<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="dsa-rdf.css" type="text/css"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="en">
<channel rdf:about="http://www.debian.org/security/dsa.rdf">
  <title>Debian Security</title>
  <link>http://security.debian.org/</link>
  <description>
Debian Security Advisories
  </description>
  <dc:date>2012-02-05T23:59:03+00:00</dc:date>
  <items>
    <rdf:Seq>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2404"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2384"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2403"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2402"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2401"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2400"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2399"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2398"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2397"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2396"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2395"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2394"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2393"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2392"/>
<rdf:li resource="http://www.debian.org/security/2011/dsa-2301"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2391"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2390"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2389"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2388"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2387"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2386"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2385"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2383"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2382"/>
<rdf:li resource="http://www.debian.org/security/2012/dsa-2381"/>
    </rdf:Seq>
  </items>
</channel>
<item rdf:about="http://www.debian.org/security/2012/dsa-2404">
  <title>DSA-2404 xen-qemu-dm-4.0 - buffer overflow</title>
  <link>http://www.debian.org/security/2012/dsa-2404</link>
  <description>
&lt;p&gt;Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e
network interface card of QEMU, which is used in the xen-qemu-dm-4.0
packages. This vulnerability might enable to malicious guest systems
to crash the host system or escalate their privileges.&lt;/p&gt;
  </description>
  <dc:date>2012-02-05</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2384">
  <title>DSA-2384 cacti - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2384</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Cacti, a graphing tool
for monitoring data. Multiple cross site scripting issues allow remote
attackers to inject arbitrary web script or HTML. An SQL injection
vulnerability allows remote attackers to execute arbitrary SQL commands.&lt;/p&gt;
  </description>
  <dc:date>2012-02-04</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2403">
  <title>DSA-2403 php5 - code injection</title>
  <link>http://www.debian.org/security/2012/dsa-2403</link>
  <description>
&lt;p&gt;Stefan Esser discovered that the implementation of the max_input_vars
configuration variable in a recent PHP security update was flawed such
that it allows remote attackers to crash PHP or potentially execute
code.&lt;/p&gt;
  </description>
  <dc:date>2012-02-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2402">
  <title>DSA-2402 iceape - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2402</link>
  <description>
&lt;p&gt;Several vulnerabilities have been found in the Iceape internet suite, an
unbranded version of Seamonkey:&lt;/p&gt;
  </description>
  <dc:date>2012-02-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2401">
  <title>DSA-2401 tomcat6 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2401</link>
  <description>
&lt;p&gt;Several vulnerabilities have been found in Tomcat, a servlet and JSP
engine:&lt;/p&gt;
  </description>
  <dc:date>2012-02-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2400">
  <title>DSA-2400 iceweasel - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2400</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Iceweasel, a web browser
based on Firefox. The included XULRunner library provides rendering
services for several other applications included in Debian.&lt;/p&gt;
  </description>
  <dc:date>2012-02-02</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2399">
  <title>DSA-2399 php5 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2399</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in PHP, the web scripting
language. The Common Vulnerabilities and Exposures project identifies
the following issues:&lt;/p&gt;
  </description>
  <dc:date>2012-01-31</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2398">
  <title>DSA-2398 curl - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2398</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in cURL, an URL transfer
library. The Common Vulnerabilities and Exposures project identifies the
following problems:&lt;/p&gt;
  </description>
  <dc:date>2012-01-30</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2397">
  <title>DSA-2397 icu - buffer underflow</title>
  <link>http://www.debian.org/security/2012/dsa-2397</link>
  <description>
&lt;p&gt;It was discovered that a buffer overflow in the Unicode library ICU
could lead to the execution of arbitrary code.&lt;/p&gt;
  </description>
  <dc:date>2012-01-29</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2396">
  <title>DSA-2396 qemu-kvm - buffer underflow</title>
  <link>http://www.debian.org/security/2012/dsa-2396</link>
  <description>
&lt;p&gt;Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e
network interface card of KVM, a solution for full virtualization on
x86 hardware, which could result in denial of service or privilege
escalation.&lt;/p&gt;
  </description>
  <dc:date>2012-01-27</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2395">
  <title>DSA-2395 wireshark - buffer underflow</title>
  <link>http://www.debian.org/security/2012/dsa-2395</link>
  <description>
&lt;p&gt;Laurent Butti discovered a buffer underflow in the LANalyzer dissector
of the Wireshark network traffic analyzer, which could lead to the
execution of arbitrary code (&lt;a
href="http://security-tracker.debian.org/tracker/CVE-2012-0068"&gt;CVE-2012-0068&lt;/a&gt;).
&lt;/p&gt;
  </description>
  <dc:date>2012-01-27</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2394">
  <title>DSA-2394 libxml2 - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2394</link>
  <description>
&lt;p&gt;Many security problems have been fixed in libxml2, a popular library to handle
XML data files.&lt;/p&gt;
  </description>
  <dc:date>2012-01-27</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2393">
  <title>DSA-2393 bip - buffer overflow</title>
  <link>http://www.debian.org/security/2012/dsa-2393</link>
  <description>
&lt;p&gt;Julien Tinnes reported a buffer overflow in the Bip multiuser IRC proxy
which may allow arbitrary code execution by remote users.&lt;/p&gt;
  </description>
  <dc:date>2012-01-25</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2392">
  <title>DSA-2392 openssl - out-of-bounds read</title>
  <link>http://www.debian.org/security/2012/dsa-2392</link>
  <description>
&lt;p&gt;Antonio Martin discovered a denial-of-service vulnerability in
OpenSSL, an implementation of TLS and related protocols. A malicious
client can cause the DTLS server implementation to crash. Regular,
TCP-based TLS is not affected by this issue.&lt;/p&gt;
  </description>
  <dc:date>2012-01-23</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2011/dsa-2301">
  <title>DSA-2301 rails - several vulnerabilities</title>
  <link>http://www.debian.org/security/2011/dsa-2301</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in Rails, the Ruby web
application framework. The Common Vulnerabilities and Exposures project
identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2012-01-23</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2391">
  <title>DSA-2391 phpmyadmin - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2391</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in phpMyAdmin, a tool
to administer MySQL over the web. The Common Vulnerabilities and
Exposures project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2012-01-22</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2390">
  <title>DSA-2390 openssl - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2390</link>
  <description>
&lt;p&gt;Several vulnerabilities were discovered in OpenSSL, an implementation
of TLS and related protocols. The Common Vulnerabilities and
Exposures project identifies the following vulnerabilities:&lt;/p&gt;
  </description>
  <dc:date>2012-01-15</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2389">
  <title>DSA-2389 linux-2.6 - privilege escalation/denial of service/information leak</title>
  <link>http://www.debian.org/security/2012/dsa-2389</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in the Linux kernel that may lead
to a denial of service or privilege escalation. The Common Vulnerabilities and
Exposures project identifies the following problems:&lt;/p&gt;
  </description>
  <dc:date>2012-01-15</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2388">
  <title>DSA-2388 t1lib - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2388</link>
  <description>
&lt;p&gt;Several vulnerabilities were discovered in t1lib, a Postscript Type 1
font rasterizer library, some of which might lead to code execution
through the opening of files embedding bad fonts.&lt;/p&gt;
  </description>
  <dc:date>2012-01-14</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2387">
  <title>DSA-2387 simplesamlphp - insufficient input sanitation</title>
  <link>http://www.debian.org/security/2012/dsa-2387</link>
  <description>
&lt;p&gt;&lt;q&gt;timtai1&lt;/q&gt; discovered that simpleSAMLphp, an authentication and federation
platform, is vulnerable to a cross site scripting attack, allowing a
remote attacker to access sensitive client data.&lt;/p&gt;
  </description>
  <dc:date>2012-01-11</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2386">
  <title>DSA-2386 openttd - several vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2386</link>
  <description>
&lt;p&gt;Several vulnerabilities have been discovered in OpenTTD, a transport
business simulation game. Multiple buffer overflows and off-by-one
errors allow remote attackers to cause denial of service.&lt;/p&gt;
  </description>
  <dc:date>2012-01-10</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2385">
  <title>DSA-2385 pdns - packet loop</title>
  <link>http://www.debian.org/security/2012/dsa-2385</link>
  <description>
&lt;p&gt;Ray Morris discovered that the PowerDNS authoritative server responds
to response packets. An attacker who can spoof the source address of
IP packets can cause an endless packet loop between a PowerDNS
authoritative server and another DNS server, leading to a denial of
service.&lt;/p&gt;
  </description>
  <dc:date>2012-01-10</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2383">
  <title>DSA-2383 super - buffer overflow</title>
  <link>http://www.debian.org/security/2012/dsa-2383</link>
  <description>
&lt;p&gt;Robert Luberda discovered a buffer overflow in the syslog logging code of
Super, a tool to execute scripts (or other commands) as if they were root.
The default Debian configuration is not affected.&lt;/p&gt;
  </description>
  <dc:date>2012-01-08</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2382">
  <title>DSA-2382 ecryptfs-utils - multiple vulnerabilities</title>
  <link>http://www.debian.org/security/2012/dsa-2382</link>
  <description>
&lt;p&gt;Several problems have been discovered in eCryptfs, a cryptographic
filesystem for Linux.&lt;/p&gt;
  </description>
  <dc:date>2012-01-07</dc:date>
</item>
<item rdf:about="http://www.debian.org/security/2012/dsa-2381">
  <title>DSA-2381 squid3 - invalid memory deallocation</title>
  <link>http://www.debian.org/security/2012/dsa-2381</link>
  <description>
&lt;p&gt;It was discovered that the IPv6 support code in Squid does not
properly handle certain DNS responses, resulting in deallocation of an
invalid pointer and a daemon crash.&lt;/p&gt;
  </description>
  <dc:date>2012-01-06</dc:date>
</item>
</rdf:RDF>

