<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>LinuxSecurity.com - Security Advisories</title>
    <link>http://www.linuxsecurity.com/</link>
    <description>The central voice for Linux and Open Source security news.</description>
    <language>en-us</language>
    <generator>update-rss-feeds.pl (1.01)</generator>

  <item>
    <title>Slackware:   php </title>
    <link>http://www.linuxsecurity.com/content/view/141239?rdf</link>
    <pubDate>Wed, 03 Sep 2008 23:39:00 +0000</pubDate>
    <description>&#60;b&#62;LinuxSecurity.com&#60;/b&#62;: New php packages are available for Slackware 10.2 and 11.0 to fix security issues.  These releases are the last to contain PHP 4.4.x, which was upgraded to version 4.4.9 to fix PCRE issues and other bugs. Please note that this is the FINAL release of PHP4, and it has already passed the announced end-of-life.  Sites should seriously consider migrating to PHP5 rather than upgrading to php-4.4.9. </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/141239?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>Ubuntu:  libxml2 vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/141238?rdf</link>
    <pubDate>Wed, 03 Sep 2008 19:10:00 +0000</pubDate>
    <description>&#60;b&#62;LinuxSecurity.com&#60;/b&#62;: Andreas Solberg discovered that libxml2 did not handle recursive entities safely.  If an application linked against libxml2 were made to process a specially crafted XML document, a remote attacker could exhaust the system's CPU resources, leading to a denial of service. </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/141238?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>Mandriva: Subject: [Security Announce] [ MDVSA-2008:185 ] python-django</title>
    <link>http://www.linuxsecurity.com/content/view/141236?rdf</link>
    <pubDate>Wed, 03 Sep 2008 16:50:00 +0000</pubDate>
    <description>&#60;b&#62;LinuxSecurity.com&#60;/b&#62;: A cross-site request forgery vulnerability was discovered in Django that, if exploited, could be used to perform unrequested deletion or modification of data.  Updated versions of Django will now discard posts from users whose sessions have expired, so data will need to be re-entered in these cases. </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/141236?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>Mandriva: Subject: [Security Announce] [ MDVSA-2008:184 ] libtiff</title>
    <link>http://www.linuxsecurity.com/content/view/141235?rdf</link>
    <pubDate>Wed, 03 Sep 2008 15:16:00 +0000</pubDate>
    <description>&#60;b&#62;LinuxSecurity.com&#60;/b&#62;: Drew Yaro of the Apple Product Security Team reported multiple uses of uninitialized values in libtiff's LZW compression algorithm decoder. An attacker could create a carefully crafted LZW-encoded TIFF file that would cause an application linked to libtiff to crash or potentially execute arbitrary code (CVE-2008-2327). The updated packages have been patched to prevent this issue.</description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/141235?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>Mandriva: Subject: [Security Announce] [ MDVSA-2008:183 ] opensc</title>
    <link>http://www.linuxsecurity.com/content/view/141232?rdf</link>
    <pubDate>Tue, 02 Sep 2008 17:16:00 +0000</pubDate>
    <description>&#60;b&#62;LinuxSecurity.com&#60;/b&#62;: Chaskiel M Grundman found that OpenSC would initialize smart cards with the Siemens CardOS M4 card operating system without proper access rights.  This allowed everyone to change the card's PIN without first having the PIN or PUK, or the superuser's PIN or PUK (CVE-2008-2235). </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/141232?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>Ubuntu:  tiff vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/141231?rdf</link>
    <pubDate>Tue, 02 Sep 2008 17:07:00 +0000</pubDate>
    <description>&#60;b&#62;LinuxSecurity.com&#60;/b&#62;: Drew Yao discovered that the TIFF library did not correctly validate LZW compressed TIFF images.  If a user or automated system were tricked into processing a malicious image, a remote attacker could execute arbitrary code or cause an application linked against libtiff to crash, leading to a denial of service. </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/141231?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  </channel>
</rss>
