1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47
|
# List of packages whose security support is limited or ends before the distribution EOL
# File format: Columns, separated by one or more space characters
# 1. source package name
# 2. non-supported if security support ends completely, limited if it doesn't
# benefit from the regular security support
# 3. last version with support
# Important: If there have been binNMUs, enter the highest version
# number used (only when non-supported)
# 4. Date when support ended or will end, in the form YYYY-mm-dd (only when non-supported)
# 5. Descriptive text or URL with more details (optional)
# In the program's output, this is prefixed with "Details:"
adns limited Stub resolver that should only be used with trusted recursors
binutils limited Only suitable for trusted content; see https://lists.debian.org/msgid-search/87lfqsomtg.fsf@mid.deneb.enyo.de
chromium non-supported 90.0.4430.212-1~deb10u1 2022-01-14 https://lists.debian.org/debian-security-announce/2022/msg00012.html
ckeditor3 non-supported 3.6.6.1+dfsg-1 2022-08-09 https://lists.debian.org/debian-lts/2022/08/msg00001.html
ganglia limited See README.Debian.security, only supported behind an authenticated HTTP zone, #702775
ganglia-web limited See README.Debian.security, only supported behind an authenticated HTTP zone, #702776
gnupg1 limited See #982258 and https://www.debian.org/releases/stretch/amd64/release-notes.en.txt
golang* limited See https://www.debian.org/releases/buster/amd64/release-notes/ch-information.en.html#golang-static-linking
gpac non-supported 0.5.2-426-gc5ad4e4+dfsg5-5 2022-08-03 https://lists.debian.org/debian-lts/2022/05/msg00043.html
kde4libs limited khtml has no security support upstream, only for use on trusted content
khtml limited khtml has no security support upstream, only for use on trusted content, see #1004293
libperlspeak-perl non-supported 2.01-2 2020-04-16 https://bugs.debian.org/954238 (CVE-2020-10674) and https://bugs.debian.org/954297 and 954298
libsoup2.4 limited Only supported as a client, not as a server: see https://gitlab.gnome.org/GNOME/libsoup/-/commit/2a9d8ecc45bb814f6a81b1241e6c0c55d632aa28
libspring-java non-supported 4.3.5-1+deb9u1 2022-08-09 https://lists.debian.org/debian-lts/2022/08/msg00001.html
lucene-solr non-supported 3.6.2+dfsg-20+deb10u2 2024-04-07 Ancient version with limited use for the server component.
mozjs52 limited Not covered by security support, only suitable for trusted content
mozjs60 limited Not covered by security support, only suitable for trusted content
musescore limited Only supported with trusted files, see README.Debian shipped in package and #1070860
nvidia-cuda-toolkit non-supported 9.2.148-7+deb10u1 2024-04-30 Impossible to backport single patches to fix open issues since the package is closed-source. A full version backport is not binary compatible
ocsinventory-server limited Only supported behind an authenticated HTTP zone
pluxml non-supported 5.6-1 2023-05-06 Removed from Debian. No upstream response to CVE.
qtwebengine-opensource-src limited No security support upstream and backports not feasible, only for use on trusted content
qtwebkit limited No security support upstream and backports not feasible, only for use on trusted content
qtwebkit-opensource-src limited support upstream and backports not feasible, only for use on trusted content
salt non-supported 2018.3.4+dfsg1-6+deb10u3 2024-01-29 Required fixes for open issues are way too complex to be backported. Require a change in communication protocol. A full version backport is too intrusive and backwards incompatible
samba limited Only non-AD Domain Controller use cases are supported. See https://lists.debian.org/debian-security-announce/2021/msg00201.html
slurm-llnl non-supported 18.08.5.2-1+deb10u2 2022-08-01 https://salsa.debian.org/lts-team/lts-extra-tasks/-/issues/39
snort non-supported 2.9.20-0+deb10u1 2024-02-11 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1063756
sql-ledger limited Only supported behind an authenticated HTTP zone
tiles limited Only supported for building packages, #1057343
tor non-supported 0.3.5.16-1+deb10u1 2023-12-03 https://lists.debian.org/debian-lts/2023/11/msg00019.html
webkit2gtk limited No longer supported, only suitable for trusted content
xen non-supported 4.11.4+107-gef32c7afa2-1 2021-08-28 https://xenbits.xen.org/docs/4.11-testing/SUPPORT.html#release-support
zoneminder limited See README.Debian.security, only supported behind an authenticated HTTP zone, #922724
|