<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="dsa-rdf.css" type="text/css"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="fr">
<channel rdf:about="http://www.debian.org/security/dsa.rdf">
  <title>Sécurité Debian</title>
  <link>http://security.debian.org/</link>
  <description>
Bulletins d'alerte Debian
  </description>
  <dc:date>2010-03-09T23:33:24+00:00</dc:date>
  <items>
    <rdf:Seq>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2009"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2008"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2007"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2006"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2004"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2005"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2003"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2002"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2001"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2000"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1999"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1998"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1997"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1996"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1995"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1994"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1993"/>
    </rdf:Seq>
  </items>
</channel>
<item rdf:about="http://www.debian.org/security/2010/dsa-2009">
  <title>DSA-2009 tdiary - insufficient input sanitising</title>
  <link>http://www.debian.org/security/2010/dsa-2009</link>
  <description>
&lt;p&gt;It was discovered that tdiary, a communication-friendly weblog system,
is prone to a cross-site scripting vulnerability due to insufficient
input sanitising in the TrackBack transmission plugin.&lt;/p&gt;
  </description>
  <dc:date>2010-03-09</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2008">
  <title>DSA-2008 typo3-src - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2008</link>
  <description>
&lt;p&gt;Several remote vulnerabilities have been discovered in the TYPO3 web
content management framework: Cross-site scripting vulnerabilities have
been discovered in both the frontend and the backend. Also, user data
could be leaked. More details can be found in the
&lt;a href="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-004/"&gt;Typo3
security advisory&lt;/a&gt;.&lt;/p&gt;
  </description>
  <dc:date>2010-03-08</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2007">
  <title>DSA-2007 cups - format string vulnerability</title>
  <link>http://www.debian.org/security/2010/dsa-2007</link>
  <description>
&lt;p&gt;Ronald Volgers discovered that the lppasswd component of the cups suite,
the Common UNIX Printing System, is vulnerable to format string attacks
due to insecure use of the LOCALEDIR environment variable. An attacker
can abuse this behaviour to execute arbitrary code via crafted localization
files and triggering calls to _cupsLangprintf(). This works as the lppasswd
binary happens to be installed with setuid 0 permissions.&lt;/p&gt;
  </description>
  <dc:date>2010-03-03</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2006">
  <title>DSA-2006 sudo - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2006</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in sudo, a program
designed to allow a sysadmin to give limited root privileges to users.
The Common Vulnerabilities and Exposures project identifies the
following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-03-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2004">
  <title>DSA-2004 samba - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2004</link>
  <description>
&lt;p&gt;Two local vulnerabilities have been discovered in samba, a SMB/CIFS file,
print, and login server for Unix. The Common Vulnerabilities and
Exposures project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-28</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2005">
  <title>DSA-2005 linux-2.6.24 - privilege escalation/denial of service/sensitive memory leak</title>
  <link>http://www.debian.org/security/2010/dsa-2005</link>
  <description>
&lt;p&gt;NOTE: This kernel update marks the final planned kernel security
update for the 2.6.24 kernel in the Debian release 'etch'. Although
security support for 'etch' officially ended on Feburary 15th, 2010,
this update was already in preparation before that date.&lt;/p&gt;
  </description>
  <dc:date>2010-02-27</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2003">
  <title>DSA-2003 linux-2.6 - privilege escalation/denial of service</title>
  <link>http://www.debian.org/security/2010/dsa-2003</link>
  <description>
&lt;p&gt;NOTE: This kernel update marks the final planned kernel security update for
the 2.6.18 kernel in the Debian release 'etch'. Although security support for
'etch' officially ended on Feburary 15th, 2010, this update was already in
preparation before that date. A final update that includes fixes for these
issues in the 2.6.24 kernel is also in preparation and will be released
shortly.&lt;/p&gt;
  </description>
  <dc:date>2010-02-22</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2002">
  <title>DSA-2002 polipo - denial of service</title>
  <link>http://www.debian.org/security/2010/dsa-2002</link>
  <description>
&lt;p&gt;Several denial of service vulnerabilities have been discovered in polipo, a
small, caching web proxy. The Common Vulnerabilities and Exposures project
identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-19</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2001">
  <title>DSA-2001 php5 - multiple vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2001</link>
  <description>
&lt;p&gt;Several remote vulnerabilities have been discovered in PHP 5, an
hypertext preprocessor. The Common Vulnerabilities and Exposures
project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-19</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2000">
  <title>DSA-2000 ffmpeg-debian - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2000</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in ffmpeg, a multimedia
player, server and encoder, which also provides a range of multimedia
libraries used in applications like MPlayer:&lt;/p&gt;
  </description>
  <dc:date>2010-02-18</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1999">
  <title>DSA-1999 xulrunner - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-1999</link>
  <description>
&lt;p&gt;Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications, such as the Iceweasel web
browser. The Common Vulnerabilities and Exposures project identifies
the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-18</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1998">
  <title>DSA-1998 kdelibs - buffer overflow</title>
  <link>http://www.debian.org/security/2010/dsa-1998</link>
  <description>
&lt;p&gt;Maksymilian Arciemowicz discovered a buffer overflow in the internal
string routines of the KDE core libraries, which could lead to the
execution of arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2010-02-17</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1997">
  <title>DSA-1997 mysql-dfsg-5.0 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-1997</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in the MySQL
database server.
The Common Vulnerabilities and Exposures project identifies the
following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-14</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1996">
  <title>DSA-1996 linux-2.6 - privilege escalation/denial of service/sensitive memory leak</title>
  <link>http://www.debian.org/security/2010/dsa-1996</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in the Linux kernel that
may lead to a denial of service, sensitive memory leak or privilege
escalation. The Common Vulnerabilities and Exposures project
identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-12</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1995">
  <title>DSA-1995 openoffice.org - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-1995</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in the OpenOffice.org office
suite. The Common Vulnerabilities and Exposures project identifies the
following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-12</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1994">
  <title>DSA-1994 ajaxterm - weak session IDs</title>
  <link>http://www.debian.org/security/2010/dsa-1994</link>
  <description>
&lt;p&gt;It was discovered that ajaxterm, a web-based terminal, generates weak
and predictable session IDs, which might be used to hijack a session or
cause a denial of service attack on a system that uses ajaxterm.&lt;/p&gt;
  </description>
  <dc:date>2010-02-11</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1993">
  <title>DSA-1993 otrs2 - sql injection</title>
  <link>http://www.debian.org/security/2010/dsa-1993</link>
  <description>
&lt;p&gt;It was discovered that otrs2, the Open Ticket Request System, does not
properly sanitise input data that is used on SQL queries, which might be
used to inject arbitrary SQL to, for example, escalate privileges on a
system that uses otrs2.&lt;/p&gt;
  </description>
  <dc:date>2010-02-10</dc:date>
</item>
</rdf:RDF>
