<?xml version="1.0" encoding="iso-8859-1"?> 
<rss version="2.0"> 
<channel> 
<title>AlienVault NVT Feed</title> 
<link>http://www.alienvault.com/free_nessus_feed.php</link>        
<description>AlienVault nessus feed updates. Sync using the updater.</description>
<copyright>(c) 2008, AlienVault. All rights reserved.</copyright> 

<item><title>debian_DSA-1683.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1683]DSA-1683-1 streamripper -- buffer overflow"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000829"
<br/>Script CVE: "CVE-2007-4337", "CVE-2008-4829"
<br/>Description:	Multiple buffer overflows involving HTTP header and playlist<br/>
parsing have been discovered in streamripper (CVE-2007-4337,<br/>
CVE-2008-4829).For the stable distribution (etch), these problems have been<br/>
fixed in version 1.61.27-1+etch1.For the unstable distribution (sid) and the testing distribution<br/>
(lenny), these problems have been fixed in version 1.63.5-2.We recommend that you upgrade your streamripper package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1683.en.htmlRisk factor : High<br/>

<br/>]]></description>
<pubDate>Dec 10 10:25 GMT</pubDate></item>
<item><title>debian_DSA-1681.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1681]DSA-1681-1 linux-2.6.24 -- denial of service/privilege escalation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000828"
<br/>Script CVE: "CVE-2008-3528", "CVE-2008-4554", "CVE-2008-4576", "CVE-2008-4618", "CVE-2008-4933", "CVE-2008-4934", "CVE-2008-5025", "CVE-2008-5029", "CVE-2008-5134", "CVE-2008-5182", "CVE-2008-5300"
<br/>Description:	Several vulnerabilities have been discovered in the Linux kernel<br/>
that may lead to a denial of service or privilege escalation. The<br/>
Common Vulnerabilities and Exposures project identifies the<br/>
following problems:For the stable distribution (etch), these problems have been<br/>
fixed in version 2.6.24-6~etchnhalf.7.We recommend that you upgrade your linux-2.6.24 packages.<br/>
Solution : http://www.debian.org/security/2008/dsa-1681.en.htmlRisk factor : High<br/>

<br/>]]></description>
<pubDate>Dec 10 10:24 GMT</pubDate></item>
<item><title>debian_DSA-1680.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1680]DSA-1680-1 clamav -- buffer overflow, stack consumption"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000827"
<br/>Script CVE: "CVE-2008-5050", "CVE-2008-5314"
<br/>Description:	Moritz Jodeit discovered that ClamAV, an anti-virus solution,<br/>
suffers from an off-by-one-error in its VBA project file<br/>
processing, leading to a heap-based buffer overflow and potentially<br/>
arbitrary code execution (CVE-2008-5050).Ilja van Sprundel discovered that ClamAV contains a denial of<br/>
service condition in its JPEG file processing because it does not<br/>
limit the recursion depth when processing JPEG thumbnails (CVE-2008-5314).For the stable distribution (etch), these problems have been ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:24 GMT</pubDate></item>
<item><title>debian_DSA-1679.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1679]DSA-1679-1 awstats -- cross-site scripting"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000826"
<br/>Script CVE: "CVE-2008-3714"
<br/>Description:	Morgan Todd discovered a cross-site scripting vulnerability in<br/>
awstats, a log file analyzer, involving the "config" request<br/>
parameter (and possibly others; CVE-2008-3714).For the stable distribution (etch), this problem has been fixed<br/>
in version 6.5+dfsg-1+etch1.The unstable (sid) and testing (lenny) distribution will be<br/>
fixed soon.We recommend that you upgrade your awstats package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1679.en.htmlRisk factor : High<br/>

<br/>]]></description>
<pubDate>Dec 10 10:24 GMT</pubDate></item>
<item><title>debian_DSA-1677.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1677]DSA-1677-1 cupsys -- integer overflow"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000824"
<br/>Script CVE: "CVE-2008-5286"
<br/>Description:	An integer overflow has been discovered in the image validation<br/>
code of cupsys, the Common UNIX Printing System. An attacker could<br/>
trigger this bug by supplying a malicious graphic that could lead<br/>
to the execution of arbitrary code.For the stable distribution (etch) this problem has been fixed<br/>
in version 1.2.7-4etch6.For testing distribution (lenny) this issue will be fixed<br/>
soon.For the unstable distribution (sid) this problem has been fixed<br/>
in version 1.3.8-1lenny4.We recommend that you upgrade your cupsys packages. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:24 GMT</pubDate></item>
<item><title>debian_DSA-1676.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1676]DSA-1676-1 flamethrower -- insecure temp file generation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000823"
<br/>Script CVE: "CVE-2008-5141"
<br/>Description:	Dmitry E. Oboukhov discovered that flamethrower creates<br/>
predictable temporary filenames, which may lead to a local denial<br/>
of service through a symlink attack.For the stable distribution (etch), this problem has been fixed<br/>
in version 0.1.8-1+etch1.For the unstable distribution (sid), this problem has been fixed<br/>
in version 0.1.8-2.We recommend that you upgrade your flamethrower package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1676.en.htmlRisk factor : High<br/>

<br/>]]></description>
<pubDate>Dec 10 10:23 GMT</pubDate></item>
<item><title>debian_DSA-1675.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1675]DSA-1675-1 phpmyadmin -- insufficient input sanitising"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000822"
<br/>Script CVE: "CVE-2008-4326"
<br/>Description:	Masako Oono discovered that phpMyAdmin, a web-based<br/>
administration interface for MySQL, insufficiently sanitises input<br/>
allowing a remote attacker to gather sensitive data through cross<br/>
site scripting, provided that the user uses the Internet Explorer<br/>
web browser.This update also fixes a regression introduced in DSA 1641, that<br/>
broke changing of the language and encoding in the login<br/>
screen.For the stable distribution (etch), these problems have been<br/>
fixed in version 4:2.9.1.1-9.For the unstable distribution (sid), these problems have been ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:23 GMT</pubDate></item>
<item><title>debian_DSA-1674.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1674]DSA-1674-1 jailer -- insecure temp file generation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000821"
<br/>Script CVE: "CVE-2008-5139"
<br/>Description:	Javier Fernandez-Sanguino Pena discovered that updatejail, a<br/>
component of the chroot maintenance tool Jailer, creates a<br/>
predictable temporary file name, which may lead to local denial of<br/>
service through a symlink attack.For the stable distribution (etch), this problem has been fixed<br/>
in version 0.4-9+etch1.For the upcoming stable distribution (lenny) and the unstable<br/>
distribution (sid), this problem has been fixed in version<br/>
0.4-10.We recommend that you upgrade your jailer package. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:23 GMT</pubDate></item>
<item><title>debian_DSA-1673.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1673]DSA-1673-1 wireshark -- several vulnerabilities"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000820"
<br/>Script CVE: "CVE-2008-3137", "CVE-2008-3138", "CVE-2008-3141", "CVE-2008-3145", "CVE-2008-3933", "CVE-2008-4683", "CVE-2008-4684", "CVE-2008-4685"
<br/>Description:	Several remote vulnerabilities have been discovered in network<br/>
traffic analyzer Wireshark. The Common Vulnerabilities and<br/>
Exposures project identifies the following problems:For the stable distribution (etch), these problems have been<br/>
fixed in version 0.99.4-5.etch.3.For the upcoming stable distribution (lenny), these problems<br/>
have been fixed in version 1.0.2-3+lenny2.For the unstable distribution (sid), these problems will be<br/>
fixed soon.We recommend that you upgrade your wireshark packages. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:12 GMT</pubDate></item>
<item><title>debian_DSA-1672.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1672]DSA-1672-1 imlib2 -- buffer overflow"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000819"
<br/>Script CVE: "CVE-2008-5187"
<br/>Description:	Julien Danjou and Peter De Wachter discovered that a buffer<br/>
overflow in the XPM loader of Imlib2, a powerful image loading and<br/>
rendering library, might lead to arbitrary code execution.For the stable distribution (etch), this problem has been fixed<br/>
in version 1.3.0.0debian1-4+etch2.For the upcoming stable distribution (lenny) and the unstable<br/>
distribution (sid), this problem has been fixed in version<br/>
1.4.0-1.2.We recommend that you upgrade your imlib2 packages.<br/>
Solution : http://www.debian.org/security/2008/dsa-1672.en.html ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:12 GMT</pubDate></item>
<item><title>debian_DSA-1671.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1671]DSA-1671-1 iceweasel -- several vulnerabilities"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000818"
<br/>Script CVE: "CVE-2008-0017", "CVE-2008-4582", "CVE-2008-5012", "CVE-2008-5013", "CVE-2008-5014", "CVE-2008-5017", "CVE-2008-5018", "CVE-2008-5021", "CVE-2008-5022", "CVE-2008-5023", "CVE-2008-5024"
<br/>Description:	Several remote vulnerabilities have been discovered in the<br/>
Iceweasel webbrowser, an unbranded version of the Firefox browser.<br/>
The Common Vulnerabilities and Exposures project identifies the<br/>
following problems:For the stable distribution (etch), these problems have been<br/>
fixed in version 2.0.0.18-0etch1.For the upcoming stable distribution (lenny) and the unstable<br/>
distribution (sid), these problems have been fixed in version<br/>
3.0.4-1 of iceweasel and version 1.9.0.4-1 of xulrunner. Packages ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:12 GMT</pubDate></item>
<item><title>debian_DSA-1670.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1670]DSA-1670-1 enscript -- buffer overflows"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000817"
<br/>Script CVE: "CVE-2008-3863", "CVE-2008-4306"
<br/>Description:	Several vulnerabilities have been discovered in Enscript, a<br/>
converter from ASCII text to Postscript, HTML or RTF. The Common<br/>
Vulnerabilities and Exposures project identifies the following<br/>
problems:For the stable distribution (etch), these problems have been<br/>
fixed in version 1.6.4-11.1.For the upcoming stable distribution (lenny) and the unstable<br/>
distribution (sid), these problems have been fixed in version<br/>
1.6.4-13.We recommend that you upgrade your enscript package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1670.en.html ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:08 GMT</pubDate></item>
<item><title>debian_DSA-1669.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1669]DSA-1669-1 xulrunner -- several vulnerabilities"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000816"
<br/>Script CVE: "CVE-2008-0016", "CVE-2008-3835", "CVE-2008-3836", "CVE-2008-3837", "CVE-2008-4058", "CVE-2008-4059", "CVE-2008-4060", "CVE-2008-4061", "CVE-2008-4062", "CVE-2008-4065", "CVE-2008-4066", "CVE-2008-4067", "CVE-2008-4068", "CVE-2008-4069", "CVE-2008-4582", "CVE-2008-5012", "CVE-2008-5013", "CVE-2008-5014", "CVE-2008-5017", "CVE-2008-5018", "CVE-2008-0017", "CVE-2008-5021", "CVE-2008-5022", "CVE-2008-5023", "CVE-2008-5024"
<br/>Description:	Several remote vulnerabilities have been discovered in<br/>
Xulrunner, a runtime environment for XUL applications. The Common<br/>
Vulnerabilities and Exposures project identifies the following<br/>
problems:For the stable distribution (etch), these problems have been<br/>
fixed in version 1.8.0.15~pre080614h-0etch1. Packages for mips will<br/>
be provided later.For the upcoming stable distribution (lenny) and the unstable<br/>
distribution (sid), these problems have been fixed in version<br/>
1.9.0.4-1.We recommend that you upgrade your xulrunner packages. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:08 GMT</pubDate></item>
<item><title>debian_DSA-1668.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1668]DSA-1668-1 hf -- programming error"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000815"
<br/>Script CVE: "CVE-2008-2378"
<br/>Description:	Steve Kemp discovered that hf, an amateur-radio protocol suite<br/>
using a soundcard as a modem, insecurely tried to execute an<br/>
external command which could lead to the elevation of privileges<br/>
for local users.For the stable distribution (etch), this problem has been fixed<br/>
in version 0.7.3-4etch1.For the unstable distribution (sid), this problem has been fixed<br/>
in version 0.8-8.1.We recommend that you upgrade your hf package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1668.en.html ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:07 GMT</pubDate></item>
<item><title>debian_DSA-1667.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1667]DSA-1667-1 python2.4 -- several vulnerabilities"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000814"
<br/>Script CVE: "CVE-2008-2315", "CVE-2008-3142", "CVE-2008-3143", "CVE-2008-3144"
<br/>Description:	Several vulnerabilities have been discovered in the interpreter<br/>
for the Python language. The Common Vulnerabilities and Exposures<br/>
project identifies the following problems:For the stable distribution (etch), these problems have been<br/>
fixed in version 2.4.4-3+etch2.For the unstable distribution (sid) and the upcoming stable<br/>
distribution (lenny), these problems have been fixed in version<br/>
2.4.5-5.We recommend that you upgrade your python2.4 packages.<br/>
Solution : http://www.debian.org/security/2008/dsa-1667.en.html ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Dec 10 10:07 GMT</pubDate></item>
<item><title>debian_DSA-1666.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1666]DSA-1666-1 libxml2 -- several vulnerabilities"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000813"
<br/>Script CVE: "CVE-2008-4225", "CVE-2008-4226"
<br/>Description:	Several vulnerabilities have been discovered in the GNOME XML<br/>
library. The Common Vulnerabilities and Exposures project<br/>
identifies the following problems:For the stable distribution (etch), these problems have been<br/>
fixed in version 2.6.27.dfsg-6.For the upcoming stable distribution (lenny) and the unstable<br/>
distribution (sid), these problems will be fixed soon.We recommend that you upgrade your libxml2 packages.<br/>
Solution : http://www.debian.org/security/2008/dsa-1666.en.htmlRisk factor : High<br/>

<br/>]]></description>
<pubDate>Nov 18 09:30 GMT</pubDate></item>
<item><title>debian_DSA-1665.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1665]DSA-1665-1 libcdaudio -- heap overflow"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000812"
<br/>Script CVE: "CVE-2008-5030"
<br/>Description:	It was discovered that a heap overflow in the CDDB retrieval<br/>
code of libcdaudio, a library for controlling a CD-ROM when playing<br/>
audio CDs, may result in the execution of arbitrary code.For the stable distribution (etch), this problem has been fixed<br/>
in version 0.99.12p2-2+etch1. A package for hppa will be provided<br/>
later.For the upcoming stable distribution (lenny) and the unstable<br/>
distribution (sid), this problem has been fixed in version<br/>
0.99.12p2-7.We recommend that you upgrade your libcdaudio packages. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Nov 18 09:30 GMT</pubDate></item>
<item><title>debian_DSA-1664.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1664]DSA-1664-1 ekg -- missing input sanitising"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000811"
<br/>Script CVE: "CVE-2008-4776"
<br/>Description:	It was discovered that ekg, a console Gadu Gadu client performs<br/>
insufficient input sanitising in the code to parse contact<br/>
descriptions, which may result in denial of service.For the stable distribution (etch), this problem has been fixed<br/>
in version 1:1.7~rc2-1etch2.For the unstable distribution (sid) and the upcoming stable<br/>
distribution (lenny), this problem has been fixed in version<br/>
1:1.8~rc1-2 of libgadu.We recommend that you upgrade your ekg package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1664.en.html ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Nov 18 09:30 GMT</pubDate></item>
<item><title>debian_DSA-1663.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1663]DSA-1663-1 net-snmp -- several vulnerabilities"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000810"
<br/>Script CVE: "CVE-2008-0960", "CVE-2008-2292", "CVE-2008-4309"
<br/>Description:	Several vulnerabilities have been discovered in NET SNMP, a<br/>
suite of Simple Network Management Protocol applications. The<br/>
Common Vulnerabilities and Exposures project identifies the<br/>
following problems:For the stable distribution (etch), these problems has been<br/>
fixed in version 5.2.3-7etch4.For the testing distribution (lenny) and unstable distribution<br/>
(sid) these problems have been fixed in version 5.4.1~dfsg-11.We recommend that you upgrade your net-snmp package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1663.en.html ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Nov 18 09:30 GMT</pubDate></item>
<item><title>debian_DSA-1662.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1662]DSA-1662-1 mysql-dfsg-5.0 -- authorization bypass"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000809"
<br/>Script CVE: "CVE-2008-4098"
<br/>Description:	A symlink traversal vulnerability was discovered in MySQL, a<br/>
relational database server. The weakness could permit an attacker<br/>
having both CREATE TABLE access to a database and the ability to<br/>
execute shell commands on the database server to bypass MySQL<br/>
access controls, enabling them to write to tables in databases to<br/>
which they would not ordinarily have access.The Common Vulnerabilities and Exposures project identifies this<br/>
vulnerability as CVE-2008-4098.<br/>
Note that a closely aligned issue, identified as CVE-2008-4097, ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Nov 18 09:30 GMT</pubDate></item>
<item><title>secpod_trendmicro_officescan_cgiparsing_bof_vuln_900164.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:      "Trend Micro OfficeScan CGI Parsing Buffer Overflow Vulnerability"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.900164"
<br/>Script BID: 31859
<br/>Script CVE: "CVE-2008-3862"
<br/>Description:	<br/>
  Overview: This host is installed with Trend Micro OfficeScan and is prone to<br/>
  stack based buffer overflow vulnerability.<br/>
<br/>
  The vulnerability is caused due to boundary error in the CGI modules when<br/>
  processing specially crafted HTTP request.<br/>
<br/>
  Impact:<br/>
  Allows an attacker to execute arbitrary code, which may facilitate a complete<br/>
  compromise of vulnerable system.<br/>
<br/>
  Impact Level: Application<br/>
<br/>
  Affected Software/OS:<br/>
  TrendMicro OfficeScan Corporate Edition 7.3 Build prior to 1374. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 30 10:42 GMT</pubDate></item>
<item><title>secpod_realvnc_remote_code_exe_vuln_win_900162.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:      "RealVNC VNC Viewer Remote Code Execution Vulnerability (Win
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.900162"
<br/>Script BID: 31832
<br/>Description:	<br/>
  Overview: This host has RealVNC VNC Viewer installed and is prone to security <br/>
  vulnerability.<br/>
<br/>
  The flaw is caused due to error in 'CMsgReader::readRect()' function in<br/>
  common/rfb/CMsgReader.cxx processing encoding types, and is exploited by<br/>
  sending specially crafted messages to the application.<br/>
<br/>
  Impact:<br/>
  Successful exploitation will allow execution of arbitrary code when user<br/>
  connects to a malicious server.<br/>
<br/>
  Impact Level: Application ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 30 10:41 GMT</pubDate></item>
<item><title>secpod_realvnc_remote_code_exe_vuln_lin_900163.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:      "RealVNC VNC Viewer Remote Code Execution Vulnerability (Linux
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.900163"
<br/>Script BID: 31832
<br/>Description:	<br/>
  Overview: This host has RealVNC VNC Viewer installed and is prone to security<br/>
  vulnerability.<br/>
<br/>
  The flaw is caused due to error in 'CMsgReader::readRect()' function in<br/>
  common/rfb/CMsgReader.cxx processing encoding types, and is exploited by<br/>
  sending specially crafted messages to the application.<br/>
<br/>
  Impact:<br/>
  Successful exploitation will allow execution of arbitrary code when user<br/>
  connects to a malicious server.<br/>
<br/>
  Impact Level: Application ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 30 10:41 GMT</pubDate></item>
<item><title>debian_DSA-1661.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1661]DSA-1661-1 openoffice.org -- several vulnerabilities"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000808"
<br/>Script CVE: "CVE-2008-2237", "CVE-2008-2238"
<br/>Description:	Several vulnerabilities have been discovered in the<br/>
OpenOffice.org office suite:For the stable distribution (etch) these problems have been<br/>
fixed in version 2.0.4.dfsg.2-7etch6.For the unstable distribution (sid) these problems have been<br/>
fixed in version 2.4.1-12.For the experimental distribution these problems have been fixed<br/>
in version 3.0.0~rc3-1.We recommend that you upgrade your OpenOffice.org package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1661.en.htmlRisk factor : High<br/>

<br/>]]></description>
<pubDate>Oct 30 10:38 GMT</pubDate></item>
<item><title>debian_DSA-1660.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1660]DSA-1660-1 clamav -- null pointer dereference, resource exhaustation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000807"
<br/>Script CVE: "CVE-2008-3912", "CVE-2008-3913", "CVE-2008-3914"
<br/>Description:	Several denial-of-service vulnerabilities have been discovered<br/>
in the ClamAV anti-virus toolkit:Insufficient checking for out-of-memory conditions results in<br/>
null pointer dereferences (CVE-2008-3912).Incorrect error handling logic leads to memory leaks (CVE-2008-3913)<br/>
and file descriptor leaks (CVE-2008-3914).For the stable distribution (etch), these problems have been<br/>
fixed in version 0.90.1dfsg-4etch15.For the unstable distribution (sid) and the testing distribution<br/>
(lenny), these problems have been fixed in version 0.94.dfsg-1.We recommend that you upgrade your clamav package. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 27 10:06 GMT</pubDate></item>
<item><title>debian_DSA-1659.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1659]DSA-1659-1 libspf2 -- buffer overflow"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000806"
<br/>Script CVE: "CVE-2008-2469"
<br/>Description:	Dan Kaminsky discovered that libspf2, an implementation of the<br/>
Sender Policy Framework (SPF) used by mail servers for mail<br/>
filtering, handles malformed TXT records incorrectly, leading to a<br/>
buffer overflow condition (CVE-2008-2469).Note that the SPF configuration template in Debians Exim<br/>
configuration recommends to use libmail-spf-query-perl, which does<br/>
not suffer from this issue.For the stable distribution (etch), this problem has been fixed<br/>
in version 1.2.5-4+etch1.For the testing distribution (lenny), this problem has been ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 27 10:06 GMT</pubDate></item>
<item><title>debian_DSA-1658.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1658]DSA-1658-1 dbus -- programming error"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000805"
<br/>Script CVE: "CVE-2008-3834"
<br/>Description:	Colin Walters discovered that the dbus_signature_validate<br/>
function in dbus, a simple interprocess messaging system, is prone<br/>
to a denial of service attack.For the stable distribution (etch), this problem has been fixed<br/>
in version 1.0.2-1+etch2.For the testing distribution (lenny) and unstable distribution<br/>
(sid) this problem will be fixed soon.We recommend that you upgrade your dbus package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1658.en.htmlRisk factor : High<br/>

<br/>]]></description>
<pubDate>Oct 27 10:06 GMT</pubDate></item>
<item><title>debian_DSA-1657.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1657]DSA-1657-1 qemu -- insecure temporary files"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000804"
<br/>Script CVE: "CVE-2008-4553"
<br/>Description:	Dmitry E. Oboukhov discovered that the qemu-make-debian-root<br/>
script in qemu, fast processor emulator, creates temporary files<br/>
insecurely, which may lead to a local denial of service through<br/>
symlink attacks.For the stable distribution (etch), this problem has been fixed<br/>
in version 0.8.2-4etch2.For the testing (lenny) and unstable distribution (sid), this<br/>
problem has been fixed in version 0.9.1-6.We recommend that you upgrade your qemu package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1657.en.html ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 27 10:06 GMT</pubDate></item>
<item><title>debian_DSA-1656.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1656]DSA-1656-1 cupsys -- several vulnerabilities"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000803"
<br/>Script CVE: "CVE-2008-3639", "CVE-2008-3640", "CVE-2008-3641"
<br/>Description:	Several local vulnerabilities have been discovered in the Common<br/>
UNIX Printing System. The Common Vulnerabilities and Exposures<br/>
project identifies the following problems:For the stable distribution (etch), these problems have been<br/>
fixed in version 1.2.7-4etch5.For the unstable distribution (sid) and the upcoming stable<br/>
distribution (lenny), these problems have been fixed in version<br/>
1.3.8-1lenny2 of the source package cups.We recommend that you upgrade your cupsys package.<br/>
Solution : http://www.debian.org/security/2008/dsa-1656.en.html ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 27 10:06 GMT</pubDate></item>
<item><title>debian_DSA-1655.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[DSA-1655]DSA-1655-1 linux-2.6.24 -- denial of service/information leak/privilege escalation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1000802"
<br/>Script CVE: "CVE-2008-1514", "CVE-2008-3525", "CVE-2008-3831", "CVE-2008-4113", "CVE-2008-4445"
<br/>Description:	Several vulnerabilities have been discovered in the Linux kernel<br/>
that may lead to a denial of service, privilege escalation or a<br/>
leak of sensitive data. The Common Vulnerabilities and Exposures<br/>
project identifies the following problems:For the stable distribution (etch), these problems have been<br/>
fixed in version 2.6.24-6~etchnhalf.6.We recommend that you upgrade your linux-2.6.24 packages.<br/>
Solution : http://www.debian.org/security/2008/dsa-1655.en.htmlRisk factor : High<br/>

<br/>]]></description>
<pubDate>Oct 27 10:05 GMT</pubDate></item>
<item><title>gentoo_GLSA-200810-02.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[GLSA-200810-02]Portage: Untrusted search path local root vulnerability"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1011312"
<br/>Description:	The remote host is affected by the vulnerability described in GLSA-200810-02<br/>
Portage: Untrusted search path local root vulnerability<br/>
<br/>
Synopsis:<br/>
<br/>
A search path vulnerability in Portage allows local attackers to<br/>
execute commands with root privileges if emerge is called from<br/>
untrusted directories.<br/>
<br/>
Background:<br/>
<br/>
Portage is Gentoos package manager which is responsible for<br/>
installing, compiling and updating all packages on the system<br/>
through the Gentoo rsync tree. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 27 09:58 GMT</pubDate></item>
<item><title>secpod_ms08-067_900055.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:      "Server Service Could Allow Remote Code Execution Vulnerability (958644
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.900055"
<br/>Script BID: 31874
<br/>Script CVE: "CVE-2008-4250"
<br/>Description:	<br/>
  MS08-067<br/>
<br/>
  Overview: This host has critical security update missing according to<br/>
  Microsoft Bulletin MS08-067.<br/>
<br/>
  Vulnerability Insight:<br/>
  Flaw is due to an error in the Server Service, that does not properly<br/>
  handle specially crafted RPC requests.<br/>
<br/>
  Impact: Successful exploitation could allow remote attackers to take<br/>
  complete control of an affected system.<br/>
<br/>
  Impact Level: System<br/>
<br/>
  Affected Software/OS:<br/>
  Microsoft Windows 2K Service Pack 4 and prior. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 27 09:39 GMT</pubDate></item>
<item><title>gentoo_GLSA-200810-01.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[GLSA-200810-01]WordNet: Execution of arbitrary code â€”Gentoo Linux Documentation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1011311"
<br/>Description:	The remote host is affected by the vulnerability described in GLSA-200810-01<br/>
WordNet: Execution of arbitrary code â€”Gentoo Linux Documentation<br/>
<br/>
Synopsis:<br/>
<br/>
Multiple vulnerabilities were found in WordNet, possibly<br/>
allowing for the execution of arbitrary code.<br/>
<br/>
Background:<br/>
<br/>
WordNet is a large lexical database of English.<br/>
<br/>
Description:<br/>
<br/>
Jukka Ruohonen initially reported a boundary error within the<br/>
searchwn() function in src/wn.c. A thorough investigation by the ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 15 10:01 GMT</pubDate></item>
<item><title>gentoo_GLSA-200809-18.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[GLSA-200809-18]ClamAV: Multiple Denials of Service â€”Gentoo Linux Documentation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1011310"
<br/>Description:	The remote host is affected by the vulnerability described in GLSA-200809-18<br/>
ClamAV: Multiple Denials of Service â€”Gentoo Linux Documentation<br/>
<br/>
Synopsis:<br/>
<br/>
Multiple vulnerabilities in ClamAV may result in a Denial of<br/>
Service.<br/>
<br/>
Background:<br/>
<br/>
Clam AntiVirus is a free anti-virus toolkit for UNIX, designed<br/>
especially for e-mail scanning on mail gateways.<br/>
<br/>
Description:<br/>
<br/>
Hanno boeck reported an error in libclamav/chmunpack.c when<br/>
processing CHM files (CVE-2008-1389). Other unspecified ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 15 10:01 GMT</pubDate></item>
<item><title>gentoo_GLSA-200809-17.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[GLSA-200809-17]Wireshark: Multiple Denials of Service â€”Gentoo Linux Documentation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1011309"
<br/>Description:	The remote host is affected by the vulnerability described in GLSA-200809-17<br/>
Wireshark: Multiple Denials of Service â€”Gentoo Linux Documentation<br/>
<br/>
Synopsis:<br/>
<br/>
Multiple Denial of Service vulnerabilities have been discovered<br/>
in Wireshark.<br/>
<br/>
Background:<br/>
<br/>
Wireshark is a network protocol analyzer with a graphical<br/>
front-end.<br/>
<br/>
Description:<br/>
<br/>
The following vulnerabilities were reported:<br/>
<br/>
Impact:<br/>
<br/>
A remote attacker could exploit these vulnerabilities by sending ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 15 10:01 GMT</pubDate></item>
<item><title>gentoo_GLSA-200809-16.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[GLSA-200809-16]Git: User-assisted execution of arbitrary codeâ€” Gentoo Linux Documentation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1011308"
<br/>Description:	The remote host is affected by the vulnerability described in GLSA-200809-16<br/>
Git: User-assisted execution of arbitrary codeâ€” Gentoo Linux Documentation<br/>
<br/>
Synopsis:<br/>
<br/>
Multiple buffer overflow vulnerabilities have been discovered in<br/>
Git.<br/>
<br/>
Background:<br/>
<br/>
Git is a distributed version control system.<br/>
<br/>
Description:<br/>
<br/>
Multiple boundary errors in the functions diff_addremove() and<br/>
diff_change() when processing overly long repository path names ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 15 10:01 GMT</pubDate></item>
<item><title>gentoo_GLSA-200809-15.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[GLSA-200809-15]GNU ed: User-assisted execution of arbitrary codeâ€” Gentoo Linux Documentation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1011307"
<br/>Description:	The remote host is affected by the vulnerability described in GLSA-200809-15<br/>
GNU ed: User-assisted execution of arbitrary codeâ€” Gentoo Linux Documentation<br/>
<br/>
Synopsis:<br/>
<br/>
A buffer overflow vulnerability in ed may allow for the remote<br/>
execution of arbitrary code.<br/>
<br/>
Background:<br/>
<br/>
GNU ed is a basic line editor. red is a restricted version of ed<br/>
that does not allow shell command execution.<br/>
<br/>
Description:<br/>
<br/>
Alfredo Ortega from Core Security Technologies reported a ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 15 10:00 GMT</pubDate></item>
<item><title>gentoo_GLSA-200809-14.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[GLSA-200809-14]BitlBee: Security bypass â€” Gentoo LinuxDocumentation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1011306"
<br/>Description:	The remote host is affected by the vulnerability described in GLSA-200809-14<br/>
BitlBee: Security bypass â€” Gentoo LinuxDocumentation<br/>
<br/>
Synopsis:<br/>
<br/>
Multiple vulnerabilities in Bitlbee may allow to bypass security<br/>
restrictions and hijack accounts.<br/>
<br/>
Background:<br/>
<br/>
BitlBee is an IRC to IM gateway that support multiple IM<br/>
protocols.<br/>
<br/>
Description:<br/>
<br/>
Multiple unspecified vulnerabilities were reported, including a<br/>
NULL pointer dereference. ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 15 10:00 GMT</pubDate></item>
<item><title>gentoo_GLSA-200809-13.nasl</title><description><![CDATA[

New Vulnerability Check
<br/>Name:       "[GLSA-200809-13]R: Insecure temporary file creation â€”Gentoo Linux Documentation"
<br/>Script OID: "1.3.6.1.4.1.25623.1.3.1011305"
<br/>Description:	The remote host is affected by the vulnerability described in GLSA-200809-13<br/>
R: Insecure temporary file creation â€”Gentoo Linux Documentation<br/>
<br/>
Synopsis:<br/>
<br/>
R is vulnerable to symlink attacks due to an insecure usage of<br/>
temporary files.<br/>
<br/>
Background:<br/>
<br/>
R is a GPL licensed implementation of S, a language and<br/>
environment for statistical computing and graphics.<br/>
<br/>
Description:<br/>
<br/>
Dmitry E. Oboukhov reported that the "javareconf" script uses ...

<br/><br/> (check full advisory/plugin to read more)<br/>

<br/>]]></description>
<pubDate>Oct 15 10:00 GMT</pubDate></item>
</channel></rss>
