<?xml version="1.0" encoding="iso-8859-1"?>
<?xml-stylesheet href="dsa-rdf.css" type="text/css"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="en">
<channel rdf:about="http://www.debian.org/security/dsa.rdf">
  <title>Debian Security</title>
  <link>http://security.debian.org/</link>
  <description>
Debian Security Advisories
  </description>
  <dc:date>2010-03-13T19:33:37+00:00</dc:date>
  <items>
    <rdf:Seq>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2016"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2014"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2013"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2012"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2011"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2010"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2009"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2008"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2007"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2006"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2004"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2005"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2003"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2002"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2001"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2000"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1999"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1998"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1997"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1996"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1995"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-1994"/>
    </rdf:Seq>
  </items>
</channel>
<item rdf:about="http://www.debian.org/security/2010/dsa-2016">
  <title>DSA-2016 drupal6 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2016</link>
  <description>
&lt;p&gt;Several vulnerabilities (SA-CORE-2010-001) have been discovered in
drupal6, a fully-featured content management framework.&lt;/p&gt;
  </description>
  <dc:date>2010-03-13</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2014">
  <title>DSA-2014 moin - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2014</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in moin, a python clone of
WikiWiki.
The Common Vulnerabilities and Exposures project identifies the
following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-03-12</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2013">
  <title>DSA-2013 egroupware - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2013</link>
  <description>
&lt;p&gt;Nahuel Grisolia discovered two vulnerabilities in Egroupware, a web-based
groupware suite: Missing input sanitising in the spellchecker integration
may lead to the execution of arbitrary commands and a cross-site scripting
vulnerability was discovered in the login page.&lt;/p&gt;
  </description>
  <dc:date>2010-03-11</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2012">
  <title>DSA-2012 linux-2.6 - privilege escalation/denial of service</title>
  <link>http://www.debian.org/security/2010/dsa-2012</link>
  <description>
&lt;p&gt;Two vulnerabilities have been discovered in the Linux kernel that
may lead to a denial of service or privilege escalation. The Common
Vulnerabilities and Exposures project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-03-11</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2011">
  <title>DSA-2011 dpkg - path traversal</title>
  <link>http://www.debian.org/security/2010/dsa-2011</link>
  <description>
&lt;p&gt;William Grant discovered that the dpkg-source component of dpkg, the
low-level infrastructure for handling the installation and removal of
Debian software packages, is vulnerable to path traversal attacks.
A specially crafted Debian source package can lead to file modification
outside of the destination directory when extracting the package content.&lt;/p&gt;
  </description>
  <dc:date>2010-03-10</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2010">
  <title>DSA-2010 kvm - privilege escalation/denial of service</title>
  <link>http://www.debian.org/security/2010/dsa-2010</link>
  <description>
&lt;p&gt;Several local vulnerabilities have been discovered in kvm, a full
virtualization system. The Common Vulnerabilities and Exposures project
identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-03-10</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2009">
  <title>DSA-2009 tdiary - insufficient input sanitising</title>
  <link>http://www.debian.org/security/2010/dsa-2009</link>
  <description>
&lt;p&gt;It was discovered that tdiary, a communication-friendly weblog system,
is prone to a cross-site scripting vulnerability due to insufficient
input sanitising in the TrackBack transmission plugin.&lt;/p&gt;
  </description>
  <dc:date>2010-03-09</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2008">
  <title>DSA-2008 typo3-src - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2008</link>
  <description>
&lt;p&gt;Several remote vulnerabilities have been discovered in the TYPO3 web
content management framework: Cross-site scripting vulnerabilities have
been discovered in both the frontend and the backend. Also, user data
could be leaked. More details can be found in the
&lt;a href="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-004/"&gt;Typo3
security advisory&lt;/a&gt;.&lt;/p&gt;
  </description>
  <dc:date>2010-03-08</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2007">
  <title>DSA-2007 cups - format string vulnerability</title>
  <link>http://www.debian.org/security/2010/dsa-2007</link>
  <description>
&lt;p&gt;Ronald Volgers discovered that the lppasswd component of the cups suite,
the Common UNIX Printing System, is vulnerable to format string attacks
due to insecure use of the LOCALEDIR environment variable. An attacker
can abuse this behaviour to execute arbitrary code via crafted localization
files and triggering calls to _cupsLangprintf(). This works as the lppasswd
binary happens to be installed with setuid 0 permissions.&lt;/p&gt;
  </description>
  <dc:date>2010-03-03</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2006">
  <title>DSA-2006 sudo - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2006</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in sudo, a program
designed to allow a sysadmin to give limited root privileges to users.
The Common Vulnerabilities and Exposures project identifies the
following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-03-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2004">
  <title>DSA-2004 samba - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2004</link>
  <description>
&lt;p&gt;Two local vulnerabilities have been discovered in samba, a SMB/CIFS file,
print, and login server for Unix. The Common Vulnerabilities and
Exposures project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-28</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2005">
  <title>DSA-2005 linux-2.6.24 - privilege escalation/denial of service/sensitive memory leak</title>
  <link>http://www.debian.org/security/2010/dsa-2005</link>
  <description>
&lt;p&gt;NOTE: This kernel update marks the final planned kernel security
update for the 2.6.24 kernel in the Debian release 'etch'. Although
security support for 'etch' officially ended on Feburary 15th, 2010,
this update was already in preparation before that date.&lt;/p&gt;
  </description>
  <dc:date>2010-02-27</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2003">
  <title>DSA-2003 linux-2.6 - privilege escalation/denial of service</title>
  <link>http://www.debian.org/security/2010/dsa-2003</link>
  <description>
&lt;p&gt;NOTE: This kernel update marks the final planned kernel security update for
the 2.6.18 kernel in the Debian release 'etch'. Although security support for
'etch' officially ended on Feburary 15th, 2010, this update was already in
preparation before that date. A final update that includes fixes for these
issues in the 2.6.24 kernel is also in preparation and will be released
shortly.&lt;/p&gt;
  </description>
  <dc:date>2010-02-22</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2002">
  <title>DSA-2002 polipo - denial of service</title>
  <link>http://www.debian.org/security/2010/dsa-2002</link>
  <description>
&lt;p&gt;Several denial of service vulnerabilities have been discovered in polipo, a
small, caching web proxy. The Common Vulnerabilities and Exposures project
identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-19</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2001">
  <title>DSA-2001 php5 - multiple vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2001</link>
  <description>
&lt;p&gt;Several remote vulnerabilities have been discovered in PHP 5, an
hypertext preprocessor. The Common Vulnerabilities and Exposures
project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-19</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2000">
  <title>DSA-2000 ffmpeg-debian - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2000</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in ffmpeg, a multimedia
player, server and encoder, which also provides a range of multimedia
libraries used in applications like MPlayer:&lt;/p&gt;
  </description>
  <dc:date>2010-02-18</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1999">
  <title>DSA-1999 xulrunner - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-1999</link>
  <description>
&lt;p&gt;Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications, such as the Iceweasel web
browser. The Common Vulnerabilities and Exposures project identifies
the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-18</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1998">
  <title>DSA-1998 kdelibs - buffer overflow</title>
  <link>http://www.debian.org/security/2010/dsa-1998</link>
  <description>
&lt;p&gt;Maksymilian Arciemowicz discovered a buffer overflow in the internal
string routines of the KDE core libraries, which could lead to the
execution of arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2010-02-17</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1997">
  <title>DSA-1997 mysql-dfsg-5.0 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-1997</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in the MySQL
database server.
The Common Vulnerabilities and Exposures project identifies the
following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-14</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1996">
  <title>DSA-1996 linux-2.6 - privilege escalation/denial of service/sensitive memory leak</title>
  <link>http://www.debian.org/security/2010/dsa-1996</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in the Linux kernel that
may lead to a denial of service, sensitive memory leak or privilege
escalation. The Common Vulnerabilities and Exposures project
identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-12</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1995">
  <title>DSA-1995 openoffice.org - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-1995</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in the OpenOffice.org office
suite. The Common Vulnerabilities and Exposures project identifies the
following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-02-12</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-1994">
  <title>DSA-1994 ajaxterm - weak session IDs</title>
  <link>http://www.debian.org/security/2010/dsa-1994</link>
  <description>
&lt;p&gt;It was discovered that ajaxterm, a web-based terminal, generates weak
and predictable session IDs, which might be used to hijack a session or
cause a denial of service attack on a system that uses ajaxterm.&lt;/p&gt;
  </description>
  <dc:date>2010-02-11</dc:date>
</item>
</rdf:RDF>
