<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="dsa-rdf.css" type="text/css"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="de">
<channel rdf:about="http://www.debian.org/security/dsa.rdf">
  <title>Debian-Sicherheit</title>
  <link>http://security.debian.org/</link>
  <description>
Debian-Sicherheitsankündigung
  </description>
  <dc:date>2012-05-17T20:10:30+00:00</dc:date>
  <items>
    <rdf:Seq>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2474"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2473"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2472"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2471"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2458"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2457"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2470"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2469"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2468"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2467"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2466"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2465"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2422"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2464"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2459"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2462"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2463"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2461"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2460"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2454"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2456"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2455"/>
    </rdf:Seq>
  </items>
</channel>
<item rdf:about="http://www.debian.org/security/2012/dsa-2474">
  <title>DSA-2474 ikiwiki - cross-site scripting</title>
  <link>http://www.debian.org/security/2012/dsa-2474</link>
  <description>
&lt;p&gt;Raúl Benencia discovered that ikiwiki, a wiki compiler, does not
properly escape the author (and its URL) of certain metadata, such as
comments. This might be used to conduct cross-site scripting attacks.&lt;/p&gt;
  </description>
  <dc:date>2012-05-16</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2473">
  <title>DSA-2473 openoffice.org - buffer overflow</title>
  <link>http://www.debian.org/security/2012/dsa-2473</link>
  <description>
&lt;p&gt;Tielei Wang discovered that OpenOffice.org does not allocate a large
enough memory region when processing a specially crafted JPEG object,
leading to a heap-based buffer overflow and potentially arbitrary code
execution.&lt;/p&gt;
  </description>
  <dc:date>2012-05-16</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2472">
  <title>DSA-2472 gridengine - privilege escalation</title>
  <link>http://www.debian.org/security/2012/dsa-2472</link>
  <description>
&lt;p&gt;Dave Love discovered that users who are allowed to submit jobs to a
Grid Engine installation can escalate their privileges to root because
the environment is not properly sanitized before creating processes.&lt;/p&gt;
  </description>
  <dc:date>2012-05-15</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2471">
  <title>DSA-2471 ffmpeg - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2471</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in FFmpeg, a multimedia
player, server and encoder. Multiple input validations in the decoders/
demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska,
Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of
arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2012-05-13</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2458">
  <title>DSA-2458 iceape - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2458</link>
  <description>
&lt;p&gt;Several vulnerabilities have been found in the Iceape internet suite,
an unbranded version of Seamonkey:&lt;/p&gt;
  </description>
  <dc:date>2012-05-13</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2457">
  <title>DSA-2457 iceweasel - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2457</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Iceweasel, a web
browser based on Firefox. The included XULRunner library provides
rendering services for several other applications included in Debian.&lt;/p&gt;
  </description>
  <dc:date>2012-05-13</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2470">
  <title>DSA-2470 wordpress - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2470</link>
  <description>
&lt;p&gt;Several vulnerabilities were identified in WordPress, a web blogging
tool. As the CVEs were allocated from releases announcements and
specific fixes are usually not identified, it has been decided to
upgrade the wordpress package to the latest upstream version instead
of backporting the patches.&lt;/p&gt;
  </description>
  <dc:date>2012-05-11</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2469">
  <title>DSA-2469 linux-2.6 - privilege escalation/denial of service</title>
  <link>http://www.debian.org/security/2012/dsa-2469</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in the Linux kernel that may lead
to a denial of service or privilege escalation. The Common Vulnerabilities and
Exposures project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2012-05-10</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2468">
  <title>DSA-2468 libjakarta-poi-java - unbounded memory allocation</title>
  <link>http://www.debian.org/security/2012/dsa-2468</link>
  <description>
&lt;p&gt;It was discovered that Apache POI, a Java implementation of the
Microsoft Office file formats, would allocate arbitrary amounts of
memory when processing crafted documents. This could impact the
stability of the Java virtual machine.&lt;/p&gt;
  </description>
  <dc:date>2012-05-09</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2467">
  <title>DSA-2467 mahara - insecure defaults</title>
  <link>http://www.debian.org/security/2012/dsa-2467</link>
  <description>
&lt;p&gt;It was discovered that Mahara, the portfolio, weblog, and resume builder,
had an insecure default with regards to SAML-based authentication used
with more than one SAML identity provider. Someone with control over one
IdP could impersonate users from other IdP's.&lt;/p&gt;
  </description>
  <dc:date>2012-05-09</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2466">
  <title>DSA-2466 rails - cross site scripting</title>
  <link>http://www.debian.org/security/2012/dsa-2466</link>
  <description>
&lt;p&gt;Sergey Nartimov discovered that in Rails, a Ruby based framework for
web development, when developers generate html options tags manually,
user input concatenated with manually built tags may not be escaped
and an attacker can inject arbitrary HTML into the document.&lt;/p&gt;
  </description>
  <dc:date>2012-05-09</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2465">
  <title>DSA-2465 php5 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2465</link>
  <description>
&lt;p&gt;De Eindbazen discovered that PHP, when run with mod_cgi, will
interpret a query string as command line parameters, allowing to
execute arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2012-05-09</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2422">
  <title>DSA-2422 file - missing bounds checks</title>
  <link>http://www.debian.org/security/2012/dsa-2422</link>
  <description>
&lt;p&gt;The file type identification tool, file, and its associated library,
libmagic, do not properly process malformed files in the Composite
Document File (CDF) format, leading to crashes.&lt;/p&gt;
  </description>
  <dc:date>2012-05-09</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2464">
  <title>DSA-2464 icedove - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2464</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Icedove, an unbranded
version of the Thunderbird mail/news client.&lt;/p&gt;
  </description>
  <dc:date>2012-05-08</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2459">
  <title>DSA-2459 quagga - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2459</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Quagga, a routing
daemon.&lt;/p&gt;
  </description>
  <dc:date>2012-05-04</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2462">
  <title>DSA-2462 imagemagick - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2462</link>
  <description>
&lt;p&gt;Several integer overflows and missing input validations were discovered
in the ImageMagick image manipulation suite, resulting in the execution
of arbitrary code or denial of service.&lt;/p&gt;
  </description>
  <dc:date>2012-05-03</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2463">
  <title>DSA-2463 samba - missing permission checks</title>
  <link>http://www.debian.org/security/2012/dsa-2463</link>
  <description>
&lt;p&gt;Ivano Cristofolini discovered that insufficient security checks in
Samba's handling of LSA RPC calls could lead to privilege escalation
by gaining the &lt;q&gt;take ownership&lt;/q&gt; privilege.&lt;/p&gt;
  </description>
  <dc:date>2012-05-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2461">
  <title>DSA-2461 spip - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2461</link>
  <description>
&lt;p&gt;Several vulnerabilities have been found in SPIP, a website engine for
publishing, resulting in cross-site scripting, script code injection
and bypass of restrictions.&lt;/p&gt;
  </description>
  <dc:date>2012-04-26</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2460">
  <title>DSA-2460 asterisk - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2460</link>
  <description>
&lt;p&gt;Several vulnerabilities were discovered in the Asterisk PBX and telephony
toolkit:&lt;/p&gt;
  </description>
  <dc:date>2012-04-25</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2454">
  <title>DSA-2454 openssl - multiple vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2454</link>
  <description>
&lt;p&gt;Multiple vulnerabilities have been found in OpenSSL. The Common
Vulnerabilities and Exposures project identifies the following issues:&lt;/p&gt;
  </description>
  <dc:date>2012-04-24</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2456">
  <title>DSA-2456 dropbear - use after free</title>
  <link>http://www.debian.org/security/2012/dsa-2456</link>
  <description>
&lt;p&gt;Danny Fullerton discovered a use-after-free in the Dropbear SSH daemon,
resulting in potential execution of arbitrary code. Exploitation is
limited to users, who have been authenticated through public key
authentication and for which command restrictions are in place.&lt;/p&gt;
  </description>
  <dc:date>2012-04-23</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2455">
  <title>DSA-2455 typo3-src - missing input sanitization</title>
  <link>http://www.debian.org/security/2012/dsa-2455</link>
  <description>
&lt;p&gt;Helmut Hummel of the TYPO3 security team discovered that TYPO3, a web
content management system, is not properly sanitizing output of the
exception handler. This allows an attacker to conduct cross-site
scripting attacks if either third-party extensions are installed that do
not sanitize this output on their own or in the presence of extensions
using the extbase MVC framework which accept objects to controller actions.&lt;/p&gt;
  </description>
  <dc:date>2012-04-20</dc:date>
</item>
</rdf:RDF>

