#907373 debsecan: regards -dbgsym packages as obsolete

#907373#5
Date:
2018-08-27 04:37:23 UTC
From:
To:
In the daily report, debsecan seems to regard -dbgsym packages as
obsolete. These packages are not obsolete, they are just from a suite and repo that is different from the rest of the installed packages.

For example, before installing pngcrush-dbgsym:

CVE-2015-7700 Double-free vulnerability in the sPLT chunk structure...
  <https://security-tracker.debian.org/tracker/CVE-2015-7700>
  - pngcrush (remotely exploitable, high urgency)

After installing pngcrush-dbgsym:

CVE-2015-7700 Double-free vulnerability in the sPLT chunk structure...
  <https://security-tracker.debian.org/tracker/CVE-2015-7700>
  - pngcrush (remotely exploitable, high urgency)
  - pngcrush-dbgsym (remotely exploitable, high urgency, obsolete)

$ apt policy pngcrush-dbgsym
pngcrush-dbgsym:
  Installed: 1.7.85-1+b2
  Candidate: 1.7.85-1+b2
  Version table:
 *** 1.7.85-1+b2 900
        900 https://deb.debian.org/debian-debug testing-debug/main amd64 Packages
        800 https://deb.debian.org/debian-debug unstable-debug/main amd64 Packages
        100 /var/lib/dpkg/status
$ apt policy pngcrush
pngcrush:
  Installed: 1.7.85-1+b2
  Candidate: 1.7.85-1+b2
  Version table:
 *** 1.7.85-1+b2 900
        900 https://deb.debian.org/debian testing/main amd64 Packages
        800 https://deb.debian.org/debian unstable/main amd64 Packages
        100 /var/lib/dpkg/status

#907373#10
Date:
2021-09-22 04:22:10 UTC
From:
To:
Hello,

Good morning,

We have gone through your samples from a partner and Here is our  Order
List. Please do bear in mind that we are very much in  need of this
order, quote your competitive prices.

Kindly send the Order confirmation.

Your early reply will be much appreciated.

Best Regards,

Maryanah Erwin.

PT FINDORA INTERNUSA

Jln Pahlawan 66 Kec. Arjawinangun

45162 CIREBON West-Java INDONESIA

tel : +62 231 357334

fax: +62 231 357260

email: marketing@findora.com