<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Insanity Reviews Friends &#187; Attacker</title>
	<atom:link href="http://friends.insanity-reviews.com/tag/attacker/feed/" rel="self" type="application/rss+xml" />
	<link>http://friends.insanity-reviews.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Sat, 20 Nov 2010 07:20:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>USN-920-1: Firefox 3.0 and Xulrunner vulnerabilities</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-920-1-firefox-3-0-and-xulrunner-vulnerabilities/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-920-1-firefox-3-0-and-xulrunner-vulnerabilities/#comments</comments>
		<pubDate>Sat, 10 Apr 2010 04:20:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[1 April]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Browser Engine]]></category>
		<category><![CDATA[Denial Of Service]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Ehsan]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Malicious Website]]></category>
		<category><![CDATA[Memory]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Paul Stone]]></category>
		<category><![CDATA[Privileges]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Usn]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Xulrunner]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-920-1-firefox-3-0-and-xulrunner-vulnerabilities/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2010-0174, CVE-2010-0175, CVE-2010-0176, CVE-2010-0177, CVE-2010-0178, CVE-2010-0179        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-920-1             April 09, 2010
firefox-3.0, xulrunner-1.9 vulnerabilities
CVE-2010-0174, [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2010-0174, CVE-2010-0175, CVE-2010-0176, CVE-2010-0177, CVE-2010-0178, CVE-2010-0179        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-920-1             April 09, 2010<br />
firefox-3.0, xulrunner-1.9 vulnerabilities<br />
CVE-2010-0174, CVE-2010-0175, CVE-2010-0176, CVE-2010-0177,<br />
CVE-2010-0178, CVE-2010-0179<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 8.04 LTS<br />
Ubuntu 8.10<br />
Ubuntu 9.04</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 8.04 LTS:<br />
  firefox-3.0                     3.0.19+nobinonly-0ubuntu0.8.04.1<br />
  xulrunner-1.9                   1.9.0.19+nobinonly-0ubuntu0.8.04.1</p>
<p>Ubuntu 8.10:<br />
  abrowser                        3.0.19+nobinonly-0ubuntu0.8.10.1<br />
  firefox-3.0                     3.0.19+nobinonly-0ubuntu0.8.10.1<br />
  xulrunner-1.9                   1.9.0.19+nobinonly-0ubuntu0.8.10.1</p>
<p>Ubuntu 9.04:<br />
  abrowser                        3.0.19+nobinonly-0ubuntu0.9.04.1<br />
  firefox-3.0                     3.0.19+nobinonly-0ubuntu0.9.04.1<br />
  xulrunner-1.9                   1.9.0.19+nobinonly-0ubuntu0.9.04.1</p>
<p>After a standard system upgrade you need to restart Firefox and any<br />
applications that use Xulrunner to effect the necessary changes.</p>
<p>Details follow:</p>
<p>Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered<br />
flaws in the browser engine of Firefox. If a user were tricked into viewing<br />
a malicious website, a remote attacker could cause a denial of service or<br />
possibly execute arbitrary code with the privileges of the user invoking<br />
the program. (CVE-2010-0174)</p>
<p>It was discovered that Firefox could be made to access previously freed<br />
memory. If a user were tricked into viewing a malicious website, a remote<br />
attacker could cause a denial of service or possibly execute arbitrary code<br />
with the privileges of the user invoking the program. (CVE-2010-0175,<br />
CVE-2010-0176, CVE-2010-0177)</p>
<p>Paul Stone discovered that Firefox could be made to change a mouse click<br />
into a drag and drop event. If the user could be tricked into performing<br />
this action twice on a crafted website, an attacker could execute<br />
arbitrary JavaScript with chrome privileges. (CVE-2010-0178)</p>
<p>It was discovered that the XMLHttpRequestSpy module as used by the Firebug<br />
add-on could be used to escalate privileges within the browser. If the user<br />
had the Firebug add-on installed and were tricked into viewing a malicious<br />
website, an attacker could potentially run arbitrary JavaScript.<br />
(CVE-2010-0179)
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-920-1-firefox-3-0-and-xulrunner-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-921-1: Firefox 3.5 and Xulrunner vulnerabilities</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-921-1-firefox-3-5-and-xulrunner-vulnerabilities/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-921-1-firefox-3-5-and-xulrunner-vulnerabilities/#comments</comments>
		<pubDate>Sat, 10 Apr 2010 04:20:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[1 April]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Browser Engine]]></category>
		<category><![CDATA[Denial Of Service]]></category>
		<category><![CDATA[Drag And Drop]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Ehsan]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Malicious Website]]></category>
		<category><![CDATA[Memory]]></category>
		<category><![CDATA[Mouse Click]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Privileges]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Usn]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Xulrunner]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-921-1-firefox-3-5-and-xulrunner-vulnerabilities/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2010-0173, CVE-2010-0174, CVE-2010-0175, CVE-2010-0176, CVE-2010-0177, CVE-2010-0178, CVE-2010-0179, CVE-2010-0181, CVE-2010-0182        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-921-1             April 09, [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2010-0173, CVE-2010-0174, CVE-2010-0175, CVE-2010-0176, CVE-2010-0177, CVE-2010-0178, CVE-2010-0179, CVE-2010-0181, CVE-2010-0182        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-921-1             April 09, 2010<br />
firefox-3.5, xulrunner-1.9.1 vulnerabilities<br />
CVE-2010-0173, CVE-2010-0174, CVE-2010-0175, CVE-2010-0176,<br />
CVE-2010-0177, CVE-2010-0178, CVE-2010-0179, CVE-2010-0181,<br />
CVE-2010-0182<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 9.10:<br />
  firefox-3.5                     3.5.9+nobinonly-0ubuntu0.9.10.1<br />
  xulrunner-1.9.1                 1.9.1.9+nobinonly-0ubuntu0.9.10.1</p>
<p>After a standard system upgrade you need to restart Firefox and any<br />
applications that use Xulrunner to effect the necessary changes.</p>
<p>Details follow:</p>
<p>Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered<br />
flaws in the browser engine of Firefox. If a user were tricked into viewing<br />
a malicious website, a remote attacker could cause a denial of service or<br />
possibly execute arbitrary code with the privileges of the user invoking<br />
the program. (CVE-2010-0173, CVE-2010-0174)</p>
<p>It was discovered that Firefox could be made to access previously freed<br />
memory. If a user were tricked into viewing a malicious website, a remote<br />
attacker could cause a denial of service or possibly execute arbitrary code<br />
with the privileges of the user invoking the program. (CVE-2010-0175,<br />
CVE-2010-0176, CVE-2010-0177)</p>
<p>Paul Stone discovered that Firefox could be made to change a mouse click<br />
into a drag and drop event. If the user could be tricked into performing<br />
this action twice on a crafted website, an attacker could execute<br />
arbitrary JavaScript with chrome privileges. (CVE-2010-0178)</p>
<p>It was discovered that the XMLHttpRequestSpy module as used by the Firebug<br />
add-on could be used to escalate privileges within the browser. If the user<br />
had the Firebug add-on installed and were tricked into viewing a malicious<br />
website, an attacker could potentially run arbitrary JavaScript.<br />
(CVE-2010-0179)</p>
<p>Henry Sudhof discovered that an image tag could be used as a redirect to<br />
a mailto: URL to launch an external mail handler. (CVE-2010-0181)</p>
<p>Wladimir Palant discovered that Firefox did not always perform security<br />
checks on XML content. An attacker could exploit this to bypass security<br />
policies to load certain resources. (CVE-2010-0182)
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-921-1-firefox-3-5-and-xulrunner-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-927-1: NSS vulnerability</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-927-1-nss-vulnerability/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-927-1-nss-vulnerability/#comments</comments>
		<pubDate>Sat, 10 Apr 2010 04:20:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[1 April]]></category>
		<category><![CDATA[1d]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Man In The Middle Attack]]></category>
		<category><![CDATA[Marsh]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Nss]]></category>
		<category><![CDATA[Protocols]]></category>
		<category><![CDATA[Renegotiation]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Sslv3]]></category>
		<category><![CDATA[Tls]]></category>
		<category><![CDATA[Usn]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-927-1-nss-vulnerability/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2009-3555        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-927-1             April 09, 2010
nss vulnerability
CVE-2009-3555
===========================================================
A security issue affects the following Ubuntu [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2009-3555        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-927-1             April 09, 2010<br />
nss vulnerability<br />
CVE-2009-3555<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 9.10:<br />
  libnss3-1d                      3.12.6-0ubuntu0.9.10.1</p>
<p>After a standard system upgrade you need to restart your session to effect<br />
the necessary changes.</p>
<p>Details follow:</p>
<p>Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3<br />
protocols. If an attacker could perform a man in the middle attack at the<br />
start of a TLS connection, the attacker could inject arbitrary content at<br />
the beginning of the user&#8217;s session. This update adds support for the new<br />
new renegotiation extension and will use it when the server supports it.
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-927-1-nss-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-624-2: Erlang vulnerability</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-624-2-erlang-vulnerability/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-624-2-erlang-vulnerability/#comments</comments>
		<pubDate>Sat, 10 Apr 2010 04:20:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[April]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Denial Of Service]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Erlang]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Pattern Options]]></category>
		<category><![CDATA[Pcre Library]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Usn]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-624-2-erlang-vulnerability/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2008-2371        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-624-2             April 09, 2010
erlang vulnerability
CVE-2008-2371
===========================================================
A security issue affects the following Ubuntu [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2008-2371        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-624-2             April 09, 2010<br />
erlang vulnerability<br />
CVE-2008-2371<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 9.10:<br />
  erlang-base                     1:13.b.1-dfsg-2ubuntu1.1</p>
<p>In general, a standard system upgrade is sufficient to effect the<br />
necessary changes.</p>
<p>Details follow:</p>
<p>USN-624-1 fixed a vulnerability in PCRE. This update provides the<br />
corresponding update for Erlang.</p>
<p>Original advisory details:</p>
<p> Tavis Ormandy discovered that the PCRE library did not correctly handle<br />
 certain in-pattern options.  An attacker could cause applications linked<br />
 against pcre3 to crash, leading to a denial of service.
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-624-2-erlang-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-926-1: ClamAV vulnerabilities</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-926-1-clamav-vulnerabilities/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-926-1-clamav-vulnerabilities/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 22:20:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[0098]]></category>
		<category><![CDATA[1 April]]></category>
		<category><![CDATA[Application Crash]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Cab File]]></category>
		<category><![CDATA[Cves]]></category>
		<category><![CDATA[Denial Of Service]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Usn]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-926-1-clamav-vulnerabilities/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2010-0098        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-926-1             April 08, 2010
clamav vulnerabilities
CVE-2010-0098
===========================================================
A security issue affects the following Ubuntu [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2010-0098        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-926-1             April 08, 2010<br />
clamav vulnerabilities<br />
CVE-2010-0098<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 8.10<br />
Ubuntu 9.04<br />
Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 8.10:<br />
  libclamav6                      0.95.3+dfsg-1ubuntu0.09.04~intrepid3</p>
<p>Ubuntu 9.04:<br />
  libclamav6                      0.95.3+dfsg-1ubuntu0.09.04.1</p>
<p>Ubuntu 9.10:<br />
  libclamav6                      0.95.3+dfsg-1ubuntu0.09.10.1</p>
<p>In general, a standard system upgrade is sufficient to effect the<br />
necessary changes.</p>
<p>Details follow:</p>
<p>It was discovered that ClamAV did not properly verify its input when<br />
processing CAB files. A remote attacker could send a specially crafted<br />
CAB file to evade malware detection. (CVE-2010-0098)</p>
<p>It was discovered that ClamAV did not properly verify its input when<br />
processing CAB files. A remote attacker could send a specially crafted<br />
CAB file and cause a denial of service via application crash.
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-926-1-clamav-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-925-1: MoinMoin vulnerabilities</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-925-1-moinmoin-vulnerabilities/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-925-1-moinmoin-vulnerabilities/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 22:20:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[1 April]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Moinmoin]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[Python2]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Usn]]></category>
		<category><![CDATA[Wiki]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-925-1-moinmoin-vulnerabilities/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2010-0828, CVE-2010-1238        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-925-1             April 08, 2010
moin vulnerabilities
CVE-2010-0828, CVE-2010-1238
===========================================================
A security issue affects the [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2010-0828, CVE-2010-1238        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-925-1             April 08, 2010<br />
moin vulnerabilities<br />
CVE-2010-0828, CVE-2010-1238<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 6.06 LTS<br />
Ubuntu 8.04 LTS<br />
Ubuntu 8.10<br />
Ubuntu 9.04<br />
Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 6.06 LTS:<br />
  python2.4-moinmoin              1.5.2-1ubuntu2.6</p>
<p>Ubuntu 8.04 LTS:<br />
  python-moinmoin                 1.5.8-5.1ubuntu2.4</p>
<p>Ubuntu 8.10:<br />
  python-moinmoin                 1.7.1-1ubuntu1.5</p>
<p>Ubuntu 9.04:<br />
  python-moinmoin                 1.8.2-2ubuntu2.3</p>
<p>Ubuntu 9.10:<br />
  python-moinmoin                 1.8.4-1ubuntu1.2</p>
<p>In general, a standard system upgrade is sufficient to effect the<br />
necessary changes.</p>
<p>Details follow:</p>
<p>It was discovered that MoinMoin did not properly sanitize its input when<br />
processing Despam actions, resulting in cross-site scripting (XSS)<br />
vulnerabilities. If a privileged wiki user were tricked into performing<br />
the Despam action on a page with a crafted title, a remote attacker could<br />
exploit this to execute JavaScript code. (CVE-2010-0828)</p>
<p>It was discovered that the TextCha protection in MoinMoin could be bypassed<br />
by submitting a crafted form request. This issue only affected Ubuntu 8.10.<br />
(CVE-2010-1238)
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-925-1-moinmoin-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-924-1: Kerberos vulnerabilities</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-924-1-kerberos-vulnerabilities/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-924-1-kerberos-vulnerabilities/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 16:20:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[1 April]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Denial Of Service]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Free Memory]]></category>
		<category><![CDATA[Kdb]]></category>
		<category><![CDATA[Kerberos]]></category>
		<category><![CDATA[Krb5]]></category>
		<category><![CDATA[Libraries]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Sol]]></category>
		<category><![CDATA[Traffic]]></category>
		<category><![CDATA[Usn]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-924-1-kerberos-vulnerabilities/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2007-5901, CVE-2007-5902, CVE-2007-5971, CVE-2007-5972, CVE-2010-0629        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-924-1             April 07, 2010
krb5 vulnerabilities
CVE-2007-5901, CVE-2007-5902, CVE-2007-5971, [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2007-5901, CVE-2007-5902, CVE-2007-5971, CVE-2007-5972, CVE-2010-0629        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-924-1             April 07, 2010<br />
krb5 vulnerabilities<br />
CVE-2007-5901, CVE-2007-5902, CVE-2007-5971, CVE-2007-5972,<br />
CVE-2010-0629<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 8.04 LTS<br />
Ubuntu 8.10<br />
Ubuntu 9.04</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 8.04 LTS:<br />
  krb5-kdc                        1.6.dfsg.3~beta1-2ubuntu1.4<br />
  libkrb53                        1.6.dfsg.3~beta1-2ubuntu1.4</p>
<p>Ubuntu 8.10:<br />
  krb5-kdc                        1.6.dfsg.4~beta1-3ubuntu0.4</p>
<p>Ubuntu 9.04:<br />
  krb5-kdc                        1.6.dfsg.4~beta1-5ubuntu2.3<br />
  libkrb53                        1.6.dfsg.4~beta1-5ubuntu2.3</p>
<p>In general, a standard system upgrade is sufficient to effect the<br />
necessary changes.</p>
<p>Details follow:</p>
<p>Sol Jerome discovered that the Kerberos kadmind service did not correctly<br />
free memory.  An unauthenticated remote attacker could send specially<br />
crafted traffic to crash the kadmind process, leading to a denial of<br />
service. (CVE-2010-0629)</p>
<p>It was discovered that Kerberos did not correctly free memory in<br />
the GSSAPI library.  If a remote attacker were able to manipulate an<br />
application using GSSAPI carefully, the service could crash, leading to<br />
a denial of service.  (Ubuntu 8.10 was not affected.)  (CVE-2007-5901,<br />
CVE-2007-5971)</p>
<p>It was discovered that Kerberos did not correctly free memory in the<br />
GSSAPI and kdb libraries.  If a remote attacker were able to manipulate<br />
an application using these libraries carefully, the service could crash,<br />
leading to a denial of service.  (Only Ubuntu 8.04 LTS was affected.)<br />
(CVE-2007-5902, CVE-2007-5972)
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-924-1-kerberos-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-923-1: OpenJDK vulnerabilities</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-923-1-openjdk-vulnerabilities/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-923-1-openjdk-vulnerabilities/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 16:20:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[1 April]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Constraint]]></category>
		<category><![CDATA[Drag Drop]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Java Applications]]></category>
		<category><![CDATA[Lib]]></category>
		<category><![CDATA[Man In The Middle Attack]]></category>
		<category><![CDATA[Marsh]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Openjdk]]></category>
		<category><![CDATA[Protocols]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Sensitive Objects]]></category>
		<category><![CDATA[Sslv3]]></category>
		<category><![CDATA[Tls]]></category>
		<category><![CDATA[Usn]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-923-1-openjdk-vulnerabilities/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2009-3555, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085, CVE-2010-0088, CVE-2010-0091, CVE-2010-0092, CVE-2010-0093, CVE-2010-0094, CVE-2010-0095, CVE-2010-0837, CVE-2010-0838, CVE-2010-0840, CVE-2010-0845, CVE-2010-0847, CVE-2010-0848        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-923-1        [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2009-3555, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085, CVE-2010-0088, CVE-2010-0091, CVE-2010-0092, CVE-2010-0093, CVE-2010-0094, CVE-2010-0095, CVE-2010-0837, CVE-2010-0838, CVE-2010-0840, CVE-2010-0845, CVE-2010-0847, CVE-2010-0848        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-923-1             April 07, 2010<br />
openjdk-6 vulnerabilities<br />
CVE-2009-3555, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085,<br />
CVE-2010-0088, CVE-2010-0091, CVE-2010-0092, CVE-2010-0093,<br />
CVE-2010-0094, CVE-2010-0095, CVE-2010-0837, CVE-2010-0838,<br />
CVE-2010-0840, CVE-2010-0845, CVE-2010-0847, CVE-2010-0848<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 8.04 LTS<br />
Ubuntu 8.10<br />
Ubuntu 9.04<br />
Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 8.04 LTS:<br />
  openjdk-6-jre                   6b11-2ubuntu2.2<br />
  openjdk-6-jre-lib               6b11-2ubuntu2.2</p>
<p>Ubuntu 8.10:<br />
  openjdk-6-jre                   6b12-0ubuntu6.7<br />
  openjdk-6-jre-lib               6b12-0ubuntu6.7</p>
<p>Ubuntu 9.04:<br />
  openjdk-6-jre                   6b14-1.4.1-0ubuntu13<br />
  openjdk-6-jre-lib               6b14-1.4.1-0ubuntu13</p>
<p>Ubuntu 9.10:<br />
  openjdk-6-jre                   6b16-1.6.1-3ubuntu3<br />
  openjdk-6-jre-lib               6b16-1.6.1-3ubuntu3</p>
<p>After a standard system upgrade you need to restart all Java applications<br />
to effect the necessary changes.</p>
<p>Details follow:</p>
<p>Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3<br />
protocols. If an attacker could perform a man in the middle attack at the<br />
start of a TLS connection, the attacker could inject arbitrary content<br />
at the beginning of the user&#8217;s session.  (CVE-2009-3555)</p>
<p>It was discovered that Loader-constraint table, Policy/PolicyFile,<br />
Inflater/Deflater, drag/drop access, and deserialization did not correctly<br />
handle certain sensitive objects. If a user were tricked into running a<br />
specially crafted applet, private information could be leaked to a remote<br />
attacker, leading to a loss of privacy.  (CVE-2010-0082, CVE-2010-0084,<br />
CVE-2010-0085, CVE-2010-0088, CVE-2010-0091, CVE-2010-0094)</p>
<p>It was discovered that AtomicReferenceArray, System.arraycopy,<br />
InetAddress, and HashAttributeSet did not correctly handle certain<br />
situations.  If a remote attacker could trigger specific error conditions,<br />
a Java application could crash, leading to a denial of service.<br />
(CVE-2010-0092, CVE-2010-0093, CVE-2010-0095, CVE-2010-0845)</p>
<p>It was discovered that Pack200, CMM readMabCurveData, ImagingLib, and<br />
the AWT library did not correctly check buffer lengths.  If a user or<br />
automated system were tricked into handling specially crafted JAR files or<br />
images, a remote attacker could crash the Java application or possibly<br />
gain user privileges (CVE-2010-0837, CVE-2010-0838, CVE-2010-0847,<br />
CVE-2010-0848).</p>
<p>It was discovered that applets did not correctly handle certain trust<br />
chains.  If a user were tricked into running a specially crafted applet,<br />
a remote attacker could possibly run untrusted code with user privileges.<br />
(CVE-2010-0840)
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-923-1-openjdk-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-922-1: libnss-db vulnerability</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-922-1-libnss-db-vulnerability/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-922-1-libnss-db-vulnerability/#comments</comments>
		<pubDate>Thu, 01 Apr 2010 10:20:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Arbitrary Files]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Database Environment]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Escalation]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Privilege]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Stephane]]></category>
		<category><![CDATA[Usn]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-922-1-libnss-db-vulnerability/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2010-0826        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-922-1             March 31, 2010
libnss-db vulnerability
CVE-2010-0826
===========================================================
A security issue affects the following Ubuntu [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2010-0826        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-922-1             March 31, 2010<br />
libnss-db vulnerability<br />
CVE-2010-0826<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 8.04 LTS<br />
Ubuntu 8.10<br />
Ubuntu 9.04<br />
Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 8.04 LTS:<br />
  libnss-db                       2.2.3pre1-3ubuntu1.8.04.2</p>
<p>Ubuntu 8.10:<br />
  libnss-db                       2.2.3pre1-3ubuntu1.8.10.2</p>
<p>Ubuntu 9.04:<br />
  libnss-db                       2.2.3pre1-3ubuntu3.9.04.2</p>
<p>Ubuntu 9.10:<br />
  libnss-db                       2.2.3pre1-3ubuntu3.9.10.2</p>
<p>In general, a standard system upgrade is sufficient to effect the<br />
necessary changes.</p>
<p>Details follow:</p>
<p>Stephane Chazelas discovered that libnss-db did not correctly set up a<br />
database environment.  A local attacker could exploit this to read the<br />
first line of arbitrary files, leading to a loss of privacy and possibly<br />
privilege escalation.
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-922-1-libnss-db-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-919-1: Emacs vulnerability</title>
		<link>http://friends.insanity-reviews.com/2010/03/usn-919-1-emacs-vulnerability/</link>
		<comments>http://friends.insanity-reviews.com/2010/03/usn-919-1-emacs-vulnerability/#comments</comments>
		<pubDate>Wed, 31 Mar 2010 04:20:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Emacs]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[File Permissions]]></category>
		<category><![CDATA[Group Mail]]></category>
		<category><![CDATA[Group Writable]]></category>
		<category><![CDATA[Mail Directory]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Rosenberg]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Usn]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/03/usn-919-1-emacs-vulnerability/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2010-0825        



Description:&#160;


===========================================================
Ubuntu Security Notice USN-919-1             March 29, 2010
emacs22, emacs23 vulnerability
CVE-2010-0825
===========================================================
A security issue affects the following [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2010-0825        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>===========================================================<br />
Ubuntu Security Notice USN-919-1             March 29, 2010<br />
emacs22, emacs23 vulnerability<br />
CVE-2010-0825<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 8.04 LTS<br />
Ubuntu 8.10<br />
Ubuntu 9.04<br />
Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 8.04 LTS:<br />
  emacs22-bin-common              22.1-0ubuntu10.2</p>
<p>Ubuntu 8.10:<br />
  emacs22-bin-common              22.2-0ubuntu2.8.10.1</p>
<p>Ubuntu 9.04:<br />
  emacs22-bin-common              22.2-0ubuntu2.9.04.1</p>
<p>Ubuntu 9.10:<br />
  emacs22-bin-common              22.2-0ubuntu6.2<br />
  emacs23-bin-common              23.1+1-4ubuntu3.2</p>
<p>In general, a standard system upgrade is sufficient to effect the<br />
necessary changes.</p>
<p>Details follow:</p>
<p>Dan Rosenberg discovered that the email helper in Emacs did not correctly<br />
check file permissions.  A local attacker could perform a symlink race<br />
to read or append to another user&#8217;s mailbox if it was stored under a<br />
group-writable group-&#8221;mail&#8221; directory.
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/03/usn-919-1-emacs-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

