<2.0.0.18 | arbitrary-code-execution |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | arbitrary-code-execution |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | arbitrary-code-execution |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | arbitrary-code-execution |
| firefox2 | 2.0.0.16 | firefox{,-bin,-gtk1}<2.0.0.18 | security-bypass |
| thunderbird | 2.0.0.17 | thunderbird{,-gtk1}<2.0.0.18 | security-bypass |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | security-bypass |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | security-bypass |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | security-bypass |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | information-disclosure |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | information-disclosure |
| seamonkey | 1.1.12 | seamonkey{,-bin,-gtk1}<1.1.13 | information-disclosure |
| thunderbird | 2.0.0.17 | thunderbird{,-gtk1}<2.0.0.18 | information-disclosure |
| libcdaudio | 0.99.12 | libcdaudio<0.99.12nb2 | arbitrary-code-execution |
| wireshark | 1.0.4 | wireshark<1.0.4nb1 | denial-of-service |
| amaya | 10.0.1 | amaya-[0-9]* | system-access |
WARNINGS (14)
End Of Life (1)
| sqlitemanager | 1.2.0 | sqlitemanager-[0-9]* | eol |