<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce">
    <title>gmane.linux.ubuntu.security.announce</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1727"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1726"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1725"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1724"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1723"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1722"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1721"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1720"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1719"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1718"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1717"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1716"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1715"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1714"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1713"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1712"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1711"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1710"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1709"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1708"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1727">
    <title>[USN-1454-1] Linux kernel vulnerability</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1727</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1454-1
May 25, 2012

linux vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 8.04 LTS

Summary:

The system could be made to crash or become unresponsive under certain
conditions.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 8.04 LTS:
  linux-image-2.6.24-31-386       2.6.24-31.101
  linux-image-2.6.24-31-generic   2.6.24-31.101
  linux-image-2.6.24-31-hppa32    2.6.24-31.101
  linux-image-2.6.24-31-hppa64    2.6.24-31.101
  linux-image-2.6.24-31-itanium   2.6.24-31.101
  linux-image-2.6.24-31-lpia&lt;/pre&gt;</description>
    <dc:creator>John Johansen</dc:creator>
    <dc:date>2012-05-25T19:53:07</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1726">
    <title>[USN-1453-1] Linux kernel (EC2) vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1726</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1453-1
May 25, 2012

linux-ec2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ec2: Linux kernel for EC2

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attack&lt;/pre&gt;</description>
    <dc:creator>John Johansen</dc:creator>
    <dc:date>2012-05-25T19:37:56</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1725">
    <title>[USN-1452-1] Linux kernel vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1725</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1452-1
May 25, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable address
space randomization to make attacking the process with raised privileges
easier. (CVE-2012-2123)

Update instructions:

The problem can be corrected by updating your system to the f&lt;/pre&gt;</description>
    <dc:creator>John Johansen</dc:creator>
    <dc:date>2012-05-25T19:19:00</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1724">
    <title>[USN-1451-1] OpenSSL vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1724</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1451-1
May 24, 2012

openssl vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Applications using OpenSSL in certain situations could be made to
crash or expose sensitive information.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

Ivan Nestlerode discovered that the Cryptographic Message Syntax
(CMS) and PKCS #7 implementations in OpenSSL returned early if RSA
decryption failed. This could allow an attacker to expose sensitive
information via a Million Message Attack (MMA). (CVE-2012-0884)

It was discovered that an integer underflow was possible when using
TLS 1.1, TLS 1.2, or DTLS with CBC encryption. This could allow a
remote attacker to cause&lt;/pre&gt;</description>
    <dc:creator>Steve Beattie</dc:creator>
    <dc:date>2012-05-24T22:58:25</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1723">
    <title>[USN-1450-1] Net-SNMP vulnerability</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1723</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1450-1
May 23, 2012

net-snmp vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Net-SNMP could be made to crash if it received specially crafted network
traffic.

Software Description:
- net-snmp: SNMP (Simple Network Management Protocol) server and applications

Details:

It was discovered that Net-SNMP incorrectly performed entry lookups in the
extension table. A remote attacker could send a specially crafted request
and cause the SNMP server to crash, leading to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  libsnmp15                       5.4.3~dfsg-2.4ubuntu1.1

Ubuntu 11.10:
  libsnmp15       &lt;/pre&gt;</description>
    <dc:creator>Marc Deslauriers</dc:creator>
    <dc:date>2012-05-23T18:12:56</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1722">
    <title>[USN-1449-1] feedparser vulnerability</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1722</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1449-1
May 22, 2012

feedparser vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Applications using feedparser could be made to crash if they fetched a
specially crafted feed.

Software Description:
- feedparser: Universal Feed Parser for Python

Details:

It was discovered that feedparser did not properly sanitize ENTITY
declarations in encoded fields. A remote attacker could exploit this to
cause a denial of service via memory exhaustion.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  python-feedparser               5.1-0ubuntu3.1
  python3-feedparser              5.1-0ubuntu3.1

In general, a standard system update will make all the necessary changes.

References:
  http://www.ubun&lt;/pre&gt;</description>
    <dc:creator>Jamie Strandboge</dc:creator>
    <dc:date>2012-05-22T19:23:01</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1721">
    <title>[USN-1448-1] Linux kernel vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1721</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1448-1
May 21, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable address
space randomization to make attacking the process with raised privileges
easier. (CVE-2012-2123)

Update instructions:

The problem can be corrected by updating your system to t&lt;/pre&gt;</description>
    <dc:creator>John Johansen</dc:creator>
    <dc:date>2012-05-21T23:12:21</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1720">
    <title>[USN-1447-1] libxml2 vulnerability</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1720</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1447-1
May 21, 2012

libxml2 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Applications using libxml2 could be made to crash or run programs as your
login if they opened a specially crafted file.

Software Description:
- libxml2: GNOME XML library

Details:

Juri Aedla discovered that libxml2 contained an off by one error in its
XPointer functionality. If a user or application linked against libxml2
were tricked into opening a specially crafted XML file, an attacker could
cause the application to crash or possibly execute arbitrary code with the
privileges of the user invoking the program.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:
&lt;/pre&gt;</description>
    <dc:creator>Jamie Strandboge</dc:creator>
    <dc:date>2012-05-21T22:15:27</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1719">
    <title>[USN-1445-1] Linux kernel vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1719</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1445-1
May 18, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable a&lt;/pre&gt;</description>
    <dc:creator>John Johansen</dc:creator>
    <dc:date>2012-05-18T01:32:48</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1718">
    <title>[USN-1445-1] Linux kernel vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1718</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1445-1
May 18, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)

A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual
cpu setup. An unprivileged local user could exploit this flaw to crash the
system leading to a denial of service. (CVE-2012-1601)

Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable a&lt;/pre&gt;</description>
    <dc:creator>John Johansen</dc:creator>
    <dc:date>2012-05-18T00:38:04</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1717">
    <title>[USN-1444-1] BackupPC vulnerability</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1717</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1444-1
May 17, 2012

backuppc vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

BackupPC could be made to expose sensitive information over the network.

Software Description:
- backuppc: high-performance, enterprise-grade system for backing up PCs

Details:

It was discovered that BackupPC did not properly sanitize its input when
processing RestoreFile error messages, resulting in a cross-site
scripting (XSS) vulnerability. With cross-site scripting vulnerabilities,
if a user were tricked into viewing server output during a crafted server
request, a remote attacker could exploit this to modify the contents, or
steal confidential data, within the same domain.

Update instructions:

The problem can be co&lt;/pre&gt;</description>
    <dc:creator>Jamie Strandboge</dc:creator>
    <dc:date>2012-05-17T22:48:11</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1716">
    <title>[USN-1443-1] Update Manager vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1716</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1443-1
May 17, 2012

update-manager vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04

Summary:

Update Manager could expose sensitive information in certain circumstances.

Software Description:
- update-manager: GNOME application that manages apt updates

Details:

It was discovered that Update Manager created system state archive files
with incorrect permissions when upgrading releases. A local user could
possibly use this to read repository credentials. (CVE-2012-0948)

Felix Geyer discovered that the Update Manager Apport hook incorrectly
uploaded certain system state archive files to Launchpad when reporting
bugs. This could possibly result in repository credentials being included
in public bug reports. (CVE-2012-0949)

Update instructions:

&lt;/pre&gt;</description>
    <dc:creator>Marc Deslauriers</dc:creator>
    <dc:date>2012-05-17T18:51:39</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1715">
    <title>[USN-1442-1] Sudo vulnerability</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1715</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1442-1
May 16, 2012

sudo vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Sudo could allow users to run arbitrary programs as the administrator.

Software Description:
- sudo: Provide limited super user privileges to specific users

Details:

It was discovered that sudo incorrectly handled network masks when using Host
and Host_List. A local user who is listed in sudoers may be allowed to run
commands on unintended hosts when IPv4 network masks are used to grant access.
A local attacker could exploit this to bypass intended access restrictions. Host
and Host_List are not used in the default installation of Ubuntu.

Update instructions:

The problem can be corrected by updating your system to the follo&lt;/pre&gt;</description>
    <dc:creator>Tyler Hicks</dc:creator>
    <dc:date>2012-05-16T19:29:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1714">
    <title>[USN-1441-1] Quagga vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1714</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1441-1
May 15, 2012

quagga vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS

Summary:

Quagga could be made to crash if it received specially crafted network
traffic.

Software Description:
- quagga: BGP/OSPF/RIP routing daemon

Details:

It was discovered that Quagga incorrectly handled Link State Update
messages with invalid lengths. A remote attacker could use this flaw to
cause Quagga to crash, resulting in a denial of service. (CVE-2012-0249,
CVE-2012-0250)

It was discovered that Quagga incorrectly handled messages with a malformed
Four-octet AS Number Capability. A remote attacker could use this flaw to
cause Quagga to crash, resulting in a denial of service. (CVE-2012-0255)

Update instructions:

The problem can be corr&lt;/pre&gt;</description>
    <dc:creator>Marc Deslauriers</dc:creator>
    <dc:date>2012-05-15T12:54:00</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1713">
    <title>[USN-1440-1] Linux kernel (Natty backport) vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1713</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1440-1
May 08, 2012

linux-lts-backport-natty vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-backport-natty: Linux kernel backport from Natty

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)

Sasha Levin discovered a flaw in the permission checking for device
assignments requested via the kvm ioctl in the Linux kernel. A local user
could use this flaw to crash the system causing a denial of service.
(CVE-2011-4347)

Stephan BÃ¤rwolf discovered a flaw in the KVM (kernel-based virtual
machine) subsystem of the Linux kernel. A local unpriv&lt;/pre&gt;</description>
    <dc:creator>John Johansen</dc:creator>
    <dc:date>2012-05-08T07:56:29</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1712">
    <title>[USN-1432-1] Linux kernel vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1712</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1432-1
May 08, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was found in the Linux's kernels ext4 file system when mounted with
a journal. A local, unprivileged user could exploit this flaw to cause a
denial of service. (CVE-2011-4086)

A flaw was discovered in the Linux kernel's cifs file system. An
unprivileged local user could exploit this flaw to crash the system leading
to a denial of service. (CVE-2012-1090)

A flaw was found in the Linux kernel's ext4 file system when mounting a
corrupt filesystem. A user-assisted remote attacker could exploit this flaw
to cause a denial of service. (CVE-2012-2100)

Update instructions:

The problem can&lt;/pre&gt;</description>
    <dc:creator>John Johansen</dc:creator>
    <dc:date>2012-05-08T06:40:23</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1711">
    <title>[USN-1439-1] Horizon vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1711</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1439-1
May 07, 2012

horizon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Horizon could be made to expose sensitive information over the network.

Software Description:
- horizon: Web interface for OpenStack cloud infrastructure

Details:

Matthias Weckbecker discovered a cross-site scripting (XSS) vulnerability
in Horizon via the log viewer refrash mechanism. If a user were tricked
into viewing a specially crafted log message, a remote attacker could
exploit this to modify the contents or steal confidential data within the
same domain. (CVE-2012-2094)

Thomas Biege discovered a session fixation vulnerability in Horizon. An
attacker could exploit this to potentially allow access to unauthorized
information and capabilities. (CVE-2012-2144)

Update instructions:
&lt;/pre&gt;</description>
    <dc:creator>Jamie Strandboge</dc:creator>
    <dc:date>2012-05-07T14:14:10</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1710">
    <title>[USN-1437-1] PHP vulnerability</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1710</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1437-1
May 04, 2012

php5 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Standalone PHP CGI scripts could be made to execute arbitrary code with
the privilege of the web server.

Software Description:
- php5: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP, when used as a stand alone CGI processor
for the Apache Web Server, did not properly parse and filter query
strings. This could allow a remote attacker to execute arbitrary code
running with the privilege of the web server. Configurations using
mod_php5 and FastCGI were not vulnerable.

This update addresses the issue when the PHP CGI interpreter
is configured using mod_cgi and mod_actions as described
in /usr/sh&lt;/pre&gt;</description>
    <dc:creator>Steve Beattie</dc:creator>
    <dc:date>2012-05-04T20:24:58</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1709">
    <title>[USN-1430-3] Thunderbird vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1709</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1430-3
May 04, 2012

thunderbird vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in Thunderbird.

Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

USN-1430-1 fixed vulnerabilities in Firefox. This update provides the
corresponding fixes for Thunderbird.

Original advisory details:

 Bob Clary, Christian Holler, Brian Hackett, Bobby Holley, Gary Kwong,
 Hilary Hall, Honza Bambas, Jesse Ruderman, Julian Seward, and Olli Pettay
 discovered memory safety issues affecting Firefox. If the user were tricked
 into opening a specially crafted page, an attacker could exploit these to
 cause a denial of service via application crash, or potentially &lt;/pre&gt;</description>
    <dc:creator>Micah Gersten</dc:creator>
    <dc:date>2012-05-04T11:18:21</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1708">
    <title>[USN-1438-1] Nova vulnerability</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1708</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1438-1
May 03, 2012

nova vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10

Summary:

Nova could be made to crash the system under certain conditions.

Software Description:
- nova: OpenStack Compute cloud infrastructure

Details:

Dan Prince discovered that Nova did not enforce quotas for security groups
and rules added to security groups. An authenticated user could exploit
this to cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  python-nova                     2012.1-0ubuntu2.1

Ubuntu 11.10:
  python-nova                     2011.3-0ubuntu6.6

In general, a standard system update will make all the necessary changes.

References:
  http://www.ubuntu.com&lt;/pre&gt;</description>
    <dc:creator>Jamie Strandboge</dc:creator>
    <dc:date>2012-05-03T23:12:34</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1707">
    <title>[USN-1436-1] Libtasn1 vulnerability</title>
    <link>http://permalink.gmane.org/gmane.linux.ubuntu.security.announce/1707</link>
    <description>&lt;pre&gt;==========================================================================
Ubuntu Security Notice USN-1436-1
May 02, 2012

libtasn1-3 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Libtasn1 could be made to crash or run programs as your login if it
received specially crafted input.

Software Description:
- libtasn1-3: Library to manage ASN.1 structures

Details:

Matthew Hall discovered that Libtasn1 incorrectly handled certain large
values. An attacker could exploit this with a specially crafted ASN.1
structure and cause a denial of service, or possibly execute arbitrary
code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  libtasn1-3                      2.10-1ubuntu1.1

Ubuntu 11.10:
  libtasn1-3                   &lt;/pre&gt;</description>
    <dc:creator>Marc Deslauriers</dc:creator>
    <dc:date>2012-05-02T12:21:38</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.linux.ubuntu.security.announce">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.linux.ubuntu.security.announce</link>
  </textinput>
</rdf:RDF>

