Debian 2.x — End of Life

EOL High risk
EOL: Jun 30, 20033 releases in this series1 CVE

Debian 2.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
2.2Aug 15, 2000Jun 30, 20032.2r7EOL
2.1Mar 9, 1999Sep 30, 20002.1r5EOL
2.0Jul 24, 1998Feb 15, 19992.0r5EOL

CVEs affecting Debian 2.x (1)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2002-0062HIGH7.20.48%2.2Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to g…Mar 8, 2002

Debian 2.x is EOL — migrate to Debian 3.x

Debian 3.x is the next major release. Plan your upgrade before Debian 2.x stops receiving security patches.

See Debian 3.x

Frequently asked questions

Is Debian 2 end of life?

Yes. All Debian 2.x releases have reached end of life and no longer receive security patches. There are 1 known CVE affecting Debian 2.x. Migrate to Debian 3.x as soon as possible.

What CVEs affect Debian 2?

There are 1 CVE tracked for Debian 2.x. See the full list above with CVSS and EPSS scores.

What is the latest Debian 2 version?

The latest Debian 2.x patch release is 2.2r7, released on July 13, 2002. Always run the latest patch to benefit from all security fixes.

How to migrate from Debian 2 to Debian 3?

To migrate from Debian 2 to Debian 3: (1) review the official Debian 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Debian 2 in production?

No. Debian 2 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA