Debian 2.x — End of Life

EOL High risk
EOL: Jun 30, 20033 releases in this series1 CVE

Debian 2.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
2.2Aug 15, 2000Jun 30, 2003Jun 30, 20032.2r7EOL
2.1Mar 9, 1999Sep 30, 2000Oct 30, 20002.1r5EOL
2.0Jul 24, 1998Feb 15, 1999Feb 15, 19992.0r5EOL

CVEs affecting Debian 2.x (1)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2002-0062HIGH7.20.48%2.2Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to g…Mar 8, 2002

Debian 2.x is EOL — migrate to Debian 3.x

Debian 3.x is the next major release. Plan your upgrade before Debian 2.x stops receiving security patches.

See Debian 3.x

Frequently asked questions

Is Debian 2 end of life?

Yes. All Debian 2.x releases have reached end of life and no longer receive security patches. There are 1 known CVE affecting Debian 2.x. Migrate to Debian 3.x as soon as possible.

What CVEs affect Debian 2?

There are 1 CVE tracked for Debian 2.x. See the full list above with CVSS and EPSS scores.

What is the latest Debian 2 version?

The latest Debian 2.x patch release is 2.2r7, released on July 13, 2002. Always run the latest patch to benefit from all security fixes.

How to migrate from Debian 2 to Debian 3?

To migrate from Debian 2 to Debian 3: (1) review the official Debian 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Debian 2 in production?

No. Debian 2 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA