<?xml version="1.0" encoding="iso-8859-1"?><rss version="2.0"><channel><title>LD Software</title><link>http://www.ld-software.co.uk/index.php</link><description>Bespoke Software, Web Design and Security Consulting</description><language>en-uk</language><copyright>(c) Copyright 2009 by LD Software</copyright><managingEditor>webmaster@ld-software.co.uk</managingEditor><webMaster>webmaster@ld-software.co.uk</webMaster><pubDate>Fri, 03 Jul 2009 22:59:12 +0000</pubDate><lastBuildDate>Fri, 03 Jul 2009 23:59:12 +0100</lastBuildDate><docs>http://backend.userland.com/rss</docs><generator>nukebb RSS Syndication Ported Mod by LD Software</generator><ttl>1</ttl><image><title>LD Software</title><url>http://www.ld-software.co.uk/images/logoLD.gif</url><link>http://www.ld-software.co.uk/index.php</link><description>Bespoke Software, Web Design and Security Consulting</description></image>
                                      <item>
                                        <title>Vuln: Pidgin OSCAR Protocol Web Message Denial of Service V</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4150#5221</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/bid/35530&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/bid/35530&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Vuln: Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Publish Date: &lt;/span&gt; 2009-07-03&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/bid/35530&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5221#5221</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:35 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5221#5221</guid>
                                      </item>
                                      <item>
                                        <title>Vuln: APOP Protocol Insecure MD5 Hash Weakness</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4149#5220</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/bid/23257&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/bid/23257&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Vuln: APOP Protocol Insecure MD5 Hash Weakness&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
APOP Protocol Insecure MD5 Hash Weakness&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Publish Date: &lt;/span&gt; 2009-07-03&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/bid/23257&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5220#5220</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:35 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5220#5220</guid>
                                      </item>
                                      <item>
                                        <title>Vuln: Ruby 'OCSP_basic_verify()' X.509 Certificate Verifica</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4148#5219</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/bid/33769&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/bid/33769&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Vuln: Ruby 'OCSP_basic_verify()' X.509 Certificate Verification Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
Ruby 'OCSP_basic_verify()' X.509 Certificate Verification Vulnerability&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Publish Date: &lt;/span&gt; 2009-07-03&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/bid/33769&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5219#5219</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:35 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5219#5219</guid>
                                      </item>
                                      <item>
                                        <title>Vuln: Ruby BigDecimal Library Denial Of Service Vulnerabili</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4147#5218</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/bid/35278&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/bid/35278&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Vuln: Ruby BigDecimal Library Denial Of Service Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
Ruby BigDecimal Library Denial Of Service Vulnerability&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Publish Date: &lt;/span&gt; 2009-07-03&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/bid/35278&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5218#5218</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:34 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5218#5218</guid>
                                      </item>
                                      <item>
                                        <title>Bugtraq: Multiple Flaws in Axesstel MV 410R</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4146#5217</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/archive/1/504716&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/1/504716&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Bugtraq: Multiple Flaws in Axesstel MV 410R&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
Multiple Flaws in Axesstel MV 410R&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/archive/1/504716&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5217#5217</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:34 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5217#5217</guid>
                                      </item>
                                      <item>
                                        <title>Bugtraq: [ GLSA 200907-02 ] ModSecurity: Denial of Service</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4145#5216</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/archive/1/504713&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/1/504713&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Bugtraq: [ GLSA 200907-02 ] ModSecurity: Denial of Service&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
[ GLSA 200907-02 ] ModSecurity: Denial of Service&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;&lt;table class=&quot;bodyline&quot; width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;br /&gt;&lt;tr&gt; &lt;br /&gt;	  &lt;td class=&quot;helpline&quot;&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;br /&gt;&lt;script type=&quot;text/javascript&quot; src=&quot;modules/Forums/templates/select_expand_bbcodes.js&quot;&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type=&quot;text/javascript&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;!--&lt;br /&gt;&lt;br /&gt;	var id = 'SXBB' + (1000 + Math.floor(Math.random() * 5000));&lt;br /&gt;	SXBB[id] = new _SXBB(id);&lt;br /&gt;	SXBB[id].T['select'] = 'Select';&lt;br /&gt;	SXBB[id].T['expand'] = 'Expand';&lt;br /&gt;	SXBB[id].T['contract'] = 'Contract';&lt;br /&gt;	SXBB[id].writeCmd();&lt;br /&gt;&lt;br /&gt;//--&gt;&lt;br /&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;		&lt;/span&gt;&lt;/td&gt;&lt;br /&gt;	&lt;/tr&gt;&lt;br /&gt;	&lt;tr&gt;&lt;br /&gt;	  &lt;td class=&quot;quote&quot;&gt;&lt;br /&gt;&lt;script type=&quot;text/javascript&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;!--&lt;br /&gt;&lt;br /&gt;	SXBB[id].writeDiv();&lt;br /&gt;&lt;br /&gt;//--&gt;&lt;br /&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;
Gentoo Linux Security Advisory GLSA 200907-02&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br /&gt;
&lt;a href=&quot;http://security.gentoo.org/&quot; target=&quot;_blank&quot;&gt;http://security.gentoo.org/&lt;/a&gt;&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br /&gt;
&lt;br /&gt;
Severity: Normal&lt;br /&gt;
Title: ModSecurity: Denial of Service&lt;br /&gt;
Date: July 02, 2009&lt;br /&gt;
Bugs: #262302&lt;br /&gt;
ID: 200907-02&lt;br /&gt;
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br /&gt;
&lt;br /&gt;
Synopsis&lt;br /&gt;
========&lt;br /&gt;
&lt;br /&gt;
Two vulnerabilities in ModSecurity might lead to a Denial of Service.&lt;br /&gt;
&lt;br /&gt;
Background&lt;br /&gt;
==========&lt;br /&gt;
&lt;br /&gt;
ModSecurity is a popular web application firewall for the Apache HTTP&lt;br /&gt;
server.&lt;br /&gt;
&lt;br /&gt;
Affected packages&lt;br /&gt;
=================&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------&lt;br /&gt;
Package / Vulnerable / Unaffected&lt;br /&gt;
-------------------------------------------------------------------&lt;br /&gt;
1 www-apache/mod_security &amp;lt; 2.5.9 &amp;gt;= 2.5.9&lt;br /&gt;
&lt;br /&gt;
Description&lt;br /&gt;
===========&lt;br /&gt;
&lt;br /&gt;
Multiple vulnerabilities were discovered in ModSecurity:&lt;br /&gt;
&lt;br /&gt;
* Juan Galiana Lara of ISecAuditors discovered a NULL pointer&lt;br /&gt;
dereference when processing multipart requests without a part header&lt;br /&gt;
name (CVE-2009-1902).&lt;br /&gt;
&lt;br /&gt;
* Steve Grubb of Red Hat reported that the &amp;quot;PDF XSS protection&amp;quot;&lt;br /&gt;
feature does not properly handle HTTP requests to a PDF file that do&lt;br /&gt;
not use the GET method (CVE-2009-1903).&lt;br /&gt;
&lt;br /&gt;
Impact&lt;br /&gt;
======&lt;br /&gt;
&lt;br /&gt;
A remote attacker might send requests containing specially crafted&lt;br /&gt;
multipart data or send certain requests to access a PDF file, possibly&lt;br /&gt;
resulting in a Denial of Service (crash) of the Apache HTTP daemon.&lt;br /&gt;
NOTE: The PDF XSS protection is not enabled by default.&lt;br /&gt;
&lt;br /&gt;
Workaround&lt;br /&gt;
==========&lt;br /&gt;
&lt;br /&gt;
There is no known workaround at this time.&lt;br /&gt;
&lt;br /&gt;
Resolution&lt;br /&gt;
==========&lt;br /&gt;
&lt;br /&gt;
All ModSecurity users should upgrade to the latest version:&lt;br /&gt;
&lt;br /&gt;
# emerge --sync&lt;br /&gt;
# emerge --ask --oneshot --verbose &amp;quot;&amp;gt;=www-apache/mod_security-2.5.9&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References&lt;br /&gt;
==========&lt;br /&gt;
&lt;br /&gt;
[ 1 ] CVE-2009-1902&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1902&quot; target=&quot;_blank&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1902&lt;/a&gt;&lt;br /&gt;
[ 2 ] CVE-2009-1903&lt;br /&gt;
&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1903&quot; target=&quot;_blank&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1903&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Availability&lt;br /&gt;
============&lt;br /&gt;
&lt;br /&gt;
This GLSA and any updates to it are available for viewing at&lt;br /&gt;
the Gentoo Security Website:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://security.gentoo.org/glsa/glsa-200907-02.xml&quot; target=&quot;_blank&quot;&gt;http://security.gentoo.org/glsa/glsa-200907-02.xml&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Concerns?&lt;br /&gt;
=========&lt;br /&gt;
&lt;br /&gt;
Security is a primary focus of Gentoo Linux and ensuring the&lt;br /&gt;
confidentiality and security of our users machines is of utmost&lt;br /&gt;
importance to us. Any security concerns should be addressed to&lt;br /&gt;
security (at) gentoo (dot) org [email concealed] or alternatively, you may file a bug at&lt;br /&gt;
&lt;a href=&quot;http://bugs.gentoo.org.&quot; target=&quot;_blank&quot;&gt;http://bugs.gentoo.org.&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
License&lt;br /&gt;
=======&lt;br /&gt;
&lt;br /&gt;
Copyright 2009 Gentoo Foundation, Inc; referenced text&lt;br /&gt;
belongs to its owner(s).&lt;br /&gt;
&lt;br /&gt;
The contents of this document are licensed under the&lt;br /&gt;
Creative Commons - Attribution / Share Alike license.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://creativecommons.org/licenses/by-sa/2.5&quot; target=&quot;_blank&quot;&gt;http://creativecommons.org/licenses/by-sa/2.5&lt;/a&gt;&lt;br /&gt;
-----BEGIN PGP SIGNATURE-----&lt;br /&gt;
Version: GnuPG v2.0.11 (GNU/Linux)&lt;br /&gt;
&lt;br /&gt;
iEYEABECAAYFAkpNDLgACgkQk+oqhfPAZGkRbwCeIRVMW4CjMKvWK0JVslza1vnl&lt;br /&gt;
f9QAn27cJI7xa2ynOxRhSrrDTHlngn8O&lt;br /&gt;
=tqn1&lt;br /&gt;
-----END PGP SIGNATURE-----&lt;br /&gt;
&lt;br /&gt;&lt;script type=&quot;text/javascript&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;!--&lt;br /&gt;&lt;br /&gt;	document.write('&lt;/div&gt;');&lt;br /&gt;&lt;br /&gt;//--&gt;&lt;br /&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;		&lt;/td&gt;&lt;br /&gt;	&lt;/tr&gt;&lt;br /&gt;&lt;/table&gt;&lt;br /&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/archive/1/504713&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5216#5216</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:34 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5216#5216</guid>
                                      </item>
                                      <item>
                                        <title>Bugtraq: [ GLSA 200907-01 ] libwmf: User-assisted execution</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4144#5215</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/archive/1/504712&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/1/504712&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Bugtraq: [ GLSA 200907-01 ] libwmf: User-assisted execution of arbitrary code&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
[ GLSA 200907-01 ] libwmf: User-assisted execution of arbitrary code&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/archive/1/504712&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5215#5215</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:34 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5215#5215</guid>
                                      </item>
                                      <item>
                                        <title>Bugtraq: [USN-795-1] Nagios vulnerability</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4143#5214</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/archive/1/504711&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/1/504711&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Bugtraq: [USN-795-1] Nagios vulnerability&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
[USN-795-1] Nagios vulnerability&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/archive/1/504711&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5214#5214</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:33 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5214#5214</guid>
                                      </item>
                                      <item>
                                        <title>XHTML 2 Working Group Expected to Stop Work End of 2009, W3</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4142#5213</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=9'&gt;Solereaper&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.w3.org/News/2009#item119&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.w3.org/News/2009#item119&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;XHTML 2 Working Group Expected to Stop Work End of 2009, W3C to Increase Resources on HTML 5&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
2009-07-02: Today the Director announces that when the XHTML 2 Working Group charter expires as scheduled at the end of 2009, the charter will not be renewed. By doing so, and by increasing resources in the Working Group, W3C hopes to accelerate the progress of HTML 5 and clarify W3C's position regarding the future of HTML. A FAQ answers questions about the future of deliverables of the XHTML 2 Working Group, and the status of various discussions related to HTML. Learn more about the HTML Activity. (Permalink)&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.w3.org/News/2009#item119&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5213#5213</comments>
                                        <author>Solereaper@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:32 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5213#5213</guid>
                                      </item>
                                      <item>
                                        <title>Summary of Workshop on Speaker Biometrics and VoiceXML 3.0</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4141#5212</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=9'&gt;Solereaper&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.w3.org/News/2009#item121&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.w3.org/News/2009#item121&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Summary of Workshop on Speaker Biometrics and VoiceXML 3.0 Available&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
2009-07-02: W3C has published a summary and full minutes of the Workshop on Speaker biometrics and VoiceXML 3.0, that took place in Menlo Park, California on 5-6 March. Participants from 15 organizations focused discussion on Speaker Identification and Verification (SIV) functionality within VoiceXML 3.0, and identifying and prioritizing directions for the functionality. The major &amp;quot;takeaway&amp;quot; from the Workshop was confirmation that SIV fits into the VoiceXML space and generating the &amp;quot;Menlo Park Model&amp;quot;, a SIV available VoiceXML architecture. The Working Group will continue to discuss how to include the requirements expressed at the Workshop into VoiceXML 3.0 and improve the specification. Learn more about the Voice Browser Activity. (Permalink)&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.w3.org/News/2009#item121&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5212#5212</comments>
                                        <author>Solereaper@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:32 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5212#5212</guid>
                                      </item>
                                      <item>
                                        <title>First Draft of SPARQL New Features and Rationale</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4140#5211</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=9'&gt;Solereaper&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri 03 Jul 2009, 10:29&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.w3.org/News/2009#item120&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.w3.org/News/2009#item120&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;First Draft of SPARQL New Features and Rationale&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
2009-07-02: The SPARQL Working Group has published the First Public Working Draft of SPARQL New Features and Rationale. This document provides an overview of the main new features of SPARQL and their rationale. This is an update to SPARQL adding several new features that have been agreed by the SPARQL WG. These language features were determined based on real applications and user and tool-developer experience. Learn more about the Semantic Web Activity. (Permalink)&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.w3.org/News/2009#item120&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5211#5211</comments>
                                        <author>Solereaper@ld-software.co.uk</author>
                                        <pubDate>Fri, 03 Jul 2009 11:29:32 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5211#5211</guid>
                                      </item>
                                      <item>
                                        <title>Vuln: Linux Kernel Frame Size Integer Overflow Remote Infor</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4135#5206</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Thu 02 Jul 2009, 10:34&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/bid/34654&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/bid/34654&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Vuln: Linux Kernel Frame Size Integer Overflow Remote Information Disclosure Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
Linux Kernel Frame Size Integer Overflow Remote Information Disclosure Vulnerability&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Publish Date: &lt;/span&gt; 2009-07-02&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/bid/34654&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5206#5206</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Thu, 02 Jul 2009 11:34:33 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5206#5206</guid>
                                      </item>
                                      <item>
                                        <title>Vuln: Linux Kernel 'inet6_hashtables.c' NULL Pointer Derefe</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4134#5205</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Thu 02 Jul 2009, 10:34&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/bid/34602&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/bid/34602&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Vuln: Linux Kernel 'inet6_hashtables.c' NULL Pointer Dereference Denial of Service Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
Linux Kernel 'inet6_hashtables.c' NULL Pointer Dereference Denial of Service Vulnerability&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Publish Date: &lt;/span&gt; 2009-07-02&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/bid/34602&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5205#5205</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Thu, 02 Jul 2009 11:34:33 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5205#5205</guid>
                                      </item>
                                      <item>
                                        <title>Vuln: Linux Kernel 'exit_notify()' CAP_KILL Verification Lo</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4133#5204</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Thu 02 Jul 2009, 10:34&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/bid/34405&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/bid/34405&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Vuln: Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Escalation Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Escalation Vulnerability&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Publish Date: &lt;/span&gt; 2009-07-02&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/bid/34405&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5204#5204</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Thu, 02 Jul 2009 11:34:33 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5204#5204</guid>
                                      </item>
                                      <item>
                                        <title>Bugtraq: VMSA-2009-0008 ESX Service Console update for krb5</title>
                                        <link>http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=viewtopic&amp;t=4132#5203</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://www.ld-software.co.uk/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=3'&gt;Monty&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Thu 02 Jul 2009, 10:34&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;a href=&quot;http://www.securityfocus.com/archive/1/504683&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.ld-software.co.uk/images/rssIcon.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt; &lt;span style=&quot;font-size: 16px; line-height: normal&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/1/504683&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Bugtraq: VMSA-2009-0008 ESX Service Console update for krb5&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
VMSA-2009-0008 ESX Service Console update for krb5&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com/archive/1/504683&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-style: italic&quot;&gt;Read more...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Source: &lt;/span&gt;&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;SecurityFocus Vulnerabilities&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Description: &lt;/span&gt;&lt;span style=&quot;font-size: 10px; line-height: normal&quot;&gt;SecurityFocus is the most comprehensive and trusted source of security&lt;br /&gt;
information on the Internet. We are a vendor-neutral site that provides&lt;br /&gt;
objective, timely and comprehensive security information to all members of&lt;br /&gt;
the security community, from end users, security hobbyists and network&lt;br /&gt;
administrators to security consultants, IT Managers, CIOs and CSOs.&lt;/span&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityfocus.com&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;img src=&quot;http://www.securityfocus.com/rss/SFLogo_v1.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;</description>
                                        <comments>http://www.ld-software.co.uk/viewtopic.php?p=5203#5203</comments>
                                        <author>Monty@ld-software.co.uk</author>
                                        <pubDate>Thu, 02 Jul 2009 11:34:33 +0100</pubDate>
                                        <guid isPermaLink="true">http://www.ld-software.co.uk/viewtopic.php?p=5203#5203</guid>
                                      </item></channel></rss>