<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Debian Hack Shop &#187; DSA</title>
	<atom:link href="http://itsmylife.thehackshop.com/tag/dsa/feed/" rel="self" type="application/rss+xml" />
	<link>http://itsmylife.thehackshop.com</link>
	<description>If you don&#039;t know just ask ;)</description>
	<lastBuildDate>Fri, 10 Sep 2010 05:23:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>DSA-2047 aria2 &#8211; insufficient input sanitising</title>
		<link>http://itsmylife.thehackshop.com/2010/05/21/dsa-2047-aria2-insufficient-input-sanitising/</link>
		<comments>http://itsmylife.thehackshop.com/2010/05/21/dsa-2047-aria2-insufficient-input-sanitising/#comments</comments>
		<pubDate>Fri, 21 May 2010 11:45:17 +0000</pubDate>
		<dc:creator>securityadmin</dc:creator>
				<category><![CDATA[Debian Security]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itsmylife.thehackshop.com/2010/05/21/dsa-2047-aria2-insufficient-input-sanitising/</guid>
		<description><![CDATA[A vulnerability was discovered in aria2, a download client. The &#8220;name&#8221;
attribute of the &#8220;file&#8221; element of metalink files is not properly
sanitised before using it to download files. If a user is tricked into
downloading from a specially crafted metalink file, this can be
exploited to download files to directories outside of the intended
download directory.
Read the full story: [...]]]></description>
		<wfw:commentRss>http://itsmylife.thehackshop.com/2010/05/21/dsa-2047-aria2-insufficient-input-sanitising/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1811 cups, cupsys &#8211; null ptr dereference</title>
		<link>http://itsmylife.thehackshop.com/2009/06/03/dsa-1811-cups-cupsys-null-ptr-dereference/</link>
		<comments>http://itsmylife.thehackshop.com/2009/06/03/dsa-1811-cups-cupsys-null-ptr-dereference/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 19:59:26 +0000</pubDate>
		<dc:creator>securityadmin</dc:creator>
				<category><![CDATA[Debian Security]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itsmylife.thehackshop.com/2009/06/03/dsa-1811-cups-cupsys-null-ptr-dereference/</guid>
		<description><![CDATA[Anibal Sacco discovered that cups, a general printing system for UNIX
systems, suffers from null pointer dereference because of its handling
of two consecutive IPP packets with certain tag attributes that are
treated as IPP_TAG_UNSUPPORTED tags. This allows unauthenticated attackers
to perform denial of service attacks by crashing the cups daemon.
Read the full story: DSA-1811 cups, cupsys &#8211; null [...]]]></description>
		<wfw:commentRss>http://itsmylife.thehackshop.com/2009/06/03/dsa-1811-cups-cupsys-null-ptr-dereference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1810 libapache-mod-jk &#8211; information disclosure</title>
		<link>http://itsmylife.thehackshop.com/2009/06/03/dsa-1810-libapache-mod-jk-information-disclosure/</link>
		<comments>http://itsmylife.thehackshop.com/2009/06/03/dsa-1810-libapache-mod-jk-information-disclosure/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 19:59:22 +0000</pubDate>
		<dc:creator>securityadmin</dc:creator>
				<category><![CDATA[Debian Security]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itsmylife.thehackshop.com/2009/06/03/dsa-1810-libapache-mod-jk-information-disclosure/</guid>
		<description><![CDATA[An information disclosure flaw was found in mod_jk, the Tomcat Connector
module for Apache. If a buggy client included the &#8220;Content-Length&#8221; header
without providing request body data, or if a client sent repeated
requests very quickly, one client could obtain a response intended for
another client.
Read the full story: DSA-1810 libapache-mod-jk &#8211; information disclosure: http://www.debian.org/security/2009/dsa-1810
]]></description>
		<wfw:commentRss>http://itsmylife.thehackshop.com/2009/06/03/dsa-1810-libapache-mod-jk-information-disclosure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1808 drupal6 &#8211; insufficient input sanitising</title>
		<link>http://itsmylife.thehackshop.com/2009/06/02/dsa-1808-drupal6-insufficient-input-sanitising/</link>
		<comments>http://itsmylife.thehackshop.com/2009/06/02/dsa-1808-drupal6-insufficient-input-sanitising/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 03:19:54 +0000</pubDate>
		<dc:creator>securityadmin</dc:creator>
				<category><![CDATA[Debian Security]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itsmylife.thehackshop.com/2009/06/02/dsa-1808-drupal6-insufficient-input-sanitising/</guid>
		<description><![CDATA[Markus Petrux discovered a cross-site scripting vulnerability in the
taxonomy module of drupal6, a fully-featured content management
framework. It is also possible that certain browsers using the UTF-7
encoding are vulnerable to a different cross-site scripting
vulnerability.
Read the full story: DSA-1808 drupal6 &#8211; insufficient input sanitising: http://www.debian.org/security/2009/dsa-1808
]]></description>
		<wfw:commentRss>http://itsmylife.thehackshop.com/2009/06/02/dsa-1808-drupal6-insufficient-input-sanitising/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DSA-1807 cyrus-sasl2, cyrus-sasl2-heimdal &#8211; buffer overflow</title>
		<link>http://itsmylife.thehackshop.com/2009/06/02/dsa-1807-cyrus-sasl2-cyrus-sasl2-heimdal-buffer-overflow/</link>
		<comments>http://itsmylife.thehackshop.com/2009/06/02/dsa-1807-cyrus-sasl2-cyrus-sasl2-heimdal-buffer-overflow/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 03:19:48 +0000</pubDate>
		<dc:creator>securityadmin</dc:creator>
				<category><![CDATA[Debian Security]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itsmylife.thehackshop.com/2009/06/02/dsa-1807-cyrus-sasl2-cyrus-sasl2-heimdal-buffer-overflow/</guid>
		<description><![CDATA[James Ralston discovered that the sasl_encode64() function of cyrus-sasl2,
a free library implementing the Simple Authentication and Security Layer,
suffers from a missing null termination in certain situations. This causes
several buffer overflows in situations where cyrus-sasl2 itself requires
the string to be null terminated which can lead to denial of service or
arbitrary code execution.
Read the full story: DSA-1807 [...]]]></description>
		<wfw:commentRss>http://itsmylife.thehackshop.com/2009/06/02/dsa-1807-cyrus-sasl2-cyrus-sasl2-heimdal-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
