<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>LinuxSecurity.com: FreeBSD Advisories</title>
    <link>http://www.linuxsecurity.com/</link>
    <description>The central voice for Linux and Open Source security news.</description>
    <language>en-us</language>
    <generator>generate-advisory-rss.pl (1.01)</generator>

  <item>
    <title>Study: Spammers use e-mail ID to gain legitimacy</title>
    <link>http://www.linuxsecurity.com/content/view/116271?rdf</link>
    <description>(Sep 9) With few junk e-mail filters supporting a protocol for verifying the source address of digital messages, spammers have adopted it themselves as a way to appear more legitimate, according to a report released on Wednesday. . . . ... </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/116271?rdf</guid>
    <source url='http://www.linuxsecurity.com'>Robert Lemos, CNET News.com</source>
  </item>

  <item>
    <title>Review: The Book of Wireless</title>
    <link>http://www.linuxsecurity.com/content/view/136167?rdf</link>
    <description>(Apr 15)  "The Book of Wireless" by John Ross is an answer to the problem of learning about wireless networking. With the wide spread use of Wireless networks today anyone with a computer should at least know the basics of wireless. Also, with the wireless ne ... </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/136167?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: Kernel memory disclosure in procfs and linprocfs</title>
    <link>http://www.linuxsecurity.com/content/view/117318?rdf</link>
    <description>(Dec 2) The implementation of the /proc/curproc/cmdline pseudofile in the procfs(5) file system on FreeBSD 4.x and 5.x, and of the /proc/self/cmdline pseudofile in the linprocfs(5) file system on FreeBSD 5.x reads a process' argument vector from the process address space.  During this operation, a pointer was dereferenced directly without the necessary validation steps being performed.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/117318?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: fetch Overflow error</title>
    <link>http://www.linuxsecurity.com/content/view/106881?rdf</link>
    <description>(Nov 18) An integer overflow condition in the processing of HTTP headers can result in a buffer overflow.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106881?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: syscons Boundary checking errors in syscons</title>
    <link>http://www.linuxsecurity.com/content/view/106592?rdf</link>
    <description>(Oct 4) The syscons CONS_SCRSHOT ioctl(2) does insufficient validation of its input arguments.  In particular, negative coordinates or large coordinates may cause unexpected behavior.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106592?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: cvs number of vulnerabilities</title>
    <link>http://www.linuxsecurity.com/content/view/106514?rdf</link>
    <description>(Sep 20) A number of vulnerabilities were discovered in CVS by Stefan Esser, Sebastian Krahmer, and Derek Price.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106514?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: kernel Improper memory access vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/106224?rdf</link>
    <description>(Jul 2) It may be possible for a local attacker to read and/or overwrite portions of kernel memory, resulting in disclosure of sensitive information or potential privilege escalation.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106224?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: kernel Excessive privilege vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/106133?rdf</link>
    <description>(Jun 8) Jailed processes can manipulate host routing tables.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106133?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: core:sys Buffer cache invalidation vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/106113?rdf</link>
    <description>(May 27) In some situations, a user with read access to a file may be able to prevent changes to that file from being committed to disk.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106113?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: cvs Heap overflow vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/106072?rdf</link>
    <description>(May 19) Malformed data can cause a heap buffer to overflow, allowing the client to overwrite arbitrary portions of the server's memory.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106072?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: crypto_heimdal Heap overflow vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/106021?rdf</link>
    <description>(May 10) A remote attacker may send a specially formatted message to k5admind, causing it to crash or possibly resulting in arbitrary code execution.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106021?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>FreeBSD: heimdal Cross-realm trust vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/106020?rdf</link>
    <description>(May 10) It is possible for the Key Distribution Center (KDC) of a realm to forge part or all of the `transited' field to fake zone trustedness.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106020?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  </channel>
</rss>
