<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>LinuxSecurity.com: OpenBSD Advisories</title>
    <link>http://www.linuxsecurity.com/</link>
    <description>The central voice for Linux and Open Source security news.</description>
    <language>en-us</language>
    <generator>generate-advisory-rss.pl (1.01)</generator>

  <item>
    <title>Study: Spammers use e-mail ID to gain legitimacy</title>
    <link>http://www.linuxsecurity.com/content/view/116271?rdf</link>
    <description>(Sep 9) With few junk e-mail filters supporting a protocol for verifying the source address of digital messages, spammers have adopted it themselves as a way to appear more legitimate, according to a report released on Wednesday. . . . ... </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/116271?rdf</guid>
    <source url='http://www.linuxsecurity.com'>Robert Lemos, CNET News.com</source>
  </item>

  <item>
    <title>Review: The Book of Wireless</title>
    <link>http://www.linuxsecurity.com/content/view/136167?rdf</link>
    <description>(Apr 15)  "The Book of Wireless" by John Ross is an answer to the problem of learning about wireless networking. With the wide spread use of Wireless networks today anyone with a computer should at least know the basics of wireless. Also, with the wireless ne ... </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/136167?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: kernel heap overflow in IPsec</title>
    <link>http://www.linuxsecurity.com/content/view/117493?rdf</link>
    <description>(Dec 14) On systems running isakmpd(8) it is possible for a local user to cause kernel memory corruption and system panic by setting ipsec(4) credentials on a socket.  Stopping isakmpd(8) does not prevent the memory corruption.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/117493?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: login_radius security flaw</title>
    <link>http://www.linuxsecurity.com/content/view/106526?rdf</link>
    <description>(Sep 21) Eilko Bos has reported that radius authentication, as implemented by login_radius(8), was not checking the shared secret used for replies sent by the radius server.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106526?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: Xpm security fix</title>
    <link>http://www.linuxsecurity.com/content/view/106524?rdf</link>
    <description>(Sep 16) Chris Evans reported several flaws (stack and integer overflows) in theXpm library code that parses image files (CAN-2004-0687, CAN-2004-0688).Some of these would be exploitable when parsing malicious image files inan application that handles XPM images, if they could escape ProPolice.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106524?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: zlib reliabilty fix</title>
    <link>http://www.linuxsecurity.com/content/view/106415?rdf</link>
    <description>(Aug 31) A bug has been found in the version of zlib included in OpenBSD 3.5(and only 3.5) that could allow an attacker to crash programs linkedwith it  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106415?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: cvs Multiple vulnerabilities</title>
    <link>http://www.linuxsecurity.com/content/view/106156?rdf</link>
    <description>(Jun 10) While no exploits are known to exist for these bugs under OpenBSD at this time, some of the bugs have proven exploitable on other operating systems.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106156?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: cvs Heap overflow vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/106096?rdf</link>
    <description>(May 25) Malignant clients can run arbitrary code on CVS servers.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106096?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: procfs Incorrect bounds checking vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/106037?rdf</link>
    <description>(May 13) Incorrect bounds checking in several procfs functions could allow an unprivileged malicious user to read arbitrary kernel memory.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106037?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: cvs Pathname validation vulnerabilities</title>
    <link>http://www.linuxsecurity.com/content/view/106016?rdf</link>
    <description>(May 10) Patches for both client and server prevent file creation and modification outside of allowed directories.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/106016?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: OpenSSL Denial of service vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/105852?rdf</link>
    <description>(Mar 17) Remote attacker can trigger a null-pointer dereference, crashing OpenSSL.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/105852?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  <item>
    <title>OpenBSD: isakmpd Denial of service vulnerability</title>
    <link>http://www.linuxsecurity.com/content/view/105848?rdf</link>
    <description>(Mar 17) An attacker can craft malformed payloads that can cause the isakmpd(8) process to stop processing requests.  </description>
    <guid isPermaLink='true'>http://www.linuxsecurity.com/content/view/105848?rdf</guid>
    <source url='http://www.linuxsecurity.com'>LinuxSecurity.com</source>
  </item>

  </channel>
</rss>
