<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE vuxml PUBLIC "-//vuxml.org//DTD VuXML 1.1//EN" "http://www.vuxml.org/dtd/vuxml-1/vuxml-11.dtd">
<!--
Copyright 2003-2007 Jacques Vidrine and contributors

Redistribution and use in source (VuXML) and 'compiled' forms (SGML,
HTML, PDF, PostScript, RTF and so forth) with or without modification,
are permitted provided that the following conditions are met:
1. Redistributions of source code (VuXML) must retain the above
   copyright notice, this list of conditions and the following
   disclaimer as the first lines of this file unmodified.
2. Redistributions in compiled form (transformed to other DTDs,
   published online in any format, converted to PDF, PostScript,
   RTF and other formats) must reproduce the above copyright
   notice, this list of conditions and the following disclaimer
   in the documentation and/or other materials provided with the
   distribution.

THIS DOCUMENTATION IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS "AS IS"
AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS
BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY,
OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT
OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS DOCUMENTATION,
EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

  $FreeBSD: ports/security/vuxml/vuln.xml,v 1.1624 2008/05/11 19:35:33 naddy Exp $

Note:  Please add new entries to the beginning of this file.

-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
  <vuln vid="633716fa-1f8f-11dd-b143-0211d880e350">
    <topic>vorbis-tools -- Speex header processing vulnerability</topic>
    <affects>
      <package>
	<name>vorbis-tools</name>
	<range><lt>1.2.0_2,3</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/29882/">
	  <p>A vulnerability has been reported in vorbis-tools,
	    which can potentially be exploited by malicious people
	    to compromise a user's system.</p>
	  <p>The vulnerability is caused due to an input validation
	    error when processing Speex headers, which can be
	    exploited via a specially crafted Speex stream containing
	    a negative "modeID" field in the header.</p>
	  <p>Successful exploitation may allow execution of arbitrary
	    code.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1686</cvename>
      <url>http://secunia.com/advisories/29882/</url>
    </references>
    <dates>
      <discovery>2008-04-18</discovery>
      <entry>2008-05-11</entry>
    </dates>
  </vuln>

  <vuln vid="8950ac62-1d30-11dd-9388-0211060005df">
    <topic>qemu -- "drive_init()" Disk Format Security Bypass</topic>
    <affects>
      <package>
	<name>qemu</name>
	<name>qemu-devel</name>
	<range><lt>0.9.1_6</lt></range>
	<range><ge>0.9.1s.20070101*</ge><lt>0.9.1s.20080302_6</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/30111/">
	  <p>A vulnerability has been reported in QEMU, which can be exploited
	    by malicious, local users to bypass certain security
	    restrictions.</p>
	  <p>The vulnerability is caused due to the "drive_init()" function
	    in vl.c determining the format of a disk from data contained in
	    the disk's header. This can be exploited by a malicious user in
	    a guest system to e.g. read arbitrary files on the host by
	    writing a fake header to a raw formatted disk image.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-2004</cvename>
      <url>http://secunia.com/advisories/30111/</url>
      <mlist>http://lists.gnu.org/archive/html/qemu-devel/2008-04/msg00675.html</mlist>
    </references>
    <dates>
      <discovery>2008-04-28</discovery>
      <entry>2008-05-08</entry>
    </dates>
  </vuln>

  <vuln vid="5ef12755-1c6c-11dd-851d-0016d325a0ed">
    <topic>swfdec -- exposure of sensitive information</topic>
    <affects>
      <package>
	<name>swfdec</name>
	<range><lt>0.6.4</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/29915">
	  <p>A vulnerability has been reported in swfdec, which can be
    	    exploited by malicious people to disclose sensitive
    	    information.</p>
	  <p>The vulnerability is caused due to swfdec not properly
	    restricting untrusted sandboxes from reading local files,
	    which can be exploited to disclose the content of arbitrary
	    local files by e.g. tricking a user into visiting a malicious
	    website.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1834</cvename>
      <url>http://secunia.com/advisories/29915</url>
    </references>
    <dates>
      <discovery>2008-04-09</discovery>
      <entry>2008-05-07</entry>
    </dates>
  </vuln>

  <vuln vid="86a4d810-1884-11dd-a914-0016179b2dd5">
    <topic>mt-daapd -- integer overflow</topic>
    <affects>
      <package>
	<name>mt-daapd</name>
	<range><lt>0.2.4.2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>FrSIRT reports:</p>
	<blockquote cite="http://www.frsirt.com/english/advisories/2008/1303">
	  <p>A vulnerability has been identified in mt-daapd which could be exploited
	    by remote attackers to cause a denial of service or compromise an
	    affected system. This issue is caused by a buffer overflow error in the
	    ws_getpostvars() function when processing a negative Content-Length:
	    header value, which could be exploited by remote unauthenticated
	    attackers to crash an affected application or execute arbitrary
	    code.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1771</cvename>
      <url>http://secunia.com/advisories/29917</url>
      <url>http://www.frsirt.com/english/advisories/2008/1303</url>
    </references>
    <dates>
      <discovery>2008-04-21</discovery>
      <entry>2008-05-02</entry>
    </dates>
  </vuln>

  <vuln vid="b1bcab7d-1880-11dd-a914-0016179b2dd5">
    <topic>sdl_image -- buffer overflow vulnerabilities</topic>
    <affects>
      <package>
	<name>sdl_image</name>
	<range><lt>1.2.6_1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/28640">
	  <p>Two vulnerabilities have been reported in SDL_image, which can be
	    exploited by malicious people to cause a Denial of Service or potentially
	    compromise an application using the library.</p>
	  <p>A boundary error within the LWZReadByte() function in IMG_gif.c can
	    be exploited to trigger the overflow of a static buffer via a
	    specially crafted GIF file.</p>
	  <p>A boundary error within the "IMG_LoadLBM_RW()" function in IMG_lbm.c
	    can be exploited to cause a heap-based buffer overflow via a specially
	    crafted IFF ILBM file.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6697</cvename>
      <cvename>CVE-2008-0544</cvename>
      <url>http://secunia.com/advisories/28640</url>
    </references>
    <dates>
      <discovery>2008-01-24</discovery>
      <entry>2008-05-02</entry>
    </dates>
  </vuln>

  <vuln vid="30394651-13e1-11dd-bab7-0016179b2dd5">
    <topic>gnupg -- memory corruption vulnerability</topic>
    <affects>
      <package>
	<name>gnupg</name>
	<range><ge>1.0.0</ge><lt>1.4.9</lt></range>
	<range><ge>2.0.0</ge><lt>2.0.9</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/29568">
	  <p>A vulnerability has been reported in GnuPG, which can potentially
	    be exploited to compromise a vulnerable system.</p>
	  <p>The vulnerability is caused due to an error when importing keys
	    with duplicated IDs. This can be exploited to cause a memory
	    corruption when importing keys via --refresh-keys or --import.</p>
	  <p>Successful exploitation potentially allows execution of arbitrary
	    code, but has not been proven yet.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>28487</bid>
      <cvename>CVE-2008-1530</cvename>
      <url>http://www.ocert.org/advisories/ocert-2008-1.html</url>
      <url>http://secunia.com/advisories/29568</url>
      <url>https://bugs.g10code.com/gnupg/issue894</url>
    </references>
    <dates>
      <discovery>2008-03-19</discovery>
      <entry>2008-04-26</entry>
      <modified>2008-04-29</modified>
    </dates>
  </vuln>

  <vuln vid="44c8694a-12f9-11dd-9b26-001c2514716c">
    <topic>extman -- password bypass vulnerability</topic>
    <affects>
      <package>
	<name>extman</name>
	<range><ge>0.2.4</ge><lt>0.2.4_1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Extmail team reports:</p>
	<blockquote cite="http://www.extmail.org/forum/thread-7260-1-1.html">
	  <p>Emergency update #4 fixes a serious security vulnerability.</p>
	</blockquote>
	<p>Successful exploit of this vulnerability would allow attacker to
	  change user's password without knowing it by using specifically
	  crafted HTTP request.</p>
      </body>
    </description>
    <references>
      <url>http://www.extmail.org/forum/thread-7260-1-1.html</url>
    </references>
    <dates>
      <discovery>2008-04-01</discovery>
      <entry>2008-04-25</entry>
    </dates>
  </vuln>

  <vuln vid="f47f2746-12c5-11dd-bab7-0016179b2dd5">
    <topic>mailman -- script insertion vulnerability</topic>
    <affects>
      <package>
	<name>ja-mailman</name>
	<name>mailman</name>
	<name>mailman-with-htdig</name>
	<range><lt>2.1.10</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/28794">
	  <p>A vulnerability has been reported in Mailman, which can be
	    exploited by malicious users to conduct script insertion
	    attacks.</p>
	  <p>Certain input when editing the list templates and the list info
	    attribute is not properly sanitised before being stored. This can be
	    exploited to insert arbitrary HTML and script code, which is
	    executed in a user's browser session in context of an affected site
	    when the malicious website is accessed.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-0564</cvename>
      <bid>27630</bid>
      <url>http://www.ubuntu.com/usn/usn-586-1</url>
      <url>http://secunia.com/advisories/28794</url>
      <url>http://sourceforge.net/project/shownotes.php?release_id=593924</url>
    </references>
    <dates>
      <discovery>2008-02-05</discovery>
      <entry>2008-04-25</entry>
    </dates>
  </vuln>

  <vuln vid="86c05550-12c1-11dd-bab7-0016179b2dd5">
    <topic>mksh -- TTY attachment privilege escalation</topic>
    <affects>
      <package>
	<name>mksh</name>
	<range><lt>R33d</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/29803/">
	  <p>The vulnerability is caused due to an error when attaching to a TTY
	    via the -T command line switch. This can be exploited to execute
	    arbitrary commands with the privileges of the user running mksh via
	    characters previously written to the attached virtual console.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1845</cvename>
      <url>http://secunia.com/advisories/29803/</url>
      <url>http://www.mirbsd.org/mksh.htm#clog</url>
    </references>
    <dates>
      <discovery>2008-04-14</discovery>
      <entry>2008-04-25</entry>
    </dates>
  </vuln>

  <vuln vid="9c133aa0-12bd-11dd-bab7-0016179b2dd5">
    <topic>serendipity -- multiple cross site scripting vulnerabilities</topic>
    <affects>
      <package>
	<name>serendipity</name>
	<range><lt>1.3.1</lt></range>
      </package>
      <package>
	<name>serendipity-devel</name>
	<range><lt>200804242342</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Hanno Boeck reports:</p>
	<blockquote cite="http://int21.de/cve/CVE-2008-1386-s9y.html">
	  <p>The installer of serendipity 1.3 has various Cross Site Scripting
	    issues.  This is considered low priority, as attack scenarios are
	    very unlikely.</p>
	  <p>Various path fields are not escaped properly, thus filling them
	    with javascript code will lead to XSS. MySQL error messages are not
	    escaped, thus the database host field can also be filled with
	    javascript.</p>
	</blockquote>
	<blockquote cite="http://int21.de/cve/CVE-2008-1385-s9y.html">
	  <p>In the referrer plugin of the blog application serendipity,
	    the referrer string is not escaped, thus leading to a permanent
	    XSS.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>28885</bid>
      <cvename>CVE-2008-1385</cvename>
      <cvename>CVE-2008-1386</cvename>
      <url>http://int21.de/cve/CVE-2008-1385-s9y.html</url>
      <url>http://int21.de/cve/CVE-2008-1386-s9y.html</url>
      <url>http://blog.s9y.org/archives/193-Serendipity-1.3.1-released.html</url>
    </references>
    <dates>
      <discovery>2008-04-22</discovery>
      <entry>2008-04-25</entry>
    </dates>
  </vuln>

  <vuln vid="67bd39ba-12b5-11dd-bab7-0016179b2dd5">
    <topic>firefox -- javascript garbage collector vulnerability</topic>
    <affects>
      <package>
	<name>firefox</name>
	<range><lt>2.0.0.14,1</lt></range>
      </package>
      <package>
	<name>linux-firefox</name>
	<range><lt>2.0.0.14</lt></range>
      </package>
      <package>
	<name>seamonkey</name>
	<name>linux-seamonkey</name>
	<range><lt>1.1.10</lt></range>
      </package>
      <package>
	<name>flock</name>
	<name>linux-flock</name>
	<range><lt>1.1.2</lt></range>
      </package>
      <package>
	<name>linux-firefox-devel</name>
	<name>linux-seamonkey-devel</name>
	<range><gt>0</gt></range>
      </package>
      <package>
	<name>thunderbird</name>
	<name>linux-thunderbird</name>
	<range><lt>2.0.0.14</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Mozilla Foundation reports:</p>
	<blockquote cite="http://www.mozilla.org/security/announce/2008/mfsa2008-20.html">
	  <p>Fixes for security problems in the JavaScript engine described in
	    MFSA 2008-15 introduced a stability problem, where some users
	    experienced crashes during JavaScript garbage collection. This is
	    being fixed primarily to address stability concerns. We have no
	    demonstration that this particular crash is exploitable but are
	    issuing this advisory because some crashes of this type have been
	    shown to be exploitable in the past.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1237</cvename>
      <cvename>CVE-2008-1380</cvename>
      <bid>28818</bid>
      <url>http://secunia.com/advisories/29787</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-20.html</url>
    </references>
    <dates>
      <discovery>2008-04-16</discovery>
      <entry>2008-04-25</entry>
      <modified>2008-04-28</modified>
    </dates>
  </vuln>

  <vuln vid="57c705d6-12ae-11dd-bab7-0016179b2dd5">
    <topic>png -- unknown chunk processing uninitialized memory access</topic>
    <affects>
      <package>
	<name>png</name>
	<range><lt>1.2.27</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://.com/advisories/29792">
	  <p>Tavis Ormandy has reported a vulnerability in libpng, which can be
	    exploited by malicious people to cause a Denial of Service, disclose
	    potentially sensitive information, or potentially compromise an
	    application using the library.</p>
	  <p>The vulnerability is caused due to the improper handling of PNG
	    chunks unknown to the library. This can be exploited to trigger the
	    use of uninitialized memory in e.g. a free() call via unknown PNG
	    chunks having a length of zero.</p>
	  <p>Successful exploitation may allow execution of arbitrary code, but
	    requires that the application calls the png_set_read_user_chunk_fn()
	    function or the png_set_keep_unknown_chunks() function under
	    specific conditions.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1382</cvename>
      <bid>28770</bid>
      <url>http://secunia.com/advisories/29792</url>
      <url>http://libpng.sourceforge.net/Advisory-1.2.26.txt</url>
    </references>
    <dates>
      <discovery>2008-04-12</discovery>
      <entry>2008-04-25</entry>
      <modified>2008-04-29</modified>
    </dates>
  </vuln>

  <vuln vid="b84a992a-12ab-11dd-bab7-0016179b2dd5">
    <topic>openfire -- unspecified denial of service</topic>
    <affects>
      <package>
	<name>openfire</name>
	<range><lt>3.5.0</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/29751">
	  <p>A vulnerability has been reported in Openfire, which can be
	    exploited by malicious people to cause a Denial of Service.</p>
	  <p>The vulnerability is caused due to an unspecified error and can be
	    exploited to cause a Denial of Service.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1728</cvename>
      <bid>28722</bid>
      <url>http://secunia.com/advisories/29751</url>
      <url>http://www.igniterealtime.org/issues/browse/JM-1289</url>
    </references>
    <dates>
      <discovery>2008-04-10</discovery>
      <entry>2008-04-25</entry>
    </dates>
  </vuln>

  <vuln vid="f6377f08-12a7-11dd-bab7-0016179b2dd5">
    <topic>php -- integer overflow vulnerability</topic>
    <affects>
      <package>
	<name>php5</name>
	<range><lt>5.2.6</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>CVE reports:</p>
	<blockquote cite="http://www.securityfocus.com/bid/28392/discuss">
	  <p>Integer overflow in PHP 5.2.5 and earlier allows context-dependent
	    attackers to cause a denial of service and possibly have unspecified
	    other impact via a printf format parameter with a large width
	    specifier, related to the php_sprintf_appendstring function in
	    formatted_print.c and probably other functions for formatted strings
	    (aka *printf functions).</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1384</cvename>
      <bid>28392</bid>
      <url>http://securityreason.com/achievement_securityalert/52</url>
    </references>
    <dates>
      <discovery>2008-03-21</discovery>
      <entry>2008-04-25</entry>
      <modified>2008-05-02</modified>
    </dates>
  </vuln>

  <vuln vid="ec41c3e2-129c-11dd-bab7-0016179b2dd5">
    <topic>python -- Integer Signedness Error in zlib Module</topic>
    <affects>
      <package>
	<name>python23</name>
	<range><lt>2.3.6_1</lt></range>
      </package>
      <package>
	<name>python24</name>
	<range><lt>2.4.5_1</lt></range>
      </package>
      <package>
	<name>python25</name>
	<range><lt>2.5.2_2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Justin Ferguson reports:</p>
	<blockquote cite="http://bugs.python.org/issue2586">
	  <p>Integer signedness error in the zlib extension module in Python
	    2.5.2 and earlier allows remote attackers to execute arbitrary code
	    via a negative signed integer, which triggers insufficient memory
	    allocation and a buffer overflow.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1721</cvename>
      <bid>28715</bid>
      <url>http://securityreason.com/securityalert/3802</url>
      <url>http://bugs.python.org/issue2586</url>
    </references>
    <dates>
      <discovery>2008-04-10</discovery>
      <entry>2008-04-25</entry>
       <modified>2008-04-28</modified>
    </dates>
  </vuln>

  <vuln vid="51436b4c-1250-11dd-bab7-0016179b2dd5">
    <topic>postgresql -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>postgresql</name>
	<name>postgresql-server</name>
	<range><ge>7.3</ge><lt>7.3.21</lt></range>
	<range><ge>7.4</ge><lt>7.4.19</lt></range>
	<range><ge>8.0</ge><lt>8.0.15</lt></range>
	<range><ge>8.1</ge><lt>8.1.11</lt></range>
	<range><ge>8.2</ge><lt>8.2.6</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The PostgreSQL developers report:</p>
	<blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6600">
	  <p>PostgreSQL allows users to create indexes on the results of
	    user-defined functions, known as "expression indexes". This provided
	    two vulnerabilities to privilege escalation: (1) index functions
	    were executed as the superuser and not the table owner during VACUUM
	    and ANALYZE, and (2) that SET ROLE and SET SESSION AUTHORIZATION
	    were permitted within index functions. Both of these holes have now
	    been closed.</p>
	</blockquote>
	<blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4772">
	  <p>PostgreSQL allowed malicious users to initiate a denial-of-service
	    by passing certain regular expressions in SQL queries. First, users
	    could create infinite loops using some specific regular expressions.
	    Second, certain complex regular expressions could consume excessive
	    amounts of memory. Third, out-of-range backref numbers could be used
	    to crash the backend.</p>
	</blockquote>
	<blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=">
	  <p>DBLink functions combined with local trust or ident authentication
	    could be used by a malicious user to gain superuser privileges. This
	    issue has been fixed, and does not affect users who have not
	    installed DBLink (an optional module), or who are using password
	    authentication for local access. This same problem was addressed in
	    the previous release cycle, but that patch failed to close all forms
	    of the loophole.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6600</cvename>
      <cvename>CVE-2007-4772</cvename>
      <cvename>CVE-2007-6067</cvename>
      <cvename>CVE-2007-4769</cvename>
      <cvename>CVE-2007-6601</cvename>
      <bid>27163</bid>
      <url>http://www.postgresql.org/about/news.905</url>
    </references>
    <dates>
      <discovery>2008-01-06</discovery>
      <entry>2008-04-24</entry>
    </dates>
  </vuln>

  <vuln vid="fe971a0f-1246-11dd-bab7-0016179b2dd5">
    <topic>phpmyadmin -- Shared Host Information Disclosure</topic>
    <affects>
      <package>
	<name>phpmyadmin</name>
	<range><lt>2.11.5.2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>A phpMyAdmin security announcement report:</p>
	<blockquote cite="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-3">
	  <p>It is possible to read the contents of any file that the web
	    server's user can access. The exact mechanism to achieve this won't
	    be disclosed.  If a user can upload on the same host where
	    phpMyAdmin is running a PHP script that can read files with the
	    rights of the web server's user, the current advisory does not
	    describe an additional threat.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1924</cvename>
      <url>http://secunia.com/advisories/29944/</url>
      <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-3</url>
    </references>
    <dates>
      <discovery>2008-04-23</discovery>
      <entry>2008-04-24</entry>
    </dates>
  </vuln>

  <vuln vid="6eb1dc51-1244-11dd-bab7-0016179b2dd5">
    <topic>phpmyadmin -- Username/Password Session File Information Disclosure</topic>
    <affects>
      <package>
	<name>phpmyadmin</name>
	<range><lt>2.11.5.1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>A phpMyAdmin security announcement report:</p>
	<blockquote cite="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-2">
	  <p>phpMyAdmin saves sensitive information like the MySQL username and
	    password and the Blowfish secret key in session data, which might be
	    unprotected on a shared host.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1567</cvename>
      <url>http://secunia.com/advisories/29613/</url>
      <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-3</url>
    </references>
    <dates>
      <discovery>2008-03-31</discovery>
      <entry>2008-04-24</entry>
    </dates>
  </vuln>

  <vuln vid="7a7c5853-10a3-11dd-8eb8-00163e000016">
    <topic>libxine -- array index vulnerability</topic>
    <affects>
      <package>
	<name>libxine</name>
	<range><lt>1.1.12</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>xine Team reports:</p>
	<blockquote cite="http://www.xinehq.de/index.php/news">
	  <p>A new xine-lib version is now available. This release contains a
	    security fix (an unchecked array index that could allows remote
	    attackers to execute arbitrary code via a header structure
	    containing a negative offset, which is used to dereference a
	    function pointer.)</p>
	</blockquote>
      </body>
    </description>
    <references>
       <cvename>CVE-2008-1686</cvename>
       <url>http://www.xinehq.de/index.php/news</url>
    </references>
    <dates>
      <discovery>2008-04-06</discovery>
      <entry>2008-04-24</entry>
    </dates>
  </vuln>

  <vuln vid="589d8053-0b03-11dd-b4ef-00e07dc4ec84">
    <topic>clamav -- Multiple Vulnerabilities</topic>
    <affects>
      <package>
	<name>clamav</name>
	<range><lt>0.93</lt></range>
      </package>
      <package>
	<name>clamav-devel</name>
	<range><lt>20080415</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/29000">
	  <p>Some vulnerabilities have been reported in ClamAV, which can be
	    exploited by malicious people to cause a DoS (Denial of Service)
	    or to compromise a vulnerable system.</p>
	  <p>1) A boundary error exists within the "cli_scanpe()" function in
	    libclamav/pe.c. This can be exploited to cause a heap-based buffer
	    overflow via a specially crafted "Upack" executable.</p>
	  <p>Successful exploitation allows execution of arbitrary code.</p>
	  <p>2) A boundary error within the processing of PeSpin packed
	    executables in libclamav/spin.c can be exploited to cause a
	    heap-based buffer overflow.</p>
	  <p>Successful exploitation may allow execution of arbitrary code.</p>
	  <p>3) An unspecified error in the processing of ARJ files can be
	    exploited to hang ClamAV.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-1100</cvename>
      <cvename>CVE-2008-1387</cvename>
      <url>http://secunia.com/advisories/29000</url>
    </references>
    <dates>
      <discovery>2008-04-15</discovery>
      <entry>2008-04-15</entry>
    </dates>
  </vuln>

  <vuln vid="1ac77649-0908-11dd-974d-000fea2763ce">
    <topic>lighttpd -- OpenSSL Error Queue Denial of Service Vulnerability</topic>
    <affects>
      <package>
	<name>lighttpd</name>
	<range><lt>1.4.19_1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/29649">
	  <p>A vulnerability has been reported in lighttpd, which can be
	    exploited by malicious people to cause a DoS (Denial of
	    Service).</p>
	  <p>The vulnerability is caused due to lighttpd not properly clearing
	    the OpenSSL error queue. This can be exploited to close concurrent
	    SSL connections of lighttpd by terminating one SSL connection.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>28489</bid>
      <cvename>CVE-2008-1531</cvename>
      <url>http://secunia.com/advisories/29649</url>
      <url>http://trac.lighttpd.net/trac/ticket/285</url>
    </references>
    <dates>
      <discovery>2008-04-02</discovery>
      <entry>2008-04-13</entry>
    </dates>
  </vuln>

  <vuln vid="8d2c0ce1-08b6-11dd-94b4-0016d325a0ed">
    <topic>ikiwiki -- cross site request forging</topic>
    <affects>
      <package>
	<name>ikiwiki</name>
	<range><lt>2.42</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The ikiwiki development team reports:</p>
	<blockquote cite="http://ikiwiki.info/security/#index31h2">
	  <p>Cross Site Request Forging could be used to construct a link
	  that would change a logged-in user's password or other preferences
	  if they clicked on the link. It could also be used to construct a
	  link that would cause a wiki page to be modified by a logged-in
	  user.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://ikiwiki.info/security/#index31h2</url>
    </references>
    <dates>
      <discovery>2008-04-10</discovery>
      <entry>2008-04-13</entry>
    </dates>
  </vuln>

  <vuln vid="072a53e0-0397-11dd-bd06-0017319806e7">
    <topic>postfix-policyd-weight -- working directory symlink vulnerability</topic>
    <affects>
      <package>
	<name>postfix-policyd-weight</name>
	<range><lt>0.1.14.17</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>postfix-policyd-weight does not check for symlink for its working
	  directory.  If the working directory is not already setup by the
	  super root, an unprivileged user can link it to another directories
	  in the system.  This results in ownership/permission changes on the
	  target directory.</p>
      </body>
    </description>
    <references>
      <bid>28480</bid>
      <mlist>http://article.gmane.org/gmane.mail.postfix.policyd-weight/815</mlist>
      <mlist>http://article.gmane.org/gmane.mail.postfix.policyd-weight/823</mlist>
    </references>
    <dates>
      <discovery>2008-03-24</discovery>
      <entry>2008-04-06</entry>
    </dates>
  </vuln>

  <vuln vid="b21790a5-02fb-11dd-bd06-0017319806e7">
    <topic>powerdns-recursor -- DNS cache poisoning</topic>
    <affects>
      <package>
	<name>powerdns-recursor</name>
	<range><lt>3.1.5</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>If the system random number generator can be predicted by its
	  past output, then an attacker may spoof Recursor to accept mallicious
	  data.  This leads to DNS cache poisoning and client redirection.</p>
      </body>
    </description>
    <references>
      <url>http://doc.powerdns.com/security-policy.html</url>
    </references>
    <dates>
      <discovery>2008-03-31</discovery>
      <entry>2008-04-05</entry>
    </dates>
  </vuln>

  <vuln vid="fb672330-02db-11dd-bd06-0017319806e7">
    <topic>suphp -- multiple local privilege escalation vulnerabilities</topic>
    <affects>
      <package>
	<name>suphp</name>
	<range><lt>0.6.3</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Multiple local privilege escalation are found in the symlink
	  verification code.  An attacker may use it to run a PHP script with
	  the victim's privilege.  This attack is a little harder when suphp
	  operates in paranoid mode.  For suphp that runs in owner mode
	  which is the default in ports, immediate upgrade to latest
	  version is advised.</p>
      </body>
    </description>
    <references>
      <bid>28568</bid>
      <url>http://lists.marsching.biz/pipermail/suphp/2008-March/001750.html</url>
    </references>
    <dates>
      <discovery>2008-03-30</discovery>
      <entry>2008-04-05</entry>
    </dates>
  </vuln>

  <vuln vid="ad4a00fa-0157-11dd-8bd3-001372ae3ab9">
    <topic>opera -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>opera</name>
	<range><lt>9.27.20080331</lt></range>
      </package>
      <package>
	<name>linux-opera</name>
	<range><lt>9.27.20080331</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Opera Software reports of multiple security issues in Opera.
	  All of them can lead to arbitrary code execution.  Details are
	  as the following:</p>
	<ul>
	  <li><a href="http://www.opera.com/support/search/view/881/">Newsfeed
	    prompt can cause Opera to execute arbitrary code</a></li>
	  <li><a href="http://www.opera.com/support/search/view/882/">Resized
	    canvas patterns can cause Opera to execute arbitrary code</a></li>
	</ul>
      </body>
    </description>
    <references>
      <bid>28585</bid>
      <url>http://www.opera.com/support/search/view/881/</url>
      <url>http://www.opera.com/support/search/view/882/</url>
    </references>
    <dates>
      <discovery>2008-04-03</discovery>
      <entry>2008-04-05</entry>
    </dates>
  </vuln>

  <vuln vid="12b336c6-fe36-11dc-b09c-001c2514716c">
    <topic>mozilla -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>firefox</name>
	<range><lt>2.0.0.13,1</lt></range>
      </package>
      <package>
	<name>linux-firefox</name>
	<range><lt>2.0.0.13</lt></range>
      </package>
      <package>
	<name>seamonkey</name>
	<name>linux-seamonkey</name>
	<range><lt>1.1.9</lt></range>
      </package>
      <package>
	<name>flock</name>
	<name>linux-flock</name>
	<range><lt>1.1.1</lt></range>
      </package>
      <package>
	<name>linux-firefox-devel</name>
	<name>linux-seamonkey-devel</name>
	<range><gt>0</gt></range>
      </package>
      <package>
	<name>thunderbird</name>
	<name>linux-thunderbird</name>
	<range><lt>2.0.0.14</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Mozilla Foundation reports of multiple security issues
	  in Firefox, Seamonkey, and Thunderbird.  Several of these
	  issues can probably be used to run arbitrary code with the
	  privilege of the user running the program.</p>
	<blockquote cite="http://www.mozilla.org/projects/security/known-vulnerabilities.html">
	  <ul>
	    <li><a href="/security/announce/2008/mfsa2008-19.html">MFSA 2008-19</a>
	      XUL popup spoofing variant (cross-tab popups)</li>
	    <li><a href="/security/announce/2008/mfsa2008-18.html">MFSA 2008-18</a>
	      Java socket connection to any local port via LiveConnect</li>
	    <li><a href="/security/announce/2008/mfsa2008-17.html">MFSA 2008-17</a>
	      Privacy issue with SSL Client Authentication</li>
	    <li><a href="/security/announce/2008/mfsa2008-16.html">MFSA 2008-16</a>
	      HTTP Referrer spoofing with malformed URLs</li>
	    <li><a href="/security/announce/2008/mfsa2008-15.html">MFSA 2008-15</a>
	      Crashes with evidence of memory corruption (rv:1.8.1.13)</li>
	    <li><a href="/security/announce/2008/mfsa2008-14.html">MFSA 2008-14</a>
	      JavaScript privilege escalation and arbitrary code execution</li>
	  </ul>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>28448</bid>
      <cvename>CVE-2008-1241</cvename>
      <cvename>CVE-2008-1240</cvename>
      <cvename>CVE-2007-4879</cvename>
      <cvename>CVE-2008-1238</cvename>
      <cvename>CVE-2008-1236</cvename>
      <cvename>CVE-2008-1237</cvename>
      <cvename>CVE-2008-1233</cvename>
      <cvename>CVE-2008-1234</cvename>
      <cvename>CVE-2008-1235</cvename>
    </references>
    <dates>
      <discovery>2008-03-26</discovery>
      <entry>2008-03-30</entry>
      <modified>2008-05-03</modified>
    </dates>
  </vuln>

  <vuln vid="ff304c35-fb5b-11dc-91c1-00e0815b8da8">
    <topic>silc -- pkcs_decode buffer overflow</topic>
    <affects>
      <package>
	<name>silc-irssi-client</name>
	<name>silc-client</name>
	<range><lt>1.1.4</lt></range>
      </package>
      <package>
	<name>silc-server</name>
	<range><lt>1.1.2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Core Security Technologies reports:</p>
	<blockquote cite="http://www.coresecurity.com/?action=item&amp;id=2206">
	  <p>A remote buffer overflow vulnerability found in a library
	    used by both the SILC server and client to process
	    packets containing cryptographic material may allow an
	    un-authenticated client to executearbitrary code on the
	    server with the privileges of the user account running the
	    server, or a malicious SILC server to compromise client
	    systems and execute arbitrary code with the privileges of
	    the user account running the SILC client program.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>28373</bid>
      <url>http://www.coresecurity.com/?action=item&amp;id=2206</url>
    </references>
    <dates>
      <discovery>2008-03-25</discovery>
      <entry>2008-03-26</entry>
    </dates>
  </vuln>

  <vuln vid="063399fc-f6d6-11dc-bcee-001c2514716c">
    <topic>bzip2 -- crash with certain malformed archive files</topic>
    <affects>
      <package>
	<name>bzip2</name>
	<range><lt>1.0.5</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>SecurityFocus reports:</p>
	<blockquote cite="http://www.securityfocus.com/bid/28286/">
	  <p>The 'bzip2' application is prone to a remote file-handling
	    vulnerability because the application fails to properly
	    handle malformed files.</p>
	  <p>Exploit attempts likely result in application crashes.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>28286</bid>
      <cvename>CVE-2008-1372</cvename>
      <url>https://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html</url>
      <url>http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/</url>
    </references>
    <dates>
      <discovery>2008-03-18</discovery>
      <entry>2008-03-20</entry>
    </dates>
  </vuln>

  <vuln vid="9cfbca7f-efb7-11dc-be01-0211060005df">
    <topic>qemu -- unchecked block read/write vulnerability</topic>
    <affects>
      <package>
	<name>qemu</name>
	<name>qemu-devel</name>
	<range><lt>0.9.1_2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Ian Jackson reports on the debian-security mailinglist:</p>
	<blockquote cite="http://lists.debian.org/debian-security/2008/02/msg00064.html">
	  <p>When a block device read or write request is made by the guest,
	    nothing checks that the request is within the range supported by
	    the backend, but the code in the backend typically assumes that
	    the request is sensible.</p>
	  <p>Depending on the backend, this can allow the guest to read
	    and write arbitrary memory locations in qemu, and possibly gain
	    control over the qemu process, escaping from the
	    emulation/virtualisation.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-0928</cvename>
      <url>http://secunia.com/advisories/29172</url>
      <url>http://secunia.com/advisories/29081</url>
      <mlist msgid="18362.62578.44273.779731@mariner.uk.xensource.com">http://lists.debian.org/debian-security/2008/02/msg00064.html</mlist>
    </references>
    <dates>
      <discovery>2008-02-19</discovery>
      <entry>2008-03-11</entry>
    </dates>
  </vuln>

  <vuln vid="b39bdc06-ee42-11dc-8678-00a0cce0781e">
    <topic>dovecot -- security hole in blocking passdbs</topic>
    <affects>
      <package>
	<name>dovecot</name>
	<range><lt>1.0.13</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Dovecot reports:</p>
	<blockquote cite="http://dovecot.org/list/dovecot-news/2008-March/000065.html">
	  <p>Security hole in blocking passdbs (MySQL always. PAM, passwd
	    and shadow if blocking=yes) where user could specify extra
	    fields in the password. The main problem here is when specifying
	    "skip_password_check" introduced in v1.0.11 for fixing master user
	    logins, allowing the user to log in as anyone without a valid
	    password.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://dovecot.org/list/dovecot-news/2008-March/000065.html</url>
      <url>http://secunia.com/advisories/29295/</url>
    </references>
    <dates>
      <discovery>2008-03-09</discovery>
      <entry>2008-03-10</entry>
    </dates>
  </vuln>

  <vuln vid="de4d4110-ebce-11dc-ae14-0016179b2dd5">
    <topic>mplayer -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>mplayer</name>
	<name>mplayer-esound</name>
	<name>mplayer-gtk</name>
	<name>mplayer-gtk2</name>
	<name>mplayer-gtk-esound</name>
	<name>mplayer-gtk2-esound</name>
	<range><lt>0.99.11_2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Mplayer team reports:</p>
	<blockquote cite="http://www.mplayerhq.hu/design7/news.html">
	  <p>A buffer overflow was found in the code used to extract album
	    titles from CDDB server answers. When parsing answers from the
	    CDDB server, the album title is copied into a fixed-size buffer
	    with insufficient size checks, which may cause a buffer overflow.
	    A malicious database entry could trigger a buffer overflow in the
	    program. That can lead to arbitrary code execution with the UID of
	    the user running MPlayer.</p>
	  <p>A buffer overflow was found in the code used to escape URL
	    strings. The code used to skip over IPv6 addresses can be tricked
	    into leaving a pointer to a temporary buffer with a non-NULL value;
	    this causes the unescape code to reuse the buffer, and may lead to
	    a buffer overflow if the old buffer is smaller than required.
	    A malicious URL string may be used to trigger a buffer overflow in
	    the program, that can lead to arbitrary code execution with the UID
	    of the user running MPlayer.</p>
	  <p>A buffer overflow was found in the code used to parse MOV file
	    headers. The code read some values from the file and used them as
	    indexes into as array allocated on the heap without performing any
	    boundary check. A malicious file may be used to trigger a buffer
	    overflow in the program. That can lead to arbitrary code execution
	    with the UID of the user running MPlayer.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-0485</cvename>
      <cvename>CVE-2008-0486</cvename>
      <cvename>CVE-2008-0629</cvename>
      <cvename>CVE-2008-0630</cvename>
      <url>http://secunia.com/advisories/28779</url>
    </references>
    <dates>
      <discovery>2008-02-05</discovery>
      <entry>2008-03-06</entry>
    </dates>
  </vuln>

  <vuln vid="ca8e56d5-e856-11dc-b5af-0017319806e7">
    <topic>ghostscript -- zseticcspace() function buffer overflow vulnerability</topic>
    <affects>
      <package>
	<name>ghostscript-gpl</name>
	<name>ghostscript-gpl-nox11</name>
	<range><lt>8.61_2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Chris Evans from the Google Security Team reports:</p>
	<blockquote cite="http://scary.beasts.org/security/CESA-2008-001.html">
	  <p>Severity: parsing of evil PostScript file will result in
	    arbitrary code execution.</p>
	  <p>A stack-based buffer overflow in the zseticcspace() function
	    in zicc.c allows remote arbitrary code execution via a
	    malicious PostScript file (.ps) that contains a long Range
	    array.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>28017</bid>
      <cvename>CVE-2008-0411</cvename>
      <url>http://scary.beasts.org/security/CESA-2008-001.html</url>
    </references>
    <dates>
      <discovery>2008-02-28</discovery>
      <entry>2008-03-05</entry>
    </dates>
  </vuln>

  <vuln vid="ce2f2ade-e7df-11dc-a701-000bcdc1757a">
    <topic>phpmyadmin -- SQL injection vulnerability</topic>
    <affects>
      <package>
	<name>phpmyadmin</name>
	<range><lt>2.11.5</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>A phpMyAdmin security announcement report:</p>
	<blockquote cite="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1">
	  <p>phpMyAdmin used the $_REQUEST superglobal as a source for
	    its parameters, instead of $_GET and $_POST. This means that
	    on most servers, a cookie with the same name as one of
	    phpMyAdmin's parameters can interfere.</p>
	  <p>Another application could set a cookie for the root path
	    "/" with a "sql_query" name, therefore overriding the
	    user-submitted sql_query because by default, the $_REQUEST
	    superglobal imports first GET, then POST then COOKIE data.</p>
	  <h3>Mitigation factor</h3>
	  <p>An attacker must trick the victim into visiting a page on
	    the same web server where he has placed code that creates
	    a malicious cookie.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>28068</bid>
      <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1</url>
    </references>
    <dates>
      <discovery>2008-03-01</discovery>
      <entry>2008-03-04</entry>
    </dates>
  </vuln>

  <vuln vid="f9e96930-e6df-11dc-8c6a-00304881ac9a">
    <topic>pcre -- buffer overflow vulnerability</topic>
    <affects>
      <package>
	<name>pcre</name>
	<range><lt>7.6</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>PCRE developers report:</p>
	<blockquote cite="http://pcre.org/changelog.txt">
	  <p>A character class containing a very large number of characters with
	    codepoints greater than 255 (in UTF-8 mode, of course) caused a
	    buffer overflow.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>27786</bid>
      <cvename>CVE-2008-0674</cvename>
      <url>http://pcre.org/changelog.txt</url>
    </references>
    <dates>
      <discovery>2008-01-28</discovery>
      <entry>2008-02-29</entry>
    </dates>
  </vuln>

  <vuln vid="e8a6a16d-e498-11dc-bb89-000bcdc1757a">
    <topic>libxine -- buffer overflow vulnerability</topic>
    <affects>
      <package>
	<name>libxine</name>
	<range><lt>1.1.10.1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>xine Team reports:</p>
	<blockquote cite="http://www.xinehq.de/index.php/news">
	  <p>A new xine-lib version is now available. This release
	   contains a security fix (array index vulnerability which
	   may lead to a stack buffer overflow.</p>
	</blockquote>
      </body>
    </description>
    <references>
       <cvename>CVE-2008-0486</cvename>
       <url>http://www.xinehq.de/index.php/news</url>
    </references>
    <dates>
      <discovery>2007-02-08</discovery>
      <entry>2008-02-26</entry>
    </dates>
  </vuln>

  <vuln vid="9f581778-e3d4-11dc-bb89-000bcdc1757a">
    <topic>coppermine - multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>coppermine</name>
	<range><lt>1.4.15</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Coppermine Security advisory</p>
	<blockquote cite="http://coppermine-gallery.net/forum/index.php?topic=48106.0">
	  <p>The development team is releasing a security update for
	   Coppermine in order to counter a recently discovered
	   cross-site-scripting vulnerability.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-0504</cvename>
      <cvename>CVE-2008-0505</cvename>
      <cvename>CVE-2008-0506</cvename>
      <url>http://coppermine-gallery.net/forum/index.php?topic=48106.0</url>
      <url>http://coppermine-gallery.net/forum/index.php?topic=50103.0</url>
      <url>http://secunia.com/advisories/28682/</url>
    </references>
    <dates>
      <discovery>2007-11-06</discovery>
      <entry>2008-02-25</entry>
    </dates>
  </vuln>

  <vuln vid="f113bbeb-e3ac-11dc-bb89-000bcdc1757a">
    <topic>moinmoin - multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>moinmoin</name>
	<range><lt>1.6.1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>MoinMoin Security advisory</p>
	<blockquote cite="http://moinmo.in/SecurityFixes">
	  <p>XSS issue in login action</p>
	  <p>XSS issue in AttachFile action</p>
	  <p>XSS issue in RenamePage/DeletePage action</p>
	  <p>XSS issue in gui editor</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>27404</bid>
      <cvename>CVE-2007-0857</cvename>
      <cvename>CVE-2007-0901</cvename>
      <cvename>CVE-2007-0902</cvename>
      <cvename>CVE-2007-2423</cvename>
      <cvename>CVE-2007-2673</cvename>
      <cvename>CVE-2008-0780</cvename>
      <cvename>CVE-2008-0781</cvename>
      <cvename>CVE-2008-0782</cvename>
      <url>http://moinmo.in/SecurityFixes</url>
      <url>http://secunia.com/advisories/29010/</url>
    </references>
    <dates>
      <discovery>2007-02-08</discovery>
      <entry>2008-02-25</entry>
      <modified>2008-02-26</modified>
    </dates>
  </vuln>

  <vuln vid="30c560ff-e0df-11dc-891a-02061b08fc24">
    <topic>opera -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>opera</name>
	<name>opera-devel</name>
	<name>linux-opera</name>
	<range><lt>9.26</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Opera Software ASA reports about multiple security
	  fixes:</p>
	<blockquote cite="http://www.opera.com/docs/changelogs/freebsd/925/">
	  <ul>
	    <li>Fixed an issue where simulated text inputs could trick
	      users into uploading arbitrary files, as reported by
	      Mozilla.</li>
	    <li>Image properties can no longer be used to execute
	      scripts, as reported by Max Leonov.</li>
	    <li>Fixed an issue where the representation of DOM
	      attribute values could allow cross site scripting, as
	      reported by Arnaud.lb.</li>
	  </ul>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://www.opera.com/docs/changelogs/freebsd/926/</url>
      <url>http://www.opera.com/support/search/view/877/</url>
      <url>http://www.opera.com/support/search/view/879/</url>
      <url>http://www.opera.com/support/search/view/880/</url>
     </references>
    <dates>
      <discovery>2008-02-20</discovery>
      <entry>2008-02-22</entry>
    </dates>
  </vuln>

  <vuln vid="810a5197-e0d9-11dc-891a-02061b08fc24">
    <topic>mozilla -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>firefox</name>
	<range><lt>2.0.0.12,1</lt></range>
      </package>
      <package>
	<name>linux-firefox</name>
	<range><lt>2.0.0.12</lt></range>
      </package>
      <package>
	<name>seamonkey</name>
	<name>linux-seamonkey</name>
	<range><lt>1.1.8</lt></range>
      </package>
      <package>
	<name>flock</name>
	<name>linux-flock</name>
	<range><lt>1.0.9</lt></range>
      </package>
      <package>
	<name>linux-firefox-devel</name>
	<name>linux-seamonkey-devel</name>
	<range><gt>0</gt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Mozilla Foundation reports of multiple security issues
	  in Firefox, Seamonkey, and Thunderbird.  Several of these
	  issues can probably be used to run arbitrary code with the
	  privilege of the user running the program.</p>
	<blockquote cite="http://www.mozilla.org/projects/security/known-vulnerabilities.html">
	  <ul>
	    <li>Web forgery overwrite with div overlay</li>
	    <li>URL token stealing via stylesheet redirect</li>
	    <li>Mishandling of locally-saved plain text files</li>
	    <li>File action dialog tampering</li>
	    <li>Possible information disclosure in BMP decoder</li>
	    <li>Web browsing history and forward navigation stealing</li>
	    <li>Directory traversal via chrome: URI</li>
	    <li>Stored password corruption</li>
	    <li>Privilege escalation, XSS, Remote Code Execution</li>
	    <li>Multiple file input focus stealing vulnerabilities</li>
	    <li>Crashes with evidence of memory corruption (rv:1.8.1.12)</li>
	  </ul>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-0412</cvename>
      <cvename>CVE-2008-0413</cvename>
      <cvename>CVE-2008-0414</cvename>
      <cvename>CVE-2008-0415</cvename>
      <cvename>CVE-2008-0417</cvename>
      <cvename>CVE-2008-0418</cvename>
      <cvename>CVE-2008-0419</cvename>
      <cvename>CVE-2008-0420</cvename>
      <cvename>CVE-2008-0591</cvename>
      <cvename>CVE-2008-0592</cvename>
      <cvename>CVE-2008-0593</cvename>
      <cvename>CVE-2008-0594</cvename>
      <url>http://www.mozilla.org/projects/security/known-vulnerabilities.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-01.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-02.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-03.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-04.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-05.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-06.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-07.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-08.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-09.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-10.html</url>
      <url>http://www.mozilla.org/security/announce/2008/mfsa2008-11.html</url>
    </references>
    <dates>
      <discovery>2008-02-07</discovery>
      <entry>2008-02-22</entry>
    </dates>
  </vuln>

  <vuln vid="e5d29309-e0db-11dc-97b2-001c2514716c">
    <topic>openldap -- modrdn Denial of Service vulnerability</topic>
    <affects>
      <package>
	<name>openldap-server</name>
	<range><lt>2.3.41</lt></range>
	<range><gt>2.4.0</gt><lt>2.4.8</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia Advisory reports:</p>
	<blockquote cite="http://secunia.com/advisories/28926/">
	  <p>A vulnerability has been reported in OpenLDAP, which can
	    be exploited by malicious users to cause a DoS (Denial of
	    Service).</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>27778</bid>
      <cvename>CVE-2008-0658</cvename>
    </references>
    <dates>
      <discovery>2008-02-13</discovery>
      <entry>2008-02-22</entry>
    </dates>
  </vuln>

  <vuln vid="be4b0529-dbaf-11dc-9791-000ea6702141">
    <topic>clamav -- ClamAV libclamav PE File Integer Overflow Vulnerability</topic>
    <affects>
      <package>
	<name>clamav</name>
	<range><ge>0.92</ge><lt>0.92.1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>iDefense Security Advisory 02.12.08:</p>
	<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=658">
	  <p>Remote exploitation of an integer overflow vulnerability
	    in Clam AntiVirus' ClamAV, as included in various vendors'
	    operating system distributions, allows attackers to execute
	    arbitrary code with the privileges of the affected process.</p>
	  <p>The vulnerability exists within the code responsible
	    for parsing and scanning PE files. While iterating through
	    all sections contained in the PE file, several attacker
	    controlled values are extracted from the file. On each iteration,
	    arithmetic operations are performed without taking into
	    consideration 32-bit integer wrap.</p>
	  <p>Since insufficient integer overflow checks are present,
	    an attacker can cause a heap overflow by causing a specially
	    crafted Petite packed PE binary to be scanned. This results
	    in an exploitable memory corruption condition.</p>
	  <p>Exploitation of this vulnerability results in the
	    execution of arbitrary code with the privileges of the process
	    using libclamav. In the case of the clamd program, this will
	    result in code execution with the privileges of the clamav user.
	    Unsuccessful exploitation results in the clamd process crashing.</p>
	</blockquote>
	<h1>Workaround</h1>
	<p>Disabling the scanning of PE files will prevent exploitation.</p>
	<p>If using clamscan, this can be done by running clamscan with the
	  '--no-pe' option.</p>
	<p>If using clamdscan, set the 'ScanPE' option in the clamd.conf
	  file to 'no'.</p>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-0318</cvename>
      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=658</url>
      <url>http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog</url>
    </references>
    <dates>
      <discovery>2008-01-07</discovery>
      <entry>2008-02-15</entry>
    </dates>
  </vuln>

  <vuln vid="dea7df85-d96c-11dc-9bfc-000e0c092e7a">
    <topic>cacti -- Multiple security vulnerabilities have been discovered</topic>
    <affects>
      <package>
	<name>cacti</name>
	<range><lt>0.8.7b</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The cacti development team reports:</p>
	<blockquote cite="http://forums.cacti.net/about25749.html">
	  <p>Multiple security vulnerabilities have been discovered in
	    Cacti's web interface:</p>
	    <ul>
	      <li>XSS vulnerabilities</li>
	      <li>Path disclosure vulnerabilities</li>
	      <li>SQL injection vulnerabilities</li>
	      <li>HTTP response splitting vulnerabilities</li>
	    </ul>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://forums.cacti.net/about25749.html</url>
    </references>
    <dates>
      <discovery>2008-02-12</discovery>
      <entry>2008-02-12</entry>
    </dates>
  </vuln>

  <vuln vid="739329c8-d8f0-11dc-ac2f-0016d325a0ed">
    <topic>ikiwiki -- javascript insertion via uris</topic>
    <affects>
      <package>
	<name>ikiwiki</name>
	<range><lt>2.32.3</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The ikiwiki development team reports:</p>
	<blockquote cite="http://ikiwiki.info/security/#index30h2">
	  <p>The htmlscrubber did not block javascript in uris.  This was
	  fixed by adding a whitelist of valid uri types, which does not
	  include javascript.  Some urls specifyable by the meta plugin
	  could also theoretically have been used to inject javascript; this
	  was also blocked.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://ikiwiki.info/security/#index30h2</url>
    </references>
    <dates>
      <discovery>2008-02-10</discovery>
      <entry>2008-02-11</entry>
    </dates>
  </vuln>

  <vuln vid="1a818749-d646-11dc-8959-000bcdc1757a">
    <topic>zenphoto -- XSS vulnerability</topic>
    <affects>
      <package>
	<name>zenphoto</name>
	<range><lt>1.1.4</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>zenphoto project reports:</p>
	<blockquote cite="http://www.zenphoto.org/2008/02/">
	  <p>A new zenphoto version is now available. This release contains
	   security fixes for HTML, XSS, and SQL injection vulnerabilities.
	   </p>
	</blockquote>
      </body>
    </description>
    <references>
	<cvename>CVE-2007-6666</cvename>
	<url>http://www.securityfocus.com/bid/27084</url>
	<url>http://secunia.com/advisories/28281</url>
    </references>
    <dates>
      <discovery>2008-01-03</discovery>
      <entry>2008-02-09</entry>
    </dates>
  </vuln>

  <vuln vid="0832ee18-cf77-11dc-8c6a-00304881ac9a">
    <topic>jetty -- multiple vulnerability</topic>
    <affects>
      <package>
	<name>jetty</name>
	<range><lt>6.1.7</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Greg Wilkins reports:</p>
	<blockquote cite="http://jira.codehaus.org/browse/JETTY-386#action_117699">
	  <p>jetty allows remote attackers to bypass protection mechanisms and
	    read the source of files via multiple '/' characters in the URI.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>27117</bid>
      <cvename>CVE-2007-6672</cvename>
      <url>http://jira.codehaus.org/browse/JETTY-386#action_117699</url>
    </references>
    <dates>
      <discovery>2007-12-22</discovery>
      <entry>2008-02-04</entry>
    </dates>
  </vuln>

  <vuln vid="6ecd0b42-ce77-11dc-89b1-000e35248ad7">
    <topic>libxine -- buffer overflow vulnerability</topic>
    <affects>
      <package>
	<name>libxine</name>
	<range><lt>1.1.10</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>xine project reports:</p>
	<blockquote cite="http://xinehq.de/index.php/news">
	  <p>A new xine-lib version is now available. This release contains
	    a security fix (remotely-expoitable buffer overflow, CVE-2006-1664).
	    (This is not the first time that that bug has been fixed...)
	    It also fixes a few more recent bugs, such as the audio output
	    problems in 1.1.9.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2006-1664</cvename>
      <url>http://secunia.com/advisories/19853/</url>
    </references>
    <dates>
      <discovery>2008-01-23</discovery>
      <entry>2008-01-29</entry>
    </dates>
  </vuln>

  <vuln vid="fe2b6597-c9a4-11dc-8da8-0008a18a9961">
    <topic>xorg -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>xorg-server</name>
	<range><lt>1.4_4,1</lt></range>
      </package>
      <package>
	<name>libXfont</name>
	<range><lt>1.3.1_2,1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Matthieu Herrb of X.Org reports:</p>
	<blockquote cite="http://lists.freedesktop.org/archives/xorg/2008-January/031918.html">
	  <p>Several vulnerabilities have been identified in server code
	    of the X window system caused by lack of proper input validation
	    on user controlled data in various parts of the software,
	    causing various kinds of overflows.</p>
	  <p>Exploiting these overflows will crash the X server or,
	    under certain circumstances allow the execution of arbitray
	    machine code.</p>
	  <p>When the X server is running with root privileges (which is the
	    case for the Xorg server and for most kdrive based servers),
	    these vulnerabilities can thus also be used to raise
	    privileges.</p>
	  <p>All these vulnerabilities, to be exploited succesfully, require
	    either an already established connection to a running X server
	    (and normally running X servers are only accepting authenticated
	    connections), or a shell access with a valid user on the machine
	    where the vulnerable server is installed.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-5760</cvename>
      <cvename>CVE-2007-5958</cvename>
      <cvename>CVE-2007-6427</cvename>
      <cvename>CVE-2007-6428</cvename>
      <cvename>CVE-2007-6429</cvename>
      <cvename>CVE-2008-0006</cvename>
      <url>http://lists.freedesktop.org/archives/xorg/2008-January/031918.html</url>
      <url>http://lists.freedesktop.org/archives/xorg/2008-January/032099.html</url>
      <url>http://secunia.com/advisories/28532/</url>
    </references>
    <dates>
      <discovery>2008-01-18</discovery>
      <entry>2008-01-23</entry>
    </dates>
  </vuln>

  <vuln vid="024edd06-c933-11dc-810c-0016179b2dd5">
    <topic>xfce -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>xfce4-panel</name>
	<name>libxfce4gui</name>
	<range><lt>4.4.2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Gentoo reports:</p>
	<blockquote cite="http://www.gentoo.org/security/en/glsa/glsa-200801-06.xml">
	  <p>A remote attacker could entice a user to install a specially
	    crafted "rc" file to execute arbitrary code via long strings
	    in the "Name" and "Comment" fields or via unspecified vectors
	    involving the second vulnerability.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6531</cvename>
      <cvename>CVE-2007-6532</cvename>
      <url>http://www.xfce.org/documentation/changelogs/4.4.2</url>
      <url>http://www.gentoo.org/security/en/glsa/glsa-200801-06.xml</url>
    </references>
    <dates>
      <discovery>2008-01-09</discovery>
      <entry>2008-01-22</entry>
      <modified>2008-02-13</modified>
    </dates>
  </vuln>

  <vuln vid="a59afa47-c930-11dc-810c-0016179b2dd5">
    <topic>claws-mail -- insecure temporary file creation</topic>
    <affects>
      <package>
	<name>claws-mail</name>
	<range><lt>3.1.0</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Nico Golde reports:</p>
	<blockquote cite="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=454089">
	  <p>A local attacker could exploit this vulnerability to conduct
	    symlink attacks to overwrite files with the privileges of the user
	    running Claws Mail.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26676</bid>
      <cvename>CVE-2007-6208</cvename>
      <url>http://www.gentoo.org/security/en/glsa/glsa-200801-03.xml</url>
      <url>http://security.gentoo.org/glsa/glsa-200801-03.xml</url>
      <url>http://secunia.com/advisories/27897</url>
    </references>
    <dates>
      <discovery>2007-12-03</discovery>
      <entry>2008-01-22</entry>
      <modified>2008-02-12</modified>
    </dates>
  </vuln>

  <vuln vid="e5a9de5f-c6bc-11dc-b9f1-00a0cce0781e">
    <topic>IRC Services-- Denial of Service Vulnerability</topic>
    <affects>
      <package>
	<name>ircservices</name>
	<range><lt>5.0.63</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/27761">
	  <p>A vulnerability has been reported in IRC Services,
	    which can be exploited by malicious people to cause
	    a Denial of Service. The vulnerability is caused due
	    to the improper handling of overly long passwords within
	    the "default_encrypt()" function in encrypt.c and can be
	    exploited to crash an affected server.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6122</cvename>
      <url>http://secunia.com/advisories/27761</url>
      <url>http://ircservices.za.net/Changes.txt</url>
    </references>
    <dates>
      <discovery>2007-11-21</discovery>
      <entry>2008-01-19</entry>
    </dates>
  </vuln>

  <vuln vid="02eedd3c-c6b5-11dc-93b6-000e35248ad7">
    <topic>libxine -- buffer overflow vulnerability</topic>
    <affects>
      <package>
	<name>libxine</name>
	<range><lt>1.1.9.1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>xine project reports:</p>
	<blockquote cite="http://xinehq.de/index.php/news">
	  <p>A new xine-lib version is now available. This release contains
	    a security fix (remotely-expoitable buffer overflow, CVE-2008-0225).
	    It also contains a read-past-end fix for an internal library
	    function which is only used if the OS does not supply it and a
	    rendering fix for Darwin/PPC.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-0225</cvename>
      <url>http://aluigi.altervista.org/adv/xinermffhof-adv.txt</url>
      <url>http://secunia.com/advisories/28384</url>
    </references>
    <dates>
      <discovery>2008-01-08</discovery>
      <entry>2008-01-19</entry>
    </dates>
  </vuln>

  <vuln vid="60e1792b-c380-11dc-821a-000bcdc1757a">
    <topic>geeklog xss vulnerability</topic>
    <affects>
      <package>
	<name>geeklog</name>
	<range><lt>1.4.1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Geeklog reports:</p>
	<blockquote cite="http://www.geeklog.net/article.php/geeklog-1.4.0sr6">
	  <p>MustLive pointed out a possible XSS in the form to email an
	    article to a friend that we're fixing with this release.</p>
	  <p>Please note that this problem only exists in Geeklog 1.4.0
	    - neither Geeklog 1.4.1 nor any older versions (1.3.x series)
	    have that problem.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2006-3756</cvename>
      <url>http://www.geeklog.net/article.php/geeklog-1.4.0sr6</url>
    </references>
    <dates>
      <discovery>2008-01-08</discovery>
      <entry>2008-01-15</entry>
    </dates>
  </vuln>

  <vuln vid="4451a4c9-c05e-11dc-982e-001372fd0af2">
    <topic>drupal -- cross site request forgery</topic>
    <affects>
      <package>
	<name>drupal5</name>
	<range><lt>5.6</lt></range>
      </package>
      <package>
	<name>drupal4</name>
	<range><lt>4.7.11</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Drupal Project reports:</p>
	<blockquote cite="http://drupal.org/node/208562">
	  <p>The aggregator module fetches items from RSS feeds and makes
	    them available on the site. The module provides an option to
	    remove items from a particular feed. This has been implemented
	    as a simple GET request and is therefore vulnerable to cross
	    site request forgeries. For example: Should a privileged user
	    view a page containing an &lt;img&gt; tag with a specially
	    constructed src pointing to a remove items URL, the items would
	    be removed.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://drupal.org/node/208562</url>
      <url>http://secunia.com/advisories/28422/</url>
    </references>
    <dates>
      <discovery>2008-01-10</discovery>
      <entry>2008-01-11</entry>
    </dates>
  </vuln>

  <vuln vid="6f736456-c060-11dc-982e-001372fd0af2">
    <topic>drupal -- cross site scripting (utf8)</topic>
    <affects>
      <package>
	<name>drupal5</name>
	<range><lt>5.6</lt></range>
      </package>
      <package>
	<name>drupal4</name>
	<range><lt>4.7.11</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Drupal Project reports:</p>
	<blockquote cite="http://drupal.org/node/208564">
	  <p>When outputting plaintext Drupal strips potentially dangerous
	    HTML tags and attributes from HTML, and escapes characters which
	    have a special meaning in HTML. This output filtering secures
	    the site against cross site scripting attacks via user input.</p>
	  <p>Certain byte sequences that are invalid in the UTF8
	    specification are not handled properly by Internet Explorer 6
	    and may lead it to see a multibyte start character where none is
	    present. Internet Explorer 6 then consumes a number of
	    subsequent UTF-8 characters. This may lead to unsafe attributes
	    that were outside a tag for the filter to appear inside a tag
	    for Internet Explorer 6. This behaviour can then be used to
	    insert and execute javascript in the context of the website.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://drupal.org/node/208564</url>
      <url>http://secunia.com/advisories/28422/</url>
    </references>
    <dates>
      <discovery>2008-01-10</discovery>
      <entry>2008-01-11</entry>
    </dates>
  </vuln>

  <vuln vid="f0fa19dd-c060-11dc-982e-001372fd0af2">
    <topic>drupal -- cross site scripting (register_globals)</topic>
    <affects>
      <package>
	<name>drupal5</name>
	<range><lt>5.6</lt></range>
      </package>
      <package>
	<name>drupal4</name>
	<range><lt>4.7.11</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Drupal Project reports:</p>
	<blockquote cite="http://drupal.org/node/208565">
	  <p>When theme .tpl.php files are accessible via the web and the PHP
	    setting register_globals is set to enabled, anonymous users are
	    able to execute cross site scripting attacks via specially
	    crafted links.</p>
	  <p>Drupal's .htaccess attempts to set register_globals to disabled
	    and also prevents access to .tpl.php files. Only when both these
	    measures are not effective and your PHP interpreter is
	    configured with register_globals set to enabled, will this issue
	    affect you.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://drupal.org/node/208565</url>
      <url>http://secunia.com/advisories/28422/</url>
    </references>
    <dates>
      <discovery>2008-01-10</discovery>
      <entry>2008-01-11</entry>
    </dates>
  </vuln>

  <vuln vid="f358de71-bf64-11dc-928b-0016179b2dd5">
    <topic>maradns -- CNAME record resource rotation denial of service</topic>
    <affects>
      <package>
	<name>maradns</name>
	<range><lt>1.2.12.08</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/28329">
	  <p>A vulnerability has been reported in MaraDNS, which can be
	    exploited by malicious people to cause a Denial of Service.</p>
	  <p>The vulnerability is caused due to an error within the handling of
	    certain DNS packets. This can be exploited to cause a resource
	    rotation by sending specially crafted DNS packets, which cause an
	    authoritative CNAME record to not resolve, resulting in a Denial of
	    Sevices.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2008-0061</cvename>
      <url>http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html</url>
      <url>http://secunia.com/advisories/28329</url>
    </references>
    <dates>
      <discovery>2008-01-04</discovery>
      <entry>2008-01-10</entry>
    </dates>
  </vuln>

  <vuln vid="f762ccbb-baed-11dc-a302-000102cc8983">
    <topic>linux-realplayer -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>linux-realplayer</name>
	<range><ge>10.0.5</ge><lt>10.0.9.809.20070726</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/27361">
	  <p>Multiple vulnerabilities have been reported in
	    RealPlayer/RealOne/HelixPlayer, which can be exploited by malicious
	    people to compromise a user's system.</p>
	  <p>An input validation error when processing .RA/.RAM files can be
	    exploited to cause a heap corruption via a specially crafted
	    .RA/.RAM file with an overly large size field in the header.</p>
	  <p>An error in the processing of .PLS files can be exploited to cause
	    a memory corruption and execute arbitrary code via a specially
	    crafted .PLS file.</p>
	  <p>An input validation error when parsing .SWF files can be exploited
	    to cause a buffer overflow via a specially crafted .SWF file with
	    malformed record headers.</p>
	  <p>A boundary error when processing rm files can be exploited to
	    cause a buffer overflow.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-5081</cvename>
      <cvename>CVE-2007-3410</cvename>
      <cvename>CVE-2007-2263</cvename>
      <cvename>CVE-2007-2264</cvename>
      <url>http://secunia.com/advisories/27361</url>
      <url>http://service.real.com/realplayer/security/10252007_player/en/</url>
      <url>http://www.zerodayinitiative.com/advisories/ZDI-07-063.html</url>
      <url>http://www.zerodayinitiative.com/advisories/ZDI-07-062.html</url>
      <url>http://www.zerodayinitiative.com/advisories/ZDI-07-061.html</url>
      <url>http://secunia.com/advisories/25819/</url>
      <certvu>759385</certvu>
    </references>
    <dates>
      <discovery>2007-10-25</discovery>
      <entry>2008-01-04</entry>
    </dates>
  </vuln>

  <vuln vid="562cf6c4-b9f1-11dc-a302-000102cc8983">
    <topic>linux-flashplugin -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>linux-flashplugin</name>
	<range><ge>9.0</ge><lt>9.0r115</lt></range>
	<range><ge>7.0</ge><lt>7.0r73</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Adobe Security bulletin:</p>
	<blockquote cite="http://www.adobe.com/support/security/bulletins/apsb07-20.html">
	  <p>Critical vulnerabilities have been identified in Adobe Flash
	    Player that could allow an attacker who successfully exploits these
	    potential vulnerabilities to take control of the affected system. A
	    malicious SWF must be loaded in Flash Player by the user for an
	    attacker to exploit these potential vulnerabilities. Users are
	    recommended to update to the most current version of Flash Player
	    available for their platform.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6242</cvename>
      <cvename>CVE-2007-4768</cvename>
      <cvename>CVE-2007-5275</cvename>
      <cvename>CVE-2007-6243</cvename>
      <cvename>CVE-2007-6244</cvename>
      <cvename>CVE-2007-6245</cvename>
      <cvename>CVE-2007-4324</cvename>
      <cvename>CVE-2007-6246</cvename>
      <cvename>CVE-2007-5476</cvename>
      <url>http://www.adobe.com/support/security/bulletins/apsb07-20.html</url>
      <url>http://secunia.com/advisories/28161/</url>
    </references>
    <dates>
      <discovery>2007-12-18</discovery>
      <entry>2008-01-03</entry>
    </dates>
  </vuln>

  <vuln vid="cf484358-b5d6-11dc-8de0-001c2514716c">
    <topic>dovecot -- Specific LDAP + auth cache configuration may mix up user logins</topic>
    <affects>
      <package>
	<name>dovecot</name>
	<range><lt>1.0.10</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Dovecot reports:</p>
	<blockquote cite="http://www.dovecot.org/list/dovecot-news/2007-December/000057.html">
	  <p>If two users with the same password and same pass_filter
	    variables log in within auth_cache_ttl seconds (1h by default),
	    the second user may get logged in with the first user's cached
	    pass_attrs. For example if pass_attrs contained the user's
	    home/mail directory, this would mean that the second user will
	    be accessing the first user's mails.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://www.dovecot.org/list/dovecot-news/2007-December/000057.html</url>
    </references>
    <dates>
      <discovery>2007-12-21</discovery>
      <entry>2007-12-29</entry>
    </dates>
  </vuln>

  <vuln vid="4aab7bcd-b294-11dc-a6f0-00a0cce0781e">
    <topic>gallery2 -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>gallery2</name>
	<range><lt>2.2.4</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Gallery team reports:</p>
	<blockquote cite="http://gallery.menalto.com/gallery_2.2.4_released">
	  <p>Gallery 2.2.4 addresses the following security
	    vulnerabilities:</p>
	  <ul>
	    <li>Publish XP module - Fixed unauthorized album creation
	      and file uploads.</li>
	    <li>URL rewrite module - Fixed local file inclusion
	      vulnerability in unsecured admin controller and
	      information disclosure in hotlink protection.</li>
	    <li>Core / add-item modules - Fixed Cross Site Scripting
	      (XSS) vulnerabilities through malicious file names.</li>
	    <li>Installation (Gallery application) - Update
	      web-accessibility protection of the storage folder for
	      Apache 2.2.</li>
	    <li>Core (Gallery application) / MIME module - Fixed
	      vulnerability in checks for disallowed file extensions
	      in file uploads.</li>
	    <li>Gallery Remote module - Added missing permissions
	      checks for some GR commands.</li>
	    <li>WebDAV module - Fixed Cross Site Scripting (XSS)
	      vulnerability through HTTP PROPPATCH.</li>
	    <li>WebDAV module - Fixed information (item data)
	      disclosure in a WebDAV view.</li>
	    <li>Comment module - Fixed information (item data)
	      disclosure in comment views.</li>
	    <li>Core module (Gallery application) - Improved
	      resilience against item information disclosure
	      attacks.</li>
	    <li>Slideshow module - Fixed information (item data)
	      disclosure in the slideshow.</li>
	    <li>Print modules - Fixed information (item data)
	      disclosure in several print modules.</li>
	    <li>Core / print modules - Fixed arbitrary URL redirection
	      (phishing attacks) in the core module and several print
	      modules.</li>
	    <li>WebCam module - Fixed proxied request weakness.</li>
	  </ul>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://gallery.menalto.com/gallery_2.2.4_released</url>
    </references>
    <dates>
      <discovery>2007-12-24</discovery>
      <entry>2007-12-25</entry>
      <modified>2007-12-29</modified>
    </dates>
  </vuln>

  <vuln vid="299e3f81-aee7-11dc-b781-0016179b2dd5">
    <topic>e2fsprogs -- heap buffer overflow</topic>
    <affects>
      <package>
	<name>e2fsprogs</name>
	<range><lt>1.40.3</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Theodore Y. Ts'o reports:</p>
	<blockquote cite="http://sourceforge.net/project/shownotes.php?group_id=2406&amp;release_id=560230">
	  <p>Fix a potential security vulnerability where an untrusted
	    filesystem can be corrupted in such a way that a program using
	    libext2fs will allocate a buffer which is far too small.  This
	    can lead to either a crash or potentially a heap-based buffer
	    overflow crash.  No known exploits exist, but main concern is
	    where an untrusted user who possesses privileged access in a
	    guest Xen environment could corrupt a filesystem which is then
	    accessed by thus allowing the untrusted user to gain privileged
	    access in the host OS.  Thanks to the McAfee AVERT Research group
	    for reporting this issue.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26772</bid>
      <cvename>CVE-2007-5497</cvename>
      <url>http://secunia.com/advisories/27889/</url>
      <url>http://sourceforge.net/project/shownotes.php?group_id=2406&amp;release_id=560230</url>
    </references>
    <dates>
      <discovery>2007-12-07</discovery>
      <entry>2007-12-20</entry>
    </dates>
  </vuln>

  <vuln vid="8a835235-ae84-11dc-a5f9-001a4d49522b">
    <topic>wireshark -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>wireshark</name>
	<name>wireshark-lite</name>
	<name>ethereal</name>
	<name>ethereal-lite</name>
	<name>tethereal</name>
	<name>tethereal-lite</name>
	<range><ge>0.8.16</ge><lt>0.99.7</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Wireshark team reports of multiple vulnerabilities:</p>
	<blockquote cite="http://www.wireshark.org/security/wnpa-sec-2007-03.html">
	  <ul>
	    <li>Wireshark could crash when reading an MP3 file.</li>
	    <li>Beyond Security discovered that Wireshark could loop
	      excessively while reading a malformed DNP packet.</li>
	    <li>Stefan Esser discovered a buffer overflow in the SSL
	      dissector.</li>
	    <li>The ANSI MAP dissector could be susceptible to a
	      buffer overflow on some platforms.</li>
	    <li>The Firebird/Interbase dissector could go into an
	      infinite loop or crash.</li>
	    <li>The NCP dissector could cause a crash.</li>
	    <li>The HTTP dissector could crash on some systems while
	      decoding chunked messages.</li>
	    <li>The MEGACO dissector could enter a large loop and
	      consume system resources.</li>
	    <li>The DCP ETSI dissector could enter a large loop and
	      consume system resources.</li>
	    <li>Fabiodds discovered a buffer overflow in the iSeries
	      (OS/400) Communication trace file parser.</li>
	    <li>The PPP dissector could overflow a buffer.</li>
	    <li>The Bluetooth SDP dissector could go into an infinite
	      loop.</li>
	    <li>A malformed RPC Portmap packet could cause a
	      crash.</li>
	    <li>The IPv6 dissector could loop excessively.</li>
	    <li>The USB dissector could loop excessively or crash.</li>
	    <li>The SMB dissector could crash.</li>
	    <li>The RPL dissector could go into an infinite loop.</li>
	    <li>The WiMAX dissector could crash due to unaligned
	      access on some platforms.</li>
	    <li>The CIP dissector could attempt to allocate a huge
	      amount of memory and crash.</li>
	  </ul>

	  <h2>Impact</h2>

	  <p>It may be possible to make Wireshark or Ethereal crash or
	    use up available memory by injecting a purposefully
	    malformed packet onto the wire or by convincing someone to
	    read a malformed packet trace file.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6112</cvename>
      <cvename>CVE-2007-6113</cvename>
      <cvename>CVE-2007-6114</cvename>
      <cvename>CVE-2007-6115</cvename>
      <cvename>CVE-2007-6117</cvename>
      <cvename>CVE-2007-6118</cvename>
      <cvename>CVE-2007-6120</cvename>
      <cvename>CVE-2007-6121</cvename>
      <cvename>CVE-2007-6438</cvename>
      <cvename>CVE-2007-6439</cvename>
      <cvename>CVE-2007-6441</cvename>
      <cvename>CVE-2007-6450</cvename>
      <cvename>CVE-2007-6451</cvename>
      <url>http://www.wireshark.org/security/wnpa-sec-2007-03.html</url>
    </references>
    <dates>
      <discovery>2007-12-19</discovery>
      <entry>2007-12-19</entry>
      <modified>2007-12-22</modified>
    </dates>
  </vuln>

  <vuln vid="31b045e7-ae75-11dc-a5f9-001a4d49522b">
    <topic>opera -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>opera</name>
	<name>opera-devel</name>
	<name>linux-opera</name>
	<range><lt>9.25</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Opera Software ASA reports about multiple security
	  fixes:</p>
	<blockquote cite="http://www.opera.com/docs/changelogs/freebsd/925/">
	  <ul>
	    <li>Fixed an issue where plug-ins could be used to allow
	      cross domain scripting, as reported by David
	      Bloom. Details will be disclosed at a later date.</li>
	    <li>Fixed an issue with TLS certificates that could be
	      used to execute arbitrary code, as reported by Alexander
	      Klink (Cynops GmbH). Details will be disclosed at a
	      later date.</li>
	    <li>Rich text editing can no longer be used to allow cross
	      domain scripting, as reported by David Bloom. See our
	      advisory.</li>
	    <li>Prevented bitmaps from revealing random data from
	      memory, as reported by Gynvael Coldwind. Details will be
	      disclosed at a later date.</li>
	  </ul>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6520</cvename>
      <cvename>CVE-2007-6521</cvename>
      <cvename>CVE-2007-6522</cvename>
      <cvename>CVE-2007-6524</cvename>
      <url>http://www.opera.com/docs/changelogs/freebsd/925/</url>
      <url>http://www.opera.com/support/search/view/875/</url>
    </references>
    <dates>
      <discovery>2007-12-19</discovery>
      <entry>2007-12-19</entry>
      <modified>2007-12-29</modified>
    </dates>
  </vuln>

  <vuln vid="31435fbc-ae73-11dc-a5f9-001a4d49522b">
    <topic>peercast -- buffer overflow vulnerability</topic>
    <affects>
      <package>
	<name>peercast</name>
	<range><lt>0.1218</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Luigi Auriemma reports that peercast is vulnerable to a
	  buffer overflow which could lead to a DoS or potentially
	  remote code execution:</p>
	<blockquote cite="http://aluigi.altervista.org/adv/peercasthof-adv.txt">
	  <p>The handshakeHTTP function which handles all the requests
	    received by the other clients is vulnerable to a heap
	    overflow which allows an attacker to fill the
	    loginPassword and loginMount buffers located in the
	    Servent class with how much data he wants.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://aluigi.altervista.org/adv/peercasthof-adv.txt</url>
      <url>http://secunia.com/advisories/28120/</url>
    </references>
    <dates>
      <discovery>2007-12-17</discovery>
      <entry>2007-12-19</entry>
    </dates>
  </vuln>

  <vuln vid="fee7e059-acec-11dc-807f-001b246e4fdf">
    <topic>ganglia-webfrontend -- XSS vulnerabilities</topic>
    <affects>
      <package>
	<name>ganglia-webfrontend</name>
	<range><lt>3.0.6</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Ganglia project reports:</p>
	<blockquote cite="http://ganglia.info/?p=60">
	  <p>The Ganglia development team is pleased to release Ganglia
	    3.0.6 (Foss) which is available[...].  This release includes a
	    security fix for web frontend cross-scripting vulnerability.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://sourceforge.net/mailarchive/message.php?msg_name=d4c731da0712101044l7245cba9l34974008879f47a3%40mail.gmail.com</url>
      <url>http://sourceforge.net/mailarchive/forum.php?thread_name=d4c731da0712101044l7245cba9l34974008879f47a3%40mail.gmail.com&amp;forum_name=ganglia-developers</url>
    </references>
    <dates>
      <discovery>2007-12-10</discovery>
      <entry>2007-12-17</entry>
      <modified>2007-12-18</modified>
    </dates>
  </vuln>

  <vuln vid="30f5ca1d-a90b-11dc-bf13-0211060005df">
    <topic>qemu -- Translation Block Local Denial of Service Vulnerability</topic>
    <affects>
      <package>
	<name>qemu</name>
	<name>qemu-devel</name>
	<range><lt>0.9.0_4</lt></range>
	<range><ge>0.9.0s.20070101*</ge><lt>0.9.0s.20070802_1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>SecurityFocus reports:</p>
	<blockquote cite="http://www.securityfocus.com/bid/26666/discuss">
	  <p>QEMU is prone to a local denial-of-service vulnerability
	    because it fails to perform adequate boundary checks when
	    handling user-supplied input.</p>
	  <p>Attackers can exploit this issue to cause denial-of-service
	    conditions. Given the nature of the issue, attackers may also be
	    able to execute arbitrary code, but this has not been confirmed.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26666</bid>
      <cvename>CVE-2007-6227</cvename>
      <url>http://www.securityfocus.com/archive/1/484429</url>
    </references>
    <dates>
      <discovery>2007-11-30</discovery>
      <entry>2007-12-12</entry>
      <modified>2007-12-14</modified>
    </dates>
  </vuln>

  <vuln vid="fa708908-a8c7-11dc-b41d-000fb5066b20">
    <topic>drupal -- SQL injection vulnerability</topic>
    <affects>
      <package>
	<name>drupal5</name>
	<range><lt>5.4</lt></range>
      </package>
      <package>
	<name>drupal4</name>
	<range><lt>4.7.9</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Drupal Project reports:</p>
	<blockquote cite="http://drupal.org/node/198162">
	  <p>The function taxonomy_select_nodes() directly injects variables
	    into SQL queries instead of using placeholders. While taxonomy
	    module itself validates the input passed to
	    taxonomy_select_nodes(), this is a weakness in Drupal core.
	    Several contributed modules, such as taxonomy_menu, ajaxLoader,
	    and ubrowser, directly pass user input to taxonomy_select_nodes(),
	    enabling SQL injection attacks by anonymous users.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6299</cvename>
      <url>http://drupal.org/node/198162</url>
      <url>http://secunia.com/advisories/27932/</url>
    </references>
    <dates>
      <discovery>2007-12-05</discovery>
      <entry>2007-12-12</entry>
    </dates>
  </vuln>

  <vuln vid="ffcbd42d-a8c5-11dc-bec2-02e0185f8d72">
    <topic>samba -- buffer overflow vulnerability</topic>
    <affects>
      <package>
	<name>samba</name>
	<name>samba3</name>
	<name>ja-samba</name>
	<range><lt>3.0.28,1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secuna Research reports:</p>
	<blockquote cite="http://secunia.com/advisories/27760/">
	  <p>Secunia Research has discovered a vulnerability in Samba, which
	    can be exploited by malicious people to compromise a vulnerable
	    system.  The vulnerability is caused due to a boundary error within
	    the "send_mailslot()" function.  This can be exploited to cause a
	    stack-based buffer overflow with zero bytes via a specially crafted
	    "SAMLOGON" domain logon packet containing a username string placed
	    at an odd offset followed by an overly long GETDC string.
	    Successful exploitation allows execution of arbitrary code, but
	    requires that the "domain logons" option is enabled.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6015</cvename>
      <url>http://secunia.com/advisories/27760/</url>
    </references>
    <dates>
      <discovery>2007-12-10</discovery>
      <entry>2007-12-12</entry>
    </dates>
  </vuln>

  <vuln vid="b2571f88-a867-11dc-a6f0-00a0cce0781e">
    <topic>smbftpd -- format string vulnerability </topic>
    <affects>
      <package>
	<name>smbftpd</name>
	<range><lt>0.96</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/27014/">
	  <p>Format string vulnerability in the SMBDirList function in dirlist.c
	    in SmbFTPD 0.96 allows remote attackers to execute arbitrary code
	    via format string specifiers in a directory name.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-5184</cvename>
      <url>http://secunia.com/advisories/27014/</url>
      <url>http://sourceforge.net/project/shownotes.php?release_id=543077</url>
    </references>
    <dates>
      <discovery>2007-10-01</discovery>
      <entry>2007-12-12</entry>
    </dates>
  </vuln>

  <vuln vid="6ae7cef2-a6ae-11dc-95e6-000c29c5647f">
    <topic>jetty -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>jetty</name>
	<range><lt>6.1.6</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5613">
	  <p>Cross-site scripting (XSS) vulnerability in Dump Servlet in
	    Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject
	    arbitrary web script or HTML via unspecified parameters and
	    cookies.</p>
	</blockquote>
	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5614">
	  <p>Mortbay Jetty before 6.1.6rc1 does not properly handle "certain
	    quote sequences" in HTML cookie parameters, which allows remote
	    attackers to hijack browser sessions via unspecified vectors.</p>
	</blockquote>
	<blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5615">
	  <p>CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0
	    allows remote attackers to inject arbitrary HTTP headers and
	    conduct HTTP response splitting attacks via unspecified vectors.
	  </p>
	</blockquote>
      </body>
    </description>
    <references>
      <certvu>237888</certvu>
      <certvu>212984</certvu>
      <certvu>438616</certvu>
      <cvename>CVE-2007-5613</cvename>
      <cvename>CVE-2007-5614</cvename>
      <cvename>CVE-2007-5615</cvename>
      <url>http://svn.codehaus.org/jetty/jetty/trunk/VERSION.txt</url>
    </references>
    <dates>
      <discovery>2007-12-05</discovery>
      <entry>2007-12-10</entry>
    </dates>
  </vuln>

  <vuln vid="821afaa2-9e9a-11dc-a7e3-0016360406fa">
    <topic>liveMedia -- DoS vulnerability</topic>
    <affects>
      <package>
	<name>liveMedia</name>
	<range><lt>2007.11.18,1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The live555 development team reports:</p>
	<blockquote cite="http://www.live555.com/liveMedia/public/changelog.txt">
	  <p>Fixed a bounds-checking error in "parseRTSPRequestString()"
	    caused by an int vs. unsigned problem.</p>
	</blockquote>
	<blockquote cite="http://aluigi.altervista.org/adv/live555x-adv.txt">
	  <p>The function which handles the incoming queries from the
	    clients is affected by a vulnerability which allows an attacker
	    to crash the server remotely using the smallest RTSP query
	    possible to use.</p>
    </blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6036</cvename>
      <url>http://aluigi.altervista.org/adv/live555x-adv.txt</url>
      <url>http://www.live555.com/liveMedia/public/changelog.txt</url>
    </references>
    <dates>
      <discovery>2007-11-20</discovery>
      <entry>2007-12-08</entry>
      <modified>2007-12-09</modified>
    </dates>
  </vuln>

  <vuln vid="610bc692-a2ad-11dc-900c-000bcdc1757a">
    <topic>GNU finger vulnerability</topic>
    <affects>
      <package>
	<name>gnu-finger</name>
	<range><le>1.37_1</le></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>GNU security announcement:</p>
	<blockquote cite="http://www.gnu.org/software/finger/">
	  <p>GNU Finger unfortunately has not been updated in
	   many years, and has known security vulnerabilities.
	   Please do not use it in production environments.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-1999-1165</cvename>
      <url>http://www.gnu.org/software/finger/</url>
    </references>
    <dates>
      <discovery>1999-07-21</discovery>
      <entry>2007-12-05</entry>
    </dates>
  </vuln>

  <vuln vid="6eb580d7-a29c-11dc-8919-001c2514716c">
    <topic>Squid -- Denial of Service Vulnerability</topic>
    <affects>
      <package>
	<name>squid</name>
	<range><ge>2.0</ge><lt>2.6.16_1</lt></range>
	<range><ge>3.*</ge><lt>3.0.r1.20071001_1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Squid secuirty advisory reports:</p>
	<blockquote cite="http://www.squid-cache.org/Advisories/SQUID-2007_2.txt">
	  <p>Due to incorrect bounds checking Squid is vulnerable
	    to a denial of service check during some cache update
	    reply processing.</p>
	  <p>This problem allows any client trusted to use the
	    service to perform a denial of service attack on the
	    Squid service.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26687</bid>
      <cvename>CVE-2007-6239</cvename>
    </references>
    <dates>
      <discovery>2007-11-28</discovery>
      <entry>2007-12-04</entry>
      <modified>2007-12-07</modified>
    </dates>
  </vuln>

  <vuln vid="30acb8ae-9d46-11dc-9114-001c2514716c">
    <topic>rubygem-rails -- session-fixation vulnerability</topic>
    <affects>
      <package>
	<name>rubygem-rails</name>
	<range><lt>1.2.6</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Rails core team reports:</p>
	<blockquote cite="http://weblog.rubyonrails.com/2007/11/24/ruby-on-rails-1-2-6-security-and-maintenance-release">
	  <p>The rails core team has released ruby on rails 1.2.6 to
	    address a bug in the fix for session fixation attacks
	    (CVE-2007-5380). The CVE Identifier for this new issue
	    is CVE-2007-6077.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-6077</cvename>
    </references>
    <dates>
      <discovery>2007-11-24</discovery>
      <entry>2007-11-27</entry>
    </dates>
  </vuln>

  <vuln vid="44fb0302-9d38-11dc-9114-001c2514716c">
    <topic>rubygem-rails -- JSON XSS vulnerability</topic>
    <affects>
      <package>
	<name>rubygem-rails</name>
	<range><lt>1.2.5</lt></range>
      </package>
      <package>
	<name>rubygem-activesupport</name>
	<range><lt>1.4.4</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Rails core team reports:</p>
	<blockquote cite="http://weblog.rubyonrails.org/2007/10/12/rails-1-2-5-maintenance-release">
	  <p>All users of Rails 1.2.4 or earlier are advised to upgrade
	    to 1.2.5, though it isn't strictly necessary if you
	    aren't working with JSON. For more information the JSON
	    vulnerability, see CVE-2007-3227.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-3227</cvename>
    </references>
    <dates>
      <discovery>2007-10-12</discovery>
      <entry>2007-11-28</entry>
      <modified>2007-12-01</modified>
    </dates>
  </vuln>

  <vuln vid="31d9fbb4-9d09-11dc-a29d-0016d325a0ed">
    <topic>ikiwiki -- improper symlink verification vulnerability</topic>
    <affects>
      <package>
	<name>ikiwiki</name>
	<range><lt>2.14</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The ikiwiki development team reports:</p>
	<blockquote cite="http://ikiwiki.info/security/#index29h2">
	  <p>Ikiwiki did not check if path to the srcdir to contained a
	    symlink. If an attacker had commit access to the directories in
	    the path, they could change it to a symlink, causing ikiwiki to
	    read and publish files that were not intended to be
	    published. (But not write to them due to other checks.)</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://ikiwiki.info/security/#index29h2</url>
    </references>
    <dates>
      <discovery>2007-11-26</discovery>
      <entry>2007-11-27</entry>
    </dates>
  </vuln>

  <vuln vid="f1f6f6da-9d2f-11dc-9114-001c2514716c">
    <topic>firefox -- multiple remote unspecified memory corruption vulnerabilities</topic>
    <affects>
      <package>
	<name>firefox</name>
	<range><lt>2.0.0.10,1</lt></range>
      </package>
      <package>
	<name>linux-firefox</name>
	<range><lt>2.0.0.10</lt></range>
      </package>
      <package>
	<name>seamonkey</name>
	<name>linux-seamonkey</name>
	<range><lt>1.1.7</lt></range>
      </package>
      <package>
	<name>flock</name>
	<name>linux-flock</name>
	<range><lt>1.0.2</lt></range>
      </package>
      <package>
	<name>linux-firefox-devel</name>
	<range><lt>3.0.a2007.12.12</lt></range>
      </package>
      <package>
	<name>linux-seamonkey-devel</name>
	<range><lt>2.0.a2007.12.12</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Mozilla Foundation reports:</p>
	<blockquote cite="http://www.mozilla.org/security/announce/2007/mfsa2007-38.html">
	  <p>The Firefox 2.0.0.10 update contains fixes for three bugs that
	    improve the stability of the product. These crashes showed some
	    evidence of memory corruption under certain circumstances and we
	    presume that with enough effort at least some of these could be
	    exploited to run arbitrary code.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26593</bid>
      <cvename>CVE-2007-5959</cvename>
    </references>
    <dates>
      <discovery>2007-11-26</discovery>
      <entry>2007-11-27</entry>
      <modified>2007-12-14</modified>
    </dates>
  </vuln>

  <vuln vid="15485ae8-9848-11dc-9e48-0016179b2dd5">
    <topic>phpmyadmin -- Cross Site Scripting</topic>
    <affects>
      <package>
	<name>phpmyadmin</name>
	<range><lt>2.11.2.2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>phpMyAdmin security announcement:</p>
	<blockquote cite="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-8">
	  <p>The login page auth_type cookie was vulnerable to XSS via
	    the convcharset parameter. An attacker could use this to
	    execute malicious code on the visitors computer</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-8</url>
      <url>http://www.nth-dimension.org.uk/downloads.php?id=38</url>
    </references>
    <dates>
      <discovery>2007-11-20</discovery>
      <entry>2007-11-21</entry>
    </dates>
  </vuln>

  <vuln vid="a63b15f9-97ff-11dc-9e48-0016179b2dd5">
    <topic>samba -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>samba</name>
	<name>samba3</name>
	<name>ja-samba</name>
	<range><lt>3.0.26a_2,1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The Samba Team reports:</p>
	<blockquote cite="http://us1.samba.org/samba/security/CVE-2007-5398.html">
	  <p>Secunia Research reported a vulnerability that allows for
	    the execution of arbitrary code in nmbd.  This defect may
	    only be exploited when the "wins support" parameter has
	    been enabled in smb.conf.</p>
	</blockquote>
	<blockquote cite="http://us1.samba.org/samba/security/CVE-2007-4572.html">
	  <p>Samba developers have discovered what is believed to be
	  a non-exploitable buffer over in nmbd during the processing
	  of GETDC logon server requests.  This code is only used
	  when the Samba server is configured as a Primary or Backup
	  Domain Controller.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26454</bid>
      <cvename>CVE-2007-4572</cvename>
      <cvename>CVE-2007-5398</cvename>
      <url>http://secunia.com/advisories/27450/</url>
      <url>http://us1.samba.org/samba/security/CVE-2007-4572.html</url>
      <url>http://us1.samba.org/samba/security/CVE-2007-5398.html</url>
    </references>
    <dates>
      <discovery>2007-11-15</discovery>
      <entry>2007-11-21</entry>
    </dates>
  </vuln>

  <vuln vid="392b5b1d-9471-11dc-9db7-001c2514716c">
    <topic>php -- multiple security vulnerabilities</topic>
    <affects>
      <package>
	<name>php5</name>
	<range><lt>5.2.5</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>PHP project reports:</p>
	<blockquote cite="http://www.php.net/releases/5_2_5.php">
	  <p>Security Enhancements and Fixes in PHP 5.2.5:</p>
	  <ul>
	    <li>Fixed dl() to only accept filenames. Reported by Laurent
	      Gaffie.</li>
	    <li>Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887).
	      Reported by Laurent Gaffie.</li>
	    <li>Fixed htmlentities/htmlspecialchars not to accept partial
	      multibyte sequences. Reported by Rasmus Lerdorf</li>
	    <li>Fixed possible triggering of buffer overflows inside glibc
	      implementations of the fnmatch(), setlocale() and glob()
	      functions.  Reported by Laurent Gaffie.</li>
	    <li>Fixed "mail.force_extra_parameters" php.ini directive not to be
	      modifiable in .htaccess due to the security implications. Reported
	      by SecurityReason.</li>
	    <li>Fixed bug #42869 (automatic session id insertion adds sessions
	      id to non-local forms).</li>
	    <li>Fixed bug #41561 (Values set with php_admin_* in httpd.conf can
	      be overwritten with ini_set()).</li>
	  </ul>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26403</bid>
      <cvename>CVE-2007-4887</cvename>
    </references>
    <dates>
      <discovery>2007-11-08</discovery>
      <entry>2007-11-16</entry>
    </dates>
  </vuln>

  <vuln vid="a7080c30-91a2-11dc-b2eb-00b0d07e6c7e">
    <topic>mt-daapd -- denial of service vulnerability</topic>
    <affects>
      <package>
	<name>mt-daapd</name>
	<range><lt>0.2.4.1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>US-CERT reports:</p>
	<blockquote cite="http://www.us-cert.gov/cas/bulletins/SB07-316.html">
	  <p>webserver.c in mt-dappd in Firefly Media Server 0.2.4 and
	    earlier allows remote attackers to cause a denial of service
	    (NULL dereference and daemon crash) via a stats method action
	    to /xml-rpc with (1) an empty Authorization header line, which
	    triggers a crash in the ws_decodepassword function; or (2) a
	    header line without a ':' character, which triggers a crash
	    in the ws_getheaders function.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-5824</cvename>
    </references>
    <dates>
      <discovery>2007-11-05</discovery>
      <entry>2007-11-12</entry>
    </dates>
  </vuln>

  <vuln vid="92f86b93-923f-11dc-a2bf-02e081235dab">
    <topic>net-snmp -- denial of service via GETBULK request</topic>
    <affects>
      <package>
	<name>net-snmp</name>
	<range><lt>5.3.1_7</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>CVE reports:</p>
	<blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5846">
	  <p>The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1
	    allows remote attackers to cause a denial of service (CPU
	    and memory consumption) via a GETBULK request with a large
	    max-repeaters value.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-5846</cvename>
    </references>
    <dates>
      <discovery>2007-11-06</discovery>
      <entry>2007-11-13</entry>
      <modified>2007-11-14</modified>
    </dates>
  </vuln>

  <vuln vid="ff65eecb-91e4-11dc-bd6c-0016179b2dd5">
    <topic>flac -- media file processing integer overflow vulnerabilities</topic>
    <affects>
      <package>
	<name>flac</name>
	<range><lt>1.1.2_2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>iDefense Laps reports:</p>
	<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=608">
	  <p>Remote exploitation of multiple integer overflow vulnerabilities
	    in libFLAC, as included with various vendor's software
	    distributions, allows attackers to execute arbitrary code
	    in the context of the currently logged in user.</p>
	  <p>These vulnerabilities specifically exist in the handling of
	    malformed FLAC media files. In each case, an integer overflow can
	    occur while calculating the amount of memory to allocate. As such,
	    insufficient memory is allocated for the data that is subsequently
	    read in from the file, and a heap based buffer overflow occurs.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-4619</cvename>
      <url>http://secunia.com/advisories/27210/</url>
      <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=608</url>
    </references>
    <dates>
      <discovery>2007-10-11</discovery>
      <entry>2007-11-13</entry>
    </dates>
  </vuln>

  <vuln vid="2747fc39-915b-11dc-9239-001c2514716c">
    <topic>xpdf -- multiple remote Stream.CC vulnerabilities</topic>
    <affects>
      <package>
	<name>cups-base</name>
	<range><lt>1.3.3_2</lt></range>
      </package>
      <package>
	<name>gpdf</name>
	<range><gt>0</gt></range>
      </package>
      <package>
	<name>kdegraphics</name>
	<range><lt>3.5.8_1</lt></range>
      </package>
      <package>
	<name>koffice</name>
	<range><lt>1.6.3_3,2</lt></range>
      </package>
      <package>
	<name>poppler</name>
	<range><lt>0.6</lt></range>
      </package>
      <package>
	<name>xpdf</name>
	<range><lt>3.02_5</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia Research reports:</p>
	<blockquote cite="http://www.securityfocus.com/archive/1/483372">
	  <p>Secunia Research has discovered some vulnerabilities in Xpdf,
	    which can be exploited by malicious people to compromise a user's
	    system.</p>
	  <ul>
	    <li>An array indexing error within the
	      "DCTStream::readProgressiveDataUnit()" method in xpdf/Stream.cc
	      can be exploited to corrupt memory via a specially crafted PDF
	      file.</li>
	    <li>An integer overflow error within the "DCTStream::reset()"
	      method in xpdf/Stream.cc can be exploited to cause a heap-based
	      buffer overflow via a specially crafted PDF file.</li>
	    <li>A boundary error within the "CCITTFaxStream::lookChar()" method
	      in xpdf/Stream.cc can be exploited to cause a heap-based buffer
	      overflow by tricking a user into opening a PDF file containing a
	      specially crafted "CCITTFaxDecode" filter.</li>
	  </ul>
	  <p>Successful exploitation may allow execution of arbitrary code.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26367</bid>
      <cvename>CVE-2007-4352</cvename>
      <cvename>CVE-2007-5392</cvename>
      <cvename>CVE-2007-5393</cvename>
    </references>
    <dates>
      <discovery>2007-11-07</discovery>
      <entry>2007-11-12</entry>
      <modified>2007-11-14</modified>
    </dates>
  </vuln>

  <vuln vid="ffba6ab0-90b5-11dc-9835-003048705d5a">
    <topic>plone -- unsafe data interpreted as pickles</topic>
    <affects>
      <package>
	<name>plone</name>
	<range><ge>2.5</ge><lt>2.5.5</lt></range>
	<range><ge>3.0</ge><lt>3.0.3</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Plone projectreports:</p>
	<blockquote cite="http://plone.org/about/security/advisories/cve-2007-5741">
	  <p>This hotfix corrects a vulnerability in the statusmessages
	    and linkintegrity modules, where unsafe network data was
	    interpreted as python pickles. This allows an attacker to
	    run arbitrary python code within the Zope/Plone process.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26354</bid>
      <cvename>CVE-2007-5741</cvename>
    </references>
    <dates>
      <discovery>2007-11-06</discovery>
      <entry>2007-11-12</entry>
    </dates>
  </vuln>

  <vuln vid="2d2dcbb4-906c-11dc-a951-0016179b2dd5">
    <topic>phpmyadmin -- cross-site scripting vulnerability</topic>
    <affects>
      <package>
	<name>phpMyAdmin</name>
	<range><lt>2.11.2.1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>The DigiTrust Group reports:</p>
	<blockquote cite="http://www.digitrustgroup.com/advisories/tdg-advisory071108a.html">
	  <p>When creating a new database, a malicious user can use a
	    client-side Web proxy to place malicious code in the db parameter of
	    the POST request. Since db_create.php does not properly sanitize
	    user-supplied input, an administrator could face a persistent XSS
	    attack when the database names are displayed.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <url>http://www.digitrustgroup.com/advisories/tdg-advisory071108a.html</url>
      <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-7</url>
    </references>
    <dates>
      <discovery>2007-11-11</discovery>
      <entry>2007-11-11</entry>
    </dates>
  </vuln>

  <vuln vid="9b718b82-8ef5-11dc-8e42-001c2514716c">
    <topic>gallery2 -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>gallery2</name>
	<range><lt>2.2.3</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Gallery project reports:</p>
	<blockquote cite="http://gallery.menalto.com/gallery_2.2.3_released">
	  <p>Gallery 2.2.3 addresses the following security vulnerabilities:</p>
	  <ul>
	    <li>Unauthorized renaming of items possible with WebDAV (reported
	      by Merrick Manalastas)</li>
	    <li>Unauthorized modification and retrieval of item properties
	      possible with WebDAV</li>
	    <li>Unauthorized locking and replacing of items possible with
	      WebDAV</li>
	    <li>Unauthorized editing of data file possible via linked items with
	      Reupload and WebDAV (reported by Nicklous Roberts)</li>
	  </ul>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-4650</cvename>
      <bid>25580</bid>
    </references>
    <dates>
      <discovery>2007-08-29</discovery>
      <entry>2007-11-09</entry>
    </dates>
  </vuln>

  <vuln vid="20a4eb11-8ea3-11dc-a396-0016179b2dd5">
    <topic>tikiwiki -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>tikiwik</name>
	<range><lt>1.9.8.2</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>A Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/26618/">
	  <p>Some vulnerabilities have been reported in TikiWiki, which
	    can be exploited by malicious people to conduct cross-site
	    scripting and script insertion attacks and disclose potentially
	    sensitive information.</p>
	  <p>Input passed to the username parameter in tiki-remind_password.php
	    (when remind is set to send me my password) is not properly
	    sanitised before being returned to the user. This can be exploited
	    to execute arbitrary HTML and script code (for example with meta
	    refreshes to a javascript: URL) in a user's browser session in
	    context of an affected site.</p>
	  <p>Input passed to the local_php and error_handler parameters in
	    tiki-index.php is not properly verified before being used to include
	    files. This can be exploited to include arbitrary files from local
	    resources.</p>
	  <p>Input passed to the imp_language parameter in
	    tiki-imexport_languages.php is not properly verified before being
	    used to include files.  This can be exploited to include arbitrary
	    files from local resources.</p>
	  <p>Certain img src elements are not properly santised before being
	    used.  This can be exploited to insert arbitrary HTML and script
	    code, which is executed in a user's browser session in context of an
	    affected site when the malicious data is viewed.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-4554</cvename>
      <cvename>CVE-2007-5683</cvename>
      <cvename>CVE-2007-5684</cvename>
      <url>http://secunia.com/advisories/26618/</url>
      <url>http://tikiwiki.cvs.sourceforge.net/tikiwiki/tiki/changelog.txt?view=markup&amp;pathrev=REL-1-9-8-2</url>
    </references>
    <dates>
      <discovery>2007-08-27</discovery>
      <entry>2007-11-09</entry>
    </dates>
  </vuln>

  <vuln vid="8dd9722c-8e97-11dc-b8f6-001c2514716c">
    <topic>cups -- off-by-one buffer overflow</topic>
    <affects>
      <package>
	<name>cups-base</name>
	<range><lt>1.3.3_1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Secunia reports:</p>
	<blockquote cite="http://secunia.com/advisories/27233">
	  <p>Secunia Research has discovered a vulnerability in CUPS, which can
	    be exploited by malicious people to compromise a vulnerable
	    system.</p>
	  <p>The vulnerability is caused due to a boundary error within the
	    "ippReadIO()" function in cups/ipp.c when processing IPP (Internet
	    Printing Protocol) tags.  This can be exploited to overwrite one
	    byte on the stack with a zero by sending an IPP request containing
	    specially crafted "textWithLanguage" or "nameWithLanguage" tags.</p>
	  <p>Successful exploitation allows execution of arbitrary code.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-4351</cvename>
      <url>http://secunia.com/secunia_research/2007-76/</url>
    </references>
    <dates>
      <discovery>2007-11-06</discovery>
      <entry>2007-11-09</entry>
      <modified>2007-11-12</modified>
    </dates>
  </vuln>

  <vuln vid="5b47c279-8cb5-11dc-8878-0016179b2dd5">
    <topic>perl --  regular expressions unicode data buffer overflow</topic>
    <affects>
      <package>
	<name>perl</name>
	<name>perl-threaded</name>
	<range><gt>5.8.*</gt><lt>5.8.8_1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Red Hat reports:</p>
	<blockquote cite="https://rhn.redhat.com/errata/RHSA-2007-0966.html">
	  <p>A flaw was found in Perl's regular expression engine. Specially
	    crafted input to a regular expression can cause Perl to improperly
	    allocate memory, possibly resulting in arbitrary code running with
	    the permissions of the user running Perl.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-5116</cvename>
      <url>http://secunia.com/advisories/27546/</url>
    </references>
    <dates>
      <discovery>2007-11-05</discovery>
      <entry>2007-11-06</entry>
      <modified>2007-11-07</modified>
    </dates>
  </vuln>

  <vuln vid="bfd6eef4-8c94-11dc-8c55-001c2514716c">
    <topic>pcre -- arbitrary code execution</topic>
    <affects>
      <package>
	<name>pcre</name>
	<name>pcre-utf8</name>
	<range><lt>7.3</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Debian project reports:</p>
	<blockquote cite="http://www.debian.org/security/2007/dsa-1399">
	  <p>Tavis Ormandy of the Google Security Team has discovered
	    several security issues in PCRE, the Perl-Compatible Regular
	    Expression library, which potentially allow attackers to
	    execute arbitrary code by compiling specially crafted regular
	    expressions.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-1659</cvename>
      <cvename>CVE-2007-1660</cvename>
      <cvename>CVE-2007-1661</cvename>
      <cvename>CVE-2007-1662</cvename>
      <cvename>CVE-2007-4766</cvename>
      <cvename>CVE-2007-4767</cvename>
      <cvename>CVE-2007-4768</cvename>
      <url>http://www.pcre.org/changelog.txt</url>
    </references>
    <dates>
      <discovery>2007-11-05</discovery>
      <entry>2007-11-06</entry>
    </dates>
  </vuln>

  <vuln vid="617a4021-8bf0-11dc-bffa-0016179b2dd5">
    <topic>perdition -- str_vwrite format string vulnerability</topic>
    <affects>
      <package>
	<name>perdition</name>
	<range><lt>1.17.1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>SEC-Consult reports:</p>
	<blockquote cite="http://www.sec-consult.com/300.html">
	  <p>Perdition IMAP is affected by a format string bug in one of its
	    IMAP output-string formatting functions. The bug allows the
	    execution of arbitrary code on the affected server.
	    A successful exploit does not require prior authentication.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26270</bid>
      <cvename>CVE-2007-5740</cvename>
      <url>http://www.sec-consult.com/300.html</url>
      <url>http://secunia.com/advisories/27458</url>
    </references>
    <dates>
      <discovery>2007-10-31</discovery>
      <entry>2007-11-05</entry>
    </dates>
  </vuln>

  <vuln vid="f8b0f83c-8bb3-11dc-bffa-0016179b2dd5">
    <topic>gftp -- multiple vulnerabilities</topic>
    <affects>
      <package>
	<name>gftp</name>
	<range><lt>2.0.18_6</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Gentoo reports:</p>
	<blockquote cite="http://www.gentoo.org/security/en/glsa/glsa-200711-01.xml">
	  <p>Kalle Olavi Niemitalo discovered two boundary errors in fsplib code
	    included in gFTP when processing overly long directory or file
	    names.</p>
	  <p>A remote attacker could trigger these vulnerabilities by enticing
	    a user to download a file with a specially crafted directory or file
	    name, possibly resulting in the execution of arbitrary code or a
	    Denial of Service.</p>
	</blockquote>
      </body>
    </description>
    <references>
     <cvename>CVE-2007-3961</cvename>
     <cvename>CVE-2007-3962</cvename>
     <url>http://www.gentoo.org/security/en/glsa/glsa-200711-01.xml</url>
    </references>
    <dates>
      <discovery>2007-11-01</discovery>
      <entry>2007-11-05</entry>
      <modified>2007-11-11</modified>
    </dates>
  </vuln>

  <vuln vid="a1ef3fc0-8ad0-11dc-9490-0016179b2dd5">
    <topic>dircproxy -- remote denial of service</topic>
    <affects>
      <package>
	<name>dircproxy</name>
	<range><lt>1.0.5_1</lt></range>
      </package>
      <package>
	<name>dircproxy-devel</name>
	<range><lt>1.2.0.b2_1</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Securiweb reports:</p>
	<blockquote cite="http://dircproxy.securiweb.net/ticket/89">
	  <p>dircproxy allows remote attackers to cause a denial of
	    service (segmentation fault) via an ACTION command without a
	    parameter, which triggers a NULL pointer dereference, as
	    demonstrated using a blank /me message from irssi.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-5226</cvename>
      <url>http://dircproxy.securiweb.net/ticket/89</url>
      <url>https://bugzilla.redhat.com/show_bug.cgi?id=319301</url>
    </references>
    <dates>
      <discovery>2006-09-06</discovery>
      <entry>2007-11-04</entry>
       <modified>2008-01-31</modified>
    </dates>
  </vuln>

  <vuln vid="a467d0f9-8875-11dc-b3ba-0016179b2dd5">
    <topic>wordpress -- cross-site scripting</topic>
    <affects>
      <package>
	<name>wordpress</name>
	<name>de-wordpress</name>
	<range><lt>2.3.1</lt></range>
      </package>
      <package>
	<name>zh-wordpress</name>
	<range><gt>0</gt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>A Secunia Advisory report:</p>
	<blockquote cite="http://secunia.com/advisories/27407">
	  <p>Input passed to the "posts_columns" parameter in
	    wp-admin/edit-post-rows.php is not properly sanitised before
	    being returned to the user. This can be exploited to execute
	    arbitrary HTML and script code in a user's browser session in
	    context of an affected site.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <cvename>CVE-2007-5710</cvename>
      <url>http://secunia.com/advisories/27407</url>
      <url>http://wordpress.org/development/2007/10/wordpress-231/</url>
    </references>
    <dates>
      <discovery>2007-10-29</discovery>
      <entry>2007-11-01</entry>
    </dates>
  </vuln>

  <vuln vid="db449245-870d-11dc-a3ec-001921ab2fa4">
    <topic>openldap -- multiple remote denial of service vulnerabilities</topic>
    <affects>
      <package>
	<name>openldap-server</name>
	<range><lt>2.3.39</lt></range>
	<range><gt>2.4.0</gt><lt>2.4.6</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>BugTraq reports:</p>
	<blockquote cite="http://www.securityfocus.com/bid/26245/">
	  <p>OpenLDAP is prone to multiple remote denial-of-service
	    vulnerabilities because of an incorrect NULL-termination
	    issue and a double-free issue.</p>
	</blockquote>
      </body>
    </description>
    <references>
      <bid>26245</bid>
      <cvename>CVE-2007-5707</cvename>
      <cvename>CVE-2007-5708</cvename>
    </references>
    <dates>
      <discovery>2007-10-29</discovery>
      <entry>2007-10-30</entry>
      <modified>2007-10-31</modified>
    </dates>
  </vuln>

  <vuln vid="d2c2952d-85a1-11dc-bfff-003048705d5a">
    <topic>py-django -- denial of service vulnerability</topic>
    <affects>
      <package>
	<name>py23-django</name>
	<name>py24-django</name>
	<name>py25-django</name>
	<range><lt>0.96.1</lt></range>
      </package>
      <package>
	<name>py23-django-devel</name>
	<name>py24-django-devel</name>
	<name>py25-django-devel</name>
	<range><lt>20071026</lt></range>
      </package>
    </affects>
    <description>
      <body xmlns="http://www.w3.org/1999/xhtml">
	<p>Django project reports:</p>
	<blockquote cite="http://www.djangoproject.com/weblog/2007/oct/26/security-fix/">
	  <p>A per-process cache used by Django's internationalization
	    ("i18n") system to store the results of translation lookups
	    for particular values of the HTTP Accept-Language header
	    used the full value of that header as a key. An attacker
	    could take advantage of this by sending repeated requests
	    with extremely large strings in the Accept-Language header,
	    potentially causing a denial of service by filling available
	    memory.</p>
	  <p>Due to limitations imposed by