<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel about="http://blog.gmane.org/gmane.linux.gentoo.announce">
    <title>gmane.linux.gentoo.announce</title>
    <link>http://blog.gmane.org/gmane.linux.gentoo.announce</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1629"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1628"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1627"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1626"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1625"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1624"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1623"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1622"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1621"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1620"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1619"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1618"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1617"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1616"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1615"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1614"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1613"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1612"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1611"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.linux.gentoo.announce/1610"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1629">
    <title>[ GLSA 200811-05 ] PHP: Multiple vulnerabilities</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1629</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200811-05
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: PHP: Multiple vulnerabilities
      Date: November 16, 2008
      Bugs: #209148, #212211, #215266, #228369, #230575, #234102
        ID: 200811-05

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

PHP contains several vulnerabilities including buffer and integer
overflows which could lead to the remote execution of arbitrary code.

Background
==========

PHP is a widely-used general-purpose scripting language that is
especially suited for Web development and can be embedded into HTML.

Affected packages
=================

    --------------------------------------------------------</description>
    <dc:creator>Tobias Heinlein</dc:creator>
    <dc:date>2008-11-16T16:08:59</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1628">
    <title>[ GLSA 200811-04 ] Graphviz: User-assisted execution of arbitrary code</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1628</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200811-04
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: Graphviz: User-assisted execution of arbitrary code
      Date: November 09, 2008
      Bugs: #240636
        ID: 200811-04

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A buffer overflow in Graphviz might lead to user-assisted execution of
arbitrary code via a DOT file.

Background
==========

Graphviz is an open source graph visualization software.

Affected packages
=================

    -------------------------------------------------------------------
     Package             /  Vulnerable  /                   Unaffected
    ----------------------------------------------</description>
    <dc:creator>Tobias Heinlein</dc:creator>
    <dc:date>2008-11-09T21:01:08</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1627">
    <title>[ GLSA 200811-03 ] FAAD2: User-assisted execution of arbitrary code</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1627</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200811-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: FAAD2: User-assisted execution of arbitrary code
      Date: November 09, 2008
      Bugs: #238445
        ID: 200811-03

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A buffer overflow in FAAD2 might lead to user-assisted execution of
arbitrary code via an MP4 file.

Background
==========

FAAD2 is an open source MPEG-4 and MPEG-2 AAC decoder.

Affected packages
=================

    -------------------------------------------------------------------
     Package           /  Vulnerable  /                     Unaffected
    -----------------------------------------------------</description>
    <dc:creator>Tobias Heinlein</dc:creator>
    <dc:date>2008-11-09T20:59:25</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1626">
    <title>[ GLSA 200811-02 ] Gallery: Multiple vulnerabilities</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1626</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200811-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: Gallery: Multiple vulnerabilities
      Date: November 09, 2008
      Bugs: #234137, #238113
        ID: 200811-02

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities in Gallery may lead to execution of arbitrary
code, disclosure of local files or theft of user's credentials.

Background
==========

Gallery is an open source web based photo album organizer.

Affected packages
=================

    -------------------------------------------------------------------
     Package           /  Vulnerable  /                     Unaffected
    --------------------</description>
    <dc:creator>Tobias Heinlein</dc:creator>
    <dc:date>2008-11-09T20:56:41</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1625">
    <title>[ GLSA 200811-01 ] Opera: Multiple vulnerabilities</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1625</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200811-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: Opera: Multiple vulnerabilities
      Date: November 03, 2008
      Bugs: #235298, #240500, #243060, #244980
        ID: 200811-01

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in Opera, allowing for
the execution of arbitrary code.

Background
==========

Opera is a fast web browser that is available free of charge.

Affected packages
=================

    -------------------------------------------------------------------
     Package           /  Vulnerable  /                     Unaffected
    ----------------------------------</description>
    <dc:creator>Tobias Heinlein</dc:creator>
    <dc:date>2008-11-03T18:50:10</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1624">
    <title>[ GLSA 200810-03 ] libspf2: DNS response buffer overflow</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1624</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200810-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: High
     Title: libspf2: DNS response buffer overflow
      Date: October 30, 2008
      Bugs: #242254
        ID: 200810-03

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A memory management error in libspf2 might allow for remote execution
of arbitrary code.

Background
==========

libspf2 is a library that implements the Sender Policy Framework,
allowing mail transfer agents to make sure that an email is authorized
by the domain name that it is coming from. Currently, only the exim MTA
uses libspf2 in Gentoo.

Affected packages
=================

    -------------------------------------------</description>
    <dc:creator>Robert Buchholz</dc:creator>
    <dc:date>2008-10-30T21:27:08</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1623">
    <title>[ GLSA 200810-01 ] WordNet: Execution of arbitrary code</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1623</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200810-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: WordNet: Execution of arbitrary code
      Date: October 07, 2008
      Bugs: #211491
        ID: 200810-01

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities were found in WordNet, possibly allowing for
the execution of arbitrary code.

Background
==========

WordNet is a large lexical database of English.

Affected packages
=================

    -------------------------------------------------------------------
     Package            /  Vulnerable  /                    Unaffected
    -------------------------------------------------------------------
  </description>
    <dc:creator>Tobias Heinlein</dc:creator>
    <dc:date>2008-10-07T18:13:38</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1622">
    <title>[ GLSA 200810-02 ] Portage: Untrusted search path local root vulnerability</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1622</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200810-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: High
     Title: Portage: Untrusted search path local root vulnerability
      Date: October 09, 2008
      Bugs: #239560
        ID: 200810-02

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A search path vulnerability in Portage allows local attackers to
execute commands with root privileges if emerge is called from
untrusted directories.

Background
==========

Portage is Gentoo's package manager which is responsible for
installing, compiling and updating all packages on the system through
the Gentoo rsync tree.

Affected packages
=================

    ------------------------------------------</description>
    <dc:creator>Robert Buchholz</dc:creator>
    <dc:date>2008-10-09T17:36:48</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1621">
    <title>[ GLSA 200809-18 ] ClamAV: Multiple Denials of Service</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1621</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-18
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: ClamAV: Multiple Denials of Service
        Date: September 25, 2008
        Bugs: #236665
          ID: 200809-18

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities in ClamAV may result in a Denial of Service.

Background
==========

Clam AntiVirus is a free anti-virus toolkit for UNIX, designed
especially for e-mail scanning on mail gateways.

Affected packages
=================

      -------------------------------------------------------------------
       Package               /  Vulnerable  /                 Unaffected
      --------------------</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-25T21:23:08</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1620">
    <title>[ GLSA 200809-17 ] Wireshark: Multiple Denials of Service</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1620</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-17
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: Wireshark: Multiple Denials of Service
        Date: September 25, 2008
        Bugs: #236515
          ID: 200809-17

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple Denial of Service vulnerabilities have been discovered in
Wireshark.

Background
==========

Wireshark is a network protocol analyzer with a graphical front-end.

Affected packages
=================

      -------------------------------------------------------------------
       Package                 /  Vulnerable  /               Unaffected
      ----------------------------------------------------</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-25T21:15:47</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1619">
    <title>[ GLSA 200809-16 ] Git: User-assisted execution of arbitrary code</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1619</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-16
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: Git: User-assisted execution of arbitrary code
        Date: September 25, 2008
        Bugs: #234075
          ID: 200809-16

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple buffer overflow vulnerabilities have been discovered in Git.

Background
==========

Git is a distributed version control system.

Affected packages
=================

      -------------------------------------------------------------------
       Package       /  Vulnerable  /                         Unaffected
      -------------------------------------------------------------------
    1  d</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-25T21:09:41</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1618">
    <title>[ GLSA 200809-15 ] GNU ed: User-assisted execution of arbitrary code</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1618</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-15
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: GNU ed: User-assisted execution of arbitrary code
        Date: September 23, 2008
        Bugs: #236521
          ID: 200809-15

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A buffer overflow vulnerability in ed may allow for the remote
execution of arbitrary code.

Background
==========

GNU ed is a basic line editor. red is a restricted version of ed that
does not allow shell command execution.

Affected packages
=================

      -------------------------------------------------------------------
       Package      /  Vulnerable  /                          Una</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-23T21:56:51</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1617">
    <title>[ GLSA 200809-14 ] BitlBee: Security bypass</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1617</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: BitlBee: Security bypass
        Date: September 23, 2008
        Bugs: #236160
          ID: 200809-14

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities in Bitlbee may allow to bypass security
restrictions and hijack accounts.

Background
==========

BitlBee is an IRC to IM gateway that support multiple IM protocols.

Affected packages
=================

      -------------------------------------------------------------------
       Package         /  Vulnerable  /                       Unaffected
      ----------------------------------------------</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-23T21:33:35</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1616">
    <title>[ GLSA 200809-13 ] R: Insecure temporary file creation</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1616</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-13
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: R: Insecure temporary file creation
        Date: September 22, 2008
        Bugs: #235822
          ID: 200809-13

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

R is vulnerable to symlink attacks due to an insecure usage of
temporary files.

Background
==========

R is a GPL licensed implementation of S, a language and environment for
statistical computing and graphics.

Affected packages
=================

      -------------------------------------------------------------------
       Package     /  Vulnerable  /                           Unaffected
      --------------</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-22T20:15:42</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1615">
    <title>[ GLSA 200809-12 ] Newsbeuter: User-assisted execution of arbitrary code</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1615</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: Newsbeuter: User-assisted execution of arbitrary code
        Date: September 22, 2008
        Bugs: #236506
          ID: 200809-12

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Insufficient input validation in newsbeuter may allow remote attackers
to execute arbitrary shell commands.

Background
==========

Newsbeuter is a RSS/Atom feed reader for the text console.

Affected packages
=================

      -------------------------------------------------------------------
       Package              /  Vulnerable  /                  Unaffected
      -----------------</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-22T20:07:04</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1614">
    <title>[ GLSA 200809-11 ] HAVP: Denial of Service</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1614</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: HAVP: Denial of Service
        Date: September 21, 2008
        Bugs: #234715
          ID: 200809-11

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A Denial of Service vulnerability has been reported in HAVP.

Background
==========

HAVP is a HTTP AntiVirus Proxy.

Affected packages
=================

      -------------------------------------------------------------------
       Package         /  Vulnerable  /                       Unaffected
      -------------------------------------------------------------------
    1  net-proxy/havp       &lt; 0.89                   </description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-21T17:31:33</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1613">
    <title>[ GLSA 200809-10 ] Mantis: Multiple vulnerabilities</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1613</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-10
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: High
       Title: Mantis: Multiple vulnerabilities
        Date: September 21, 2008
        Bugs: #233336
          ID: 200809-10

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been reported in Mantis.

Background
==========

Mantis is a PHP/MySQL/Web based bugtracking system.

Affected packages
=================

      -------------------------------------------------------------------
       Package            /  Vulnerable  /                    Unaffected
      -------------------------------------------------------------------
    1  www-apps/mantisbt       &lt;</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-21T17:25:09</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1612">
    <title>[ GLSA 200809-09 ] Postfix: Denial of Service</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1612</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-09
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: Postfix: Denial of Service
        Date: September 19, 2008
        Bugs: #236453
          ID: 200809-09

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A memory leak in Postfix might allow local users to cause a Denial of
Service.

Background
==========

Postfix is Wietse Venema's mailer that attempts to be fast, easy to
administer, and secure, as an alternative to the widely-used Sendmail
program.

Affected packages
=================

      -------------------------------------------------------------------
       Package           /  Vulnerable  /                     Un</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-19T20:10:45</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1611">
    <title>[ GLSA 200809-08 ] Amarok: Insecure temporary file creation</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1611</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: Amarok: Insecure temporary file creation
        Date: September 08, 2008
        Bugs: #234689
          ID: 200809-08

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Amarok uses temporary files in an insecure manner, allowing for a
symlink attack.

Background
==========

Amarok is an advanced music player.

Affected packages
=================

      -------------------------------------------------------------------
       Package             /  Vulnerable  /                   Unaffected
      -------------------------------------------------------------------
    1  medi</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-08T18:08:57</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1610">
    <title>[ GLSA 200809-07 ] libTIFF: User-assisted execution of arbitrary code</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1610</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-07
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: libTIFF: User-assisted execution of arbitrary code
        Date: September 08, 2008
        Bugs: #234080
          ID: 200809-07

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple buffer underflow vulnerabilities in libTIFF may allow for the
remote execution of arbitrary code.

Background
==========

libTIFF provides support for reading and manipulating TIFF (Tagged
Image File Format) images.

Affected packages
=================

      -------------------------------------------------------------------
       Package          /  Vulnerable  /                      Una</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-08T17:57:53</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.linux.gentoo.announce/1609">
    <title>[ GLSA 200809-06 ] VLC: Multiple vulnerabilities</title>
    <link>http://comments.gmane.org/gmane.linux.gentoo.announce/1609</link>
    <description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200809-06
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                              http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
       Title: VLC: Multiple vulnerabilities
        Date: September 07, 2008
        Bugs: #235238, #235589
          ID: 200809-06

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Two vulnerabilities in VLC may lead to the remote execution of
arbitrary code.

Background
==========

VLC is a cross-platform media player and streaming server.

Affected packages
=================

      -------------------------------------------------------------------
       Package          /   Vulnerable   /                    Unaffected
      -------------------------------------------------------------</description>
    <dc:creator>Pierre-Yves Rofes</dc:creator>
    <dc:date>2008-09-07T19:21:51</dc:date>
  </item>
  <textinput about="http://search.gmane.org/?group=$group=gmane.linux.gentoo.announce">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.linux.gentoo.announce</link>
  </textinput>
</rdf:RDF>
