<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="dsa-rdf.css" type="text/css"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="en">
<channel rdf:about="http://www.debian.org/security/dsa.rdf">
  <title>Debian Security</title>
  <link>http://security.debian.org/</link>
  <description>
Debian Security Advisories
  </description>
  <dc:date>2012-02-22T11:44:04+00:00</dc:date>
  <items>
    <rdf:Seq>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2415"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2414"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2413"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2412"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2411"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2410"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2409"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2408"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2407"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2406"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2405"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2403"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2404"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2384"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2402"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2401"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2400"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2399"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2398"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2397"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2396"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2395"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2394"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2393"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2392"/>
<rdf:li resource="http://www.debian.org/security/2011/dsa-2301"/>
    </rdf:Seq>
  </items>
</channel>
<item rdf:about="http://www.debian.org/security/2012/dsa-2415">
  <title>DSA-2415 libmodplug - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2415</link>
  <description>
&lt;p&gt;Several vulnerabilities that can lead to the execution of arbitrary code
have been discovered in libmodplug, a library for MOD music based on
ModPlug. The Common Vulnerabilities and Exposures project identifies
the following issues:&lt;/p&gt;
  </description>
  <dc:date>2012-02-21</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2414">
  <title>DSA-2414 fex - insufficient input sanitization</title>
  <link>http://www.debian.org/security/2012/dsa-2414</link>
  <description>
&lt;p&gt;Nicola Fioravanti discovered that F*X, a web service for transferring
very large files, is not properly sanitizing input parameters of the &lt;q&gt;fup&lt;/q&gt;
script. An attacker can use this flaw to conduct reflected cross-site
scripting attacks via various script parameters.&lt;/p&gt;
  </description>
  <dc:date>2012-02-21</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2413">
  <title>DSA-2413 libarchive - buffer overflows</title>
  <link>http://www.debian.org/security/2012/dsa-2413</link>
  <description>
&lt;p&gt;Two buffer overflows have been discovered in libarchive, a library
providing a flexible interface for reading and writing archives in
various formats. The possible buffer overflows while reading ISO 9660
or tar streams allow remote attackers to execute arbitrary
code depending on the application that makes use of this functionality.&lt;/p&gt;
  </description>
  <dc:date>2012-02-20</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2412">
  <title>DSA-2412 libvorbis - buffer overflow</title>
  <link>http://www.debian.org/security/2012/dsa-2412</link>
  <description>
&lt;p&gt;It was discovered that a heap overflow in the Vorbis audio compression
library could lead to the execution of arbitrary code if a malformed
Ogg Vorbis file is processed.&lt;/p&gt;
  </description>
  <dc:date>2012-02-19</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2411">
  <title>DSA-2411 mumble - information disclosure</title>
  <link>http://www.debian.org/security/2012/dsa-2411</link>
  <description>
&lt;p&gt;It was discovered that Mumble, a VoIP client, does not properly manage
permissions on its user-specific configuration files, allowing other
local users on the system to access them.&lt;/p&gt;
  </description>
  <dc:date>2012-02-19</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2410">
  <title>DSA-2410 libpng - integer overflow</title>
  <link>http://www.debian.org/security/2012/dsa-2410</link>
  <description>
&lt;p&gt;Jueri Aedla discovered an integer overflow in the libpng PNG library,
which could lead to the execution of arbitrary code if a malformed
image is processed.&lt;/p&gt;
  </description>
  <dc:date>2012-02-15</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2409">
  <title>DSA-2409 devscripts - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2409</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in debdiff, a script used
to compare two Debian packages, which is part of the devscripts package.
The following Common Vulnerabilities and Exposures project ids have been
assigned to identify them:&lt;/p&gt;
  </description>
  <dc:date>2012-02-15</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2408">
  <title>DSA-2408 php5 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2408</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in PHP, the web scripting
language. The Common Vulnerabilities and Exposures project identifies
the following issues:&lt;/p&gt;
  </description>
  <dc:date>2012-02-13</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2407">
  <title>DSA-2407 cvs - heap overflow</title>
  <link>http://www.debian.org/security/2012/dsa-2407</link>
  <description>
&lt;p&gt;It was discovered that a malicious CVS server could cause a heap
overflow in the CVS client, potentially allowing the server to execute
arbitrary code on the client.&lt;/p&gt;
  </description>
  <dc:date>2012-02-09</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2406">
  <title>DSA-2406 icedove - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2406</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Icedove, Debian's
variant of the Mozilla Thunderbird code base.&lt;/p&gt;
  </description>
  <dc:date>2012-02-09</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2405">
  <title>DSA-2405 apache2 - multiple issues</title>
  <link>http://www.debian.org/security/2012/dsa-2405</link>
  <description>
&lt;p&gt;Several vulnerabilities have been found in the Apache HTTPD Server:&lt;/p&gt;
  </description>
  <dc:date>2012-02-06</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2403">
  <title>DSA-2403 php5 - code injection</title>
  <link>http://www.debian.org/security/2012/dsa-2403</link>
  <description>
&lt;p&gt;Stefan Esser discovered that the implementation of the max_input_vars
configuration variable in a recent PHP security update was flawed such
that it allows remote attackers to crash PHP or potentially execute
code.&lt;/p&gt;
  </description>
  <dc:date>2012-02-06</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2404">
  <title>DSA-2404 xen-qemu-dm-4.0 - buffer overflow</title>
  <link>http://www.debian.org/security/2012/dsa-2404</link>
  <description>
&lt;p&gt;Nicolae Mogoreanu discovered a heap overflow in the emulated e1000e
network interface card of QEMU, which is used in the xen-qemu-dm-4.0
packages. This vulnerability might enable to malicious guest systems
to crash the host system or escalate their privileges.&lt;/p&gt;
  </description>
  <dc:date>2012-02-05</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2384">
  <title>DSA-2384 cacti - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2384</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Cacti, a graphing tool
for monitoring data. Multiple cross site scripting issues allow remote
attackers to inject arbitrary web script or HTML. An SQL injection
vulnerability allows remote attackers to execute arbitrary SQL commands.&lt;/p&gt;
  </description>
  <dc:date>2012-02-04</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2402">
  <title>DSA-2402 iceape - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2402</link>
  <description>
&lt;p&gt;Several vulnerabilities have been found in the Iceape internet suite, an
unbranded version of Seamonkey:&lt;/p&gt;
  </description>
  <dc:date>2012-02-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2401">
  <title>DSA-2401 tomcat6 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2401</link>
  <description>
&lt;p&gt;Several vulnerabilities have been found in Tomcat, a servlet and JSP
engine:&lt;/p&gt;
  </description>
  <dc:date>2012-02-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2400">
  <title>DSA-2400 iceweasel - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2400</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Iceweasel, a web browser
based on Firefox. The included XULRunner library provides rendering
services for several other applications included in Debian.&lt;/p&gt;
  </description>
  <dc:date>2012-02-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2399">
  <title>DSA-2399 php5 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2399</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in PHP, the web scripting
language. The Common Vulnerabilities and Exposures project identifies
the following issues:&lt;/p&gt;
  </description>
  <dc:date>2012-01-31</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2398">
  <title>DSA-2398 curl - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2398</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in cURL, an URL transfer
library. The Common Vulnerabilities and Exposures project identifies the
following problems:&lt;/p&gt;
  </description>
  <dc:date>2012-01-30</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2397">
  <title>DSA-2397 icu - buffer underflow</title>
  <link>http://www.debian.org/security/2012/dsa-2397</link>
  <description>
&lt;p&gt;It was discovered that a buffer overflow in the Unicode library ICU
could lead to the execution of arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2012-01-29</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2396">
  <title>DSA-2396 qemu-kvm - buffer underflow</title>
  <link>http://www.debian.org/security/2012/dsa-2396</link>
  <description>
&lt;p&gt;Nicolae Mogoreanu discovered a heap overflow in the emulated e1000e
network interface card of KVM, a solution for full virtualization on
x86 hardware, which could result in denial of service or privilege
escalation.&lt;/p&gt;
  </description>
  <dc:date>2012-01-27</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2395">
  <title>DSA-2395 wireshark - buffer underflow</title>
  <link>http://www.debian.org/security/2012/dsa-2395</link>
  <description>
&lt;p&gt;Laurent Butti discovered a buffer underflow in the LANalyzer dissector
of the Wireshark network traffic analyzer, which could lead to the
execution of arbitrary code (&lt;a
href="http://security-tracker.debian.org/tracker/CVE-2012-0068"&gt;CVE-2012-0068&lt;/a&gt;).
&lt;/p&gt;
  </description>
  <dc:date>2012-01-27</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2394">
  <title>DSA-2394 libxml2 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2394</link>
  <description>
&lt;p&gt;Many security problems have been fixed in libxml2, a popular library to handle
XML data files.&lt;/p&gt;
  </description>
  <dc:date>2012-01-27</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2393">
  <title>DSA-2393 bip - buffer overflow</title>
  <link>http://www.debian.org/security/2012/dsa-2393</link>
  <description>
&lt;p&gt;Julien Tinnes reported a buffer overflow in the Bip multiuser IRC proxy
which may allow arbitrary code execution by remote users.&lt;/p&gt;
  </description>
  <dc:date>2012-01-25</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2392">
  <title>DSA-2392 openssl - out-of-bounds read</title>
  <link>http://www.debian.org/security/2012/dsa-2392</link>
  <description>
&lt;p&gt;Antonio Martin discovered a denial-of-service vulnerability in
OpenSSL, an implementation of TLS and related protocols. A malicious
client can cause the DTLS server implementation to crash. Regular,
TCP-based TLS is not affected by this issue.&lt;/p&gt;
  </description>
  <dc:date>2012-01-23</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2011/dsa-2301">
  <title>DSA-2301 rails - several vulnerabilities</title>
  <link>http://www.debian.org/security/2011/dsa-2301</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Rails, the Ruby web
application framework. The Common Vulnerabilities and Exposures project
identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2012-01-23</dc:date>
</item>
</rdf:RDF>

