This page will hopefully soon consist of many code review reports with
proper description of project/version/architecture/possible flaws and
security relevant patches.
As a start, I will add some packages which are common across a lot of Linux distributions
and have been identified as a potential risk since they either run privileged or
with network input.
Feel free to add other OS's or move to another, separate, page. The intention is NOT to enumerate
all possibly problematic packages such as editor-foo-bar.tgz but the core packages that
are needed to setup minimal working desktop or server system.
For large packages, only per-subsystem status will likely make sense.
glibc
-
Last review: unknown
fts(3) subsystem
reviewed and patched in 2001, now might be a good time to at least double-check that the old issues were not re-introduced since then, because fts(3) is starting to be used by find(1) in GNU findutils
Status: unknown
DBUS
-
Last review: unknown
Status: unknown
ConsoleKit
-
Last review: unknown
Status: unknown
DeviceKit
-
Last review: unknown
Status: unknown
openssl
-
Last review: unknown
Status: unknown
udev
-
Last review:
checked message validation in
04-2009
Status: fixed
coreutils
-
Last review: unknown
Status: unknown
pwdutils
-
Last review: unknown
Status: unknown
PAM
-
Last review: unknown
Status: unknown
Linux Kernel
-
Last review: on going
-
Status: unknown