<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tetragono</title>
	<atom:link href="http://www.tetragono.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tetragono.com</link>
	<description>Soluzioni informatiche professionali per Linux e UNIX</description>
	<lastBuildDate>Mon, 26 Jan 2009 14:43:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>DSA-1710 ganglia-monitor-core &#8211; buffer overflow</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1710-ganglia-monitor-core-buffer-overflow/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1710-ganglia-monitor-core-buffer-overflow/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:18 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1710-ganglia-monitor-core-buffer-overflow/</guid>
		<description><![CDATA[Spike Spiegel discovered a stack-based buffer overflow in gmetad, the
meta-daemon for the ganglia cluster monitoring toolkit, which could be
triggered via a request with long path names and might enable
arbitrary code execution.
]]></description>
			<content:encoded><![CDATA[<p>Spike Spiegel discovered a stack-based buffer overflow in gmetad, the<br />
meta-daemon for the ganglia cluster monitoring toolkit, which could be<br />
triggered via a request with long path names and might enable<br />
arbitrary code execution.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1710-ganglia-monitor-core-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1709 shadow &#8211; race condition</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1709-shadow-race-condition/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1709-shadow-race-condition/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:18 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1709-shadow-race-condition/</guid>
		<description><![CDATA[Paul Szabo discovered that login, the system login tool, did not
correctly handle symlinks while setting up tty permissions. If a local
attacker were able to gain control of the system utmp file, they could
cause login to change the ownership and permissions on arbitrary files,
leading to a root privilege escalation.
]]></description>
			<content:encoded><![CDATA[<p>Paul Szabo discovered that login, the system login tool, did not<br />
correctly handle symlinks while setting up tty permissions. If a local<br />
attacker were able to gain control of the system utmp file, they could<br />
cause login to change the ownership and permissions on arbitrary files,<br />
leading to a root privilege escalation.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1709-shadow-race-condition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1708 git-core &#8211; shell command injection</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1708-git-core-shell-command-injection/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1708-git-core-shell-command-injection/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:18 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1708-git-core-shell-command-injection/</guid>
		<description><![CDATA[It was discovered that gitweb, the web interface for the Git version
control system, contained several vulnerabilities:
]]></description>
			<content:encoded><![CDATA[<p>It was discovered that gitweb, the web interface for the Git version<br />
control system, contained several vulnerabilities:</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1708-git-core-shell-command-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1707 iceweasel &#8211; several vulnerabilities</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1707-iceweasel-several-vulnerabilities/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1707-iceweasel-several-vulnerabilities/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:18 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1707-iceweasel-several-vulnerabilities/</guid>
		<description><![CDATA[Several remote vulnerabilities have been discovered in the Iceweasel web
browser, an unbranded version of the Firefox browser. The Common
Vulnerabilities and Exposures project identifies the following problems:
]]></description>
			<content:encoded><![CDATA[<p>Several remote vulnerabilities have been discovered in the Iceweasel web<br />
browser, an unbranded version of the Firefox browser. The Common<br />
Vulnerabilities and Exposures project identifies the following problems:</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1707-iceweasel-several-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1706 amarok &#8211; integer overflows</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1706-amarok-integer-overflows/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1706-amarok-integer-overflows/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:18 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1706-amarok-integer-overflows/</guid>
		<description><![CDATA[Tobias Klein discovered that integer overflows in the code the Amarok
media player uses to parse Audible files may lead to the execution of
arbitrary code.
]]></description>
			<content:encoded><![CDATA[<p>Tobias Klein discovered that integer overflows in the code the Amarok<br />
media player uses to parse Audible files may lead to the execution of<br />
arbitrary code.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1706-amarok-integer-overflows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1705 netatalk &#8211; missing input sanitising</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1705-netatalk-missing-input-sanitising/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1705-netatalk-missing-input-sanitising/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:18 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1705-netatalk-missing-input-sanitising/</guid>
		<description><![CDATA[It was discovered that netatalk, an implementation of the AppleTalk
suite, is affected by a command injection vulnerability when processing
PostScript streams via papd. This could lead to the execution of
arbitrary code. Please note that this only affects installations that are
configured to use a pipe command in combination with wildcard symbols
substituted with values of the printed job.
]]></description>
			<content:encoded><![CDATA[<p>It was discovered that netatalk, an implementation of the AppleTalk<br />
suite, is affected by a command injection vulnerability when processing<br />
PostScript streams via papd. This could lead to the execution of<br />
arbitrary code. Please note that this only affects installations that are<br />
configured to use a pipe command in combination with wildcard symbols<br />
substituted with values of the printed job.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1705-netatalk-missing-input-sanitising/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1704 xulrunner &#8211; several vulnerabilities</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1704-xulrunner-several-vulnerabilities/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1704-xulrunner-several-vulnerabilities/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:17 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1704-xulrunner-several-vulnerabilities/</guid>
		<description><![CDATA[Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications. The Common Vulnerabilities and
Exposures project identifies the following problems:
]]></description>
			<content:encoded><![CDATA[<p>Several remote vulnerabilities have been discovered in Xulrunner, a<br />
runtime environment for XUL applications. The Common Vulnerabilities and<br />
Exposures project identifies the following problems:</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1704-xulrunner-several-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1703 bind9 &#8211; interpretation conflict</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1703-bind9-interpretation-conflict/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1703-bind9-interpretation-conflict/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:17 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1703-bind9-interpretation-conflict/</guid>
		<description><![CDATA[It was discovered that BIND, an implementation of the DNS protocol
suite, does not properly check the result of an OpenSSL function which
is used to verify DSA cryptographic signatures. As a result,
incorrect DNS resource records in zones protected by DNSSEC could be
accepted as genuine.
]]></description>
			<content:encoded><![CDATA[<p>It was discovered that BIND, an implementation of the DNS protocol<br />
suite, does not properly check the result of an OpenSSL function which<br />
is used to verify DSA cryptographic signatures. As a result,<br />
incorrect DNS resource records in zones protected by DNSSEC could be<br />
accepted as genuine.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1703-bind9-interpretation-conflict/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1702 ntp &#8211; interpretation conflict</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1702-ntp-interpretation-conflict/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1702-ntp-interpretation-conflict/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:17 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1702-ntp-interpretation-conflict/</guid>
		<description><![CDATA[It has been discovered that NTP, an implementation of the Network Time
Protocol, does not properly check the result of an OpenSSL function
for verifying cryptographic signatures, which may ultimately lead to
the acceptance of unauthenticated time information. (Note that
cryptographic authentication of time servers is often not enabled in
the first place.)
]]></description>
			<content:encoded><![CDATA[<p>It has been discovered that NTP, an implementation of the Network Time<br />
Protocol, does not properly check the result of an OpenSSL function<br />
for verifying cryptographic signatures, which may ultimately lead to<br />
the acceptance of unauthenticated time information. (Note that<br />
cryptographic authentication of time servers is often not enabled in<br />
the first place.)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1702-ntp-interpretation-conflict/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1701 openssl, openssl097 &#8211; interpretation conflict</title>
		<link>http://www.tetragono.com/2009/01/26/dsa-1701-openssl-openssl097-interpretation-conflict/</link>
		<comments>http://www.tetragono.com/2009/01/26/dsa-1701-openssl-openssl097-interpretation-conflict/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 14:43:17 +0000</pubDate>
		<dc:creator>Staff</dc:creator>
				<category><![CDATA[Sicurezza]]></category>

		<guid isPermaLink="false">http://www.tetragono.com/2009/01/26/dsa-1701-openssl-openssl097-interpretation-conflict/</guid>
		<description><![CDATA[It was discovered that OpenSSL does not properly verify DSA signatures
on X.509 certificates due to an API misuse, potentially leading to the
acceptance of incorrect X.509 certificates as genuine (CVE-2008-5077).
]]></description>
			<content:encoded><![CDATA[<p>It was discovered that OpenSSL does not properly verify DSA signatures<br />
on X.509 certificates due to an API misuse, potentially leading to the<br />
acceptance of incorrect X.509 certificates as genuine (<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077">CVE-2008-5077</a>).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tetragono.com/2009/01/26/dsa-1701-openssl-openssl097-interpretation-conflict/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
