<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
	<channel>
	<title>Packet Storm Security Advisories</title>
	<link>http://packetstormsecurity.org/</link>
	<description>Packet Storm Last 10 Advisories</description>
	<language>en-us</language>

<item>
	<title>USN-612-2.txt</title>
	<link>http://packetstormsecurity.org/filedesc/USN-612-2.txt.html</link>
	<description>Ubuntu Security Notice 612-2 - A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. We consider this an extremely serious vulnerability, and urge all users to act immediately to secure their systems. </description>
</item>
<item>
	<title>dsa-1571-1.txt</title>
	<link>http://packetstormsecurity.org/filedesc/dsa-1571-1.txt.html</link>
	<description>Debian Security Advisory 1571-1 - Luciano Bello discovered that the random number generator in Debian's openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package. As a result, cryptographic key material may be guessable. This is a Debian-specific vulnerability which does not affect other operating systems which are not based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on Debian systems is recreated from scratch. Furthermore, all DSA keys ever used on affected Debian systems for signing or authentication purposes should be considered compromised; the Digital Signature Algorithm relies on a secret random value used during signature generation. </description>
</item>
<item>
	<title>dsa-1575-1.txt</title>
	<link>http://packetstormsecurity.org/filedesc/dsa-1575-1.txt.html</link>
	<description>Debian Security Advisory 1575-1 - A vulnerability has been discovered in the Linux kernel that may lead to a denial of service. Alexander Viro discovered a race condition in the fcntl code that may permit local users on multi-processor systems to execute parallel code paths that are otherwise prohibited and gain re-ordered access to the descriptor table. </description>
</item>
<item>
	<title>USN-612-1.txt</title>
	<link>http://packetstormsecurity.org/filedesc/USN-612-1.txt.html</link>
	<description>Ubuntu Security Notice 612-1 - A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. We consider this an extremely serious vulnerability, and urge all users to act immediately to secure their systems. </description>
</item>
<item>
	<title>05.12.08-1.txt</title>
	<link>http://packetstormsecurity.org/filedesc/05.12.08-1.txt.html</link>
	<description>iDefense Security Advisory 05.12.08 - Local exploitation of an input validation vulnerability within version 5.1.2600.2180 of i2omgmt.sys, as included with Microsoft Corp's Windows XP operating system, could allow an attacker to execute arbitrary code in the context of the kernel. iDefense has confirmed the existence of this vulnerability in i2omgmt.sys version 5.1.2600.2180 as installed on some Windows XP SP2 systems. All other Windows releases with this driver, including previous versions, are suspected to be vulnerable. </description>
</item>
<item>
	<title>glsa-200805-13.txt</title>
	<link>http://packetstormsecurity.org/filedesc/glsa-200805-13.txt.html</link>
	<description>Gentoo Linux Security Advisory GLSA 200805-13 - Multiple issues were found in the teTeX 2 codebase that PTeX builds upon (GLSA 200709-17, GLSA 200711-26). PTeX also includes vulnerable code from the GD library (GLSA 200708-05), from Xpdf (GLSA 200709-12, GLSA 200711-22) and from T1Lib (GLSA 200710-12). Versions less than 3.1.10_p20071203 are affected. </description>
</item>
<item>
	<title>glsa-200805-12.txt</title>
	<link>http://packetstormsecurity.org/filedesc/glsa-200805-12.txt.html</link>
	<description>Gentoo Linux Security Advisory GLSA 200805-12 - Stefan Cornelius (Secunia Research) reported a boundary error within the imb_loadhdr() function in in the file source/blender/imbuf/intern/radiance_hdr.c when processing RGBE images (CVE-2008-1102). Multiple vulnerabilities involving insecure usage of temporary files have also been reported (CVE-2008-1103). Versions less than 2.43-r2 are affected. </description>
</item>
<item>
	<title>glsa-200805-11.txt</title>
	<link>http://packetstormsecurity.org/filedesc/glsa-200805-11.txt.html</link>
	<description>Gentoo Linux Security Advisory GLSA 200805-11 - Chicken includes a copy of PCRE which is vulnerable to multiple buffer overflows and memory corruption vulnerabilities (GLSA 200711-30). Versions less than 3.1.0 are affected. </description>
</item>
<item>
	<title>SSRT071403.txt</title>
	<link>http://packetstormsecurity.org/filedesc/SSRT071403.txt.html</link>
	<description>HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running ftp. The vulnerability could be exploited remotely to create a Denial of Service (DoS). The Denial of Service (DoS) affects the ftp server application only. </description>
</item>
<item>
	<title>dsa-1574-1.txt</title>
	<link>http://packetstormsecurity.org/filedesc/dsa-1574-1.txt.html</link>
	<description>Debian Security Advisory 1574-1 - Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird client.  moz_bug_r_a4  discovered that variants of CVE-2007-3738 and CVE-2007-5338 allow the execution of arbitrary code through XPCNativeWrapper.  moz_bug_r_a4  discovered that insecure handling of event handlers could lead to cross-site scripting. Boris Zbarsky, Johnny Stenback, and  moz_bug_r_a4  discovered that incorrect principal handling can lead to cross-site scripting and the execution of arbitrary code. Tom Ferris, Seth Spitzer, Martin Wargers, John Daggett and Mats Palmgren discovered crashes in the layout engine, which might allow the execution of arbitrary code.  georgi ,  tgirmann  and Igor Bukanov discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. </description>
</item></channel>
</rss>
