<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="dsa-rdf.css" type="text/css"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="fr">
<channel rdf:about="http://www.debian.org/security/dsa.rdf">
  <title>Sécurité Debian</title>
  <link>http://security.debian.org/</link>
  <description>
Bulletins d'alerte Debian
  </description>
  <dc:date>2010-09-07T11:35:36+00:00</dc:date>
  <items>
    <rdf:Seq>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2104"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2103"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2102"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2101"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2100"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2099"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2098"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2097"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2096"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2095"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2094"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2093"/>
<rdf:li resource="http://www.debian.org/security/2010/dsa-2091"/>
    </rdf:Seq>
  </items>
</channel>
<item rdf:about="http://www.debian.org/security/2010/dsa-2104">
  <title>DSA-2104 quagga - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2104</link>
  <description>
&lt;p&gt;Several remote vulnerabilities have been discovered in the BGP
implementation of Quagga, a routing daemon.&lt;/p&gt;
  </description>
  <dc:date>2010-09-06</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2103">
  <title>DSA-2103 smbind - sql injection</title>
  <link>http://www.debian.org/security/2010/dsa-2103</link>
  <description>
&lt;p&gt;It was discovered that smbind, a PHP-based tool for managing DNS zones
for BIND, does not properly validating input.
An unauthenticated remote attacker could execute arbitrary SQL commands
or gain access to the admin account.&lt;/p&gt;
  </description>
  <dc:date>2010-09-05</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2102">
  <title>DSA-2102 barnowl - unchecked return value</title>
  <link>http://www.debian.org/security/2010/dsa-2102</link>
  <description>
&lt;p&gt;It has been discovered that in barnowl, a curses-based instant-messaging
client, the return codes of calls to the ZPending and ZReceiveNotice
functions in libzephyr were not checked, allowing attackers to cause a
denial of service (crash of the application), and possibly execute
arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2010-09-03</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2101">
  <title>DSA-2101 wireshark - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2101</link>
  <description>
&lt;p&gt;Several implementation errors in the dissector of the Wireshark network
traffic analyzer for the ASN.1 BER protocol and in the SigComp Universal
Decompressor Virtual Machine may lead to the execution of arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2010-08-31</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2100">
  <title>DSA-2100 openssl - double free</title>
  <link>http://www.debian.org/security/2010/dsa-2100</link>
  <description>
&lt;p&gt;George Guninski discovered a double free in the ECDH code of the OpenSSL
crypto library, which may lead to denial of service and potentially the
execution of arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2010-08-30</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2099">
  <title>DSA-2099 openoffice.org - buffer overflows</title>
  <link>http://www.debian.org/security/2010/dsa-2099</link>
  <description>
&lt;p&gt;Charlie Miller has discovered two vulnerabilities in OpenOffice.org
Impress, which can be exploited by malicious people to compromise a
user's system and execute arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2010-08-30</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2098">
  <title>DSA-2098 typo3-src - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2098</link>
  <description>
&lt;p&gt;Several remote vulnerabilities have been discovered in the TYPO3 web
content management framework: cross-site Scripting, open redirection,
SQL injection, broken authentication and session management,
insecure randomness, information disclosure and arbitrary code
execution. More details can be found in
&lt;a href="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-012/"&gt;the Typo3 security advisory&lt;/a&gt;.&lt;/p&gt;
  </description>
  <dc:date>2010-08-29</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2097">
  <title>DSA-2097 phpmyadmin - insufficient input sanitising</title>
  <link>http://www.debian.org/security/2010/dsa-2097</link>
  <description>
&lt;p&gt;Several remote vulnerabilities have been discovered in phpMyAdmin, a tool
to administer MySQL over the web. The Common Vulnerabilities and Exposures
project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-08-29</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2096">
  <title>DSA-2096 zope-ldapuserfolder - missing input validation</title>
  <link>http://www.debian.org/security/2010/dsa-2096</link>
  <description>
&lt;p&gt;Jeremy James discovered that in zope-ldapuserfolder, a Zope extension
used to authenticate against an LDAP server, the authentication code
does not verify the password provided for the emergency user. Malicious
users that manage to get the emergency user login can use this flaw to
gain administrative access to the Zope instance, by providing an
arbitrary password.&lt;/p&gt;
  </description>
  <dc:date>2010-08-24</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2095">
  <title>DSA-2095 lvm2 - insecure communication protocol</title>
  <link>http://www.debian.org/security/2010/dsa-2095</link>
  <description>
&lt;p&gt;Alasdair Kergon discovered that the cluster logical volume manager daemon
(clvmd) in lvm2, The Linux Logical Volume Manager, does not verify client
credentials upon a socket connection, which allows local users to cause a
denial of service.&lt;/p&gt;
  </description>
  <dc:date>2010-08-23</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2094">
  <title>DSA-2094 linux-2.6 - privilege escalation/denial of service/information leak</title>
  <link>http://www.debian.org/security/2010/dsa-2094</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in the Linux kernel that
may lead to a denial of service or privilege escalation. The Common
Vulnerabilities and Exposures project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-08-19</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2093">
  <title>DSA-2093 ghostscript - several vulnerabilities</title>
  <link>http://www.debian.org/security/2010/dsa-2093</link>
  <description>
&lt;p&gt;Two security issues have been discovered in Ghostscript, the GPL
PostScript/PDF interpreter. The Common Vulnerabilities and Exposures
project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2010-08-19</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2010/dsa-2091">
  <title>DSA-2091 squirrelmail - No user-specific token implemented</title>
  <link>http://www.debian.org/security/2010/dsa-2091</link>
  <description>
&lt;p&gt;SquirrelMail, a webmail application, does not employ a user-specific token
for webforms. This allows a remote attacker to perform a Cross Site Request
Forgery (CSRF) attack. The attacker may hijack the authentication of
unspecified victims and send messages or change user preferences among other
actions, by tricking the victim into following a link controlled by the
offender.&lt;/p&gt;
  </description>
  <dc:date>2010-08-12</dc:date>
</item>
</rdf:RDF>
