<?xml version="1.0"?>
<rss version="2.0">

<channel>
	<title>Planet Frugalware</title>
	<link>http://planet.frugalware.org/</link>
	<language>en</language>
	<description>Planet Frugalware - http://planet.frugalware.org/</description>

<item>
	<title>Boobaa: Diploma</title>
	<guid>http://blogs.frugalware.org/xmlsrv/334@http://blogs.frugalware.org</guid>
	<link>http://blogs.frugalware.org/boobaa/2008/07/03/diploma</link>
	<description>&lt;p&gt;&lt;a href=&quot;http://csecsy.hu/boobaa_blogja/informatikatanar&quot;&gt;http://csecsy.hu/boobaa_blogja/informatikatanar&lt;/a&gt;&lt;/p&gt;	&lt;p&gt;My colleague has just brought my new stuff, as I didn't take the trouble to go to Szeged for it:&lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;DIPLOMA&lt;br /&gt;
This diploma has been awarded to &lt;strong&gt;Istv&amp;#225;n L&amp;#225;szl&amp;#243; Cs&amp;#233;csy&lt;/strong&gt;, born in &lt;strong&gt;Budapest&lt;/strong&gt; (town), &lt;strong&gt;-&lt;/strong&gt; (county) &lt;strong&gt;Hungary&lt;/strong&gt; (country) on &lt;strong&gt;%j&lt;/strong&gt; (day) &lt;strong&gt;%F&lt;/strong&gt; (month) &lt;strong&gt;%Y&lt;/strong&gt; (year), who fulfilled his/her university obligations from the academic year &lt;strong&gt;2003/2004&lt;/strong&gt; to the academic year &lt;strong&gt;2007/2008&lt;/strong&gt; at &lt;strong&gt;the University of Szeged Faculty of Science and Informatics majoring in computer science.&lt;/strong&gt;&lt;br /&gt;
On the basis of the decision of the Final Examination Board dated &lt;strong&gt;6&lt;/strong&gt; (day) &lt;strong&gt;June&lt;/strong&gt; (month) &lt;strong&gt;2008&lt;/strong&gt; (year), he/she is hereby declared &lt;strong&gt;Teacher of Informatics.&lt;/strong&gt;&lt;br /&gt;
Grade of diploma: &lt;strong&gt;satisfactory (3,28)&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;Szeged&lt;/strong&gt;, &lt;strong&gt;23 June&lt;/strong&gt; 20&lt;strong&gt;08&lt;/strong&gt;&lt;/p&gt;&lt;/blockquote&gt;</description>
	<pubDate>Thu, 03 Jul 2008 17:18:16 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA485 - courier-authlib</title>
	<guid>http://frugalware.org/security/485#top</guid>
	<link>http://frugalware.org/security/485</link>
	<description>A vulnerability has been reported in the Courier Authentication Library, which can be exploited by malicious people to conduct SQL injection attacks.
			Input passed via e.g. the username to the library is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and e.g. potentially bypass authentication.
			Successful exploitation requires that a MySQL database is used for authentication and that a Non-Latin character set is selected.Vulnerable version: 0.60.2-1, Unaffected version: 0.60.6-1kalgan1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2667</description>
	<pubDate>Tue, 01 Jul 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA484 - xorg-server</title>
	<guid>http://frugalware.org/security/484#top</guid>
	<link>http://frugalware.org/security/484</link>
	<description>Some vulnerabilities have been reported in X.org X11, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
			1) An integer overflow error when calculating the size of the glyph exists in the &quot;AllocateGlyph()&quot; function within the Render extension. This can be exploited to cause a heap-based buffer overflow via a specially crafted request.
			2) An integer overflow error when calculating the size of the glyph in the &quot;ProcRenderCreateCursor()&quot; function within the Render extension can be exploited to crash the X server via a specially crafted request.
			3) An integer overflow error exists in the Render extension when parsing client requests for the &quot;SProcRenderCreateLinearGradient&quot;, &quot;SProcRenderCreateRadialGradient&quot;, or &quot;SProcRenderCreateConicalGradient&quot; functions and can be exploited to corrupt heap memory.
			4) Multiple input validation errors in the &quot;SProcSecurityGenerateAuthorization()&quot;, &quot;SProcRecordCreateContext()&quot;, and &quot;SProcRecordRegisterClients()&quot; functions within the Record and Security extensions can be exploited to corrupt heap memory via specially crafted requests.
			Successful exploitation of vulnerabilities #1, #3, and #4 may allow execution of arbitrary code with privileges of the X server (typically root).
			5) An integer overflow error when processing parameters to the &quot;ShmPutImage()&quot; request can be exploited to disclose arbitrary memory of the X server process.Vulnerable version: 1.4.0.90-5, Unaffected version: 1.4.0.90-6kalgan2, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1377
			http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1379
			http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2360
			http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2361
			http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2362</description>
	<pubDate>Tue, 01 Jul 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA483 - apache</title>
	<guid>http://frugalware.org/security/483#top</guid>
	<link>http://frugalware.org/security/483</link>
	<description>A vulnerability has been reported in the Apache mod_proxy module, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
			The vulnerability is caused due to an error in the &quot;ap_proxy_http_process_response()&quot; function when forwarding interim responses. This can be exploited to consume large amounts of memory by tricking mod_proxy into sending an overly large number of interim responses to the client.Vulnerable version: 2.2.8-1, Unaffected version: 2.2.8-2kalgan1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2364</description>
	<pubDate>Tue, 01 Jul 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Miklos: security through obscurity</title>
	<guid>http://blogs.frugalware.org/xmlsrv/333@http://blogs.frugalware.org</guid>
	<link>http://blogs.frugalware.org/vmiklos/2008/06/27/security_through_obscurity</link>
	<description>&lt;p&gt;okay, this won't be a happy post either, but i thought i would just share a few links here.&lt;/p&gt;
	&lt;p&gt;first, there was &lt;a href=&quot;http://www.heise-online.co.uk/security/Ghostly-threat-to-Internet-Explorer-users--/news/111017&quot;&gt;this&lt;/a&gt; article about some microsoft ie security problem, and the opensource evangelists started to hype again linux about being open, etc, etc. you know the story.&lt;/p&gt;
	&lt;p&gt;the sad fact is that, just being opensource, or let's say even having an open scm will not guarantee that all the details are published. i want to pick up a minor issue, so that i can be sure about i don't publish any details here which may not public.&lt;/p&gt;
	&lt;p&gt;let's take &lt;a href=&quot;http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=5816339310b2d9623cf413d33e538b45e815da5d&quot;&gt;this commit&lt;/a&gt;. it's a bugfix, right? umm, if it would be security-related, they would mention it. hm, no.&lt;/p&gt;
	&lt;p&gt;to make the long story short, the &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2137&quot;&gt;relevant cve&lt;/a&gt; is there, even secunia released an &lt;a href=&quot;http://secunia.com/advisories/30258/&quot;&gt;advisory&lt;/a&gt;.&lt;/p&gt;
	&lt;p&gt;i could add few more details (no cve on the secunia page, the &quot;from remote&quot; is probably wrong), and finally make some conclustions, but i would avoid that this sime.&lt;/p&gt;
	&lt;p&gt;take care.
&lt;/p&gt;</description>
	<pubDate>Fri, 27 Jun 2008 21:08:30 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA482 - net-snmp</title>
	<guid>http://frugalware.org/security/482#top</guid>
	<link>http://frugalware.org/security/482</link>
	<description>A vulnerability has been reported in Net-SNMP, which can be exploited by malicious people to spoof authenticated SNMPv3 packets.
			The vulnerability is caused due to an error within the verification of the HMAC digest. This can be exploited to increase the chance of successfully spoofing a packet to 1 in 256 by sending a specially crafted SNMPv3 packet with an incomplete 1 byte HMAC digest.
			Successful exploitation requires a valid username.Vulnerable version: 5.4.1-4kalgan1, Unaffected version: 5.4.1-4kalgan2, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0960</description>
	<pubDate>Wed, 25 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA481 - horde-webmail</title>
	<guid>http://frugalware.org/security/481#top</guid>
	<link>http://frugalware.org/security/481</link>
	<description>Some vulnerabilities have been reported in various Horde products, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct cross-site scripting attacks.
			1) Input passed to item names is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is viewed.
			Successful exploitation requires valid user credentials.
			2) Input passed to contact views is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is viewed.
			Successful exploitation requires valid user credentials.
			3) Input passed to unspecified input is not properly sanitised before being returned to the user in the add event screen. This can be exploited to execute arbitrary HTML and script code in a user's browser session in contact of an affected site.Vulnerable version: 1.1-1kalgan1, Unaffected version: 1.1.1-1kalgan1, CVEs: There is no CVE for this issue, see http://lists.horde.org/archives/announce/2008/000420.html.</description>
	<pubDate>Wed, 25 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA480 - exiv2</title>
	<guid>http://frugalware.org/security/480#top</guid>
	<link>http://frugalware.org/security/480</link>
	<description>A vulnerability has been reported in Exiv2, which potentially can be exploited by malicious people to crash an application using the library.
			The vulnerability is caused due to a floating point exception within the pretty printing functionality when processing certain Nicon camera lens information. This can be exploited to crash an application linked against the Exiv2 library when a image containing specially-crafted metadata is processed.Vulnerable version: 0.16-1, Unaffected version: 0.16-2kalgan1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2696</description>
	<pubDate>Wed, 25 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA479 - kernel</title>
	<guid>http://frugalware.org/security/479#top</guid>
	<link>http://frugalware.org/security/479</link>
	<description>A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
			The vulnerability is caused due to an error within the ASN.1 BER decoder of the cifs and ip_nat_snmp_basic modules when calculating the buffer size. This can be exploited to cause a crash or potentially execute arbitrary code by sending specially crafted BER encoded data to a vulnerable system.Vulnerable version: 2.6.24-4kalgan2, Unaffected version: 2.6.24-4kalgan3, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1673</description>
	<pubDate>Mon, 23 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Frugalware News: Frugalware Newsletter Issue 26</title>
	<guid>http://www.frugalware.org/news/101#top</guid>
	<link>http://www.frugalware.org/news/101</link>
	<description>The newsletter's aim is to keep you up to date with what's happened recently in the world of Frugalware.&lt;br /&gt;
            Features of this issue include:
            &lt;ul&gt;
                &lt;li&gt;Frugalware's developers are people too! - Devil505&lt;/li&gt;
                &lt;li&gt;Tips and tricks - Get a better looking &quot;man&quot;&lt;/li&gt;
                &lt;li&gt;Priyank is back!&lt;/li&gt;
            &lt;/ul&gt;
            You can read it &lt;a href=&quot;http://frugalware.org/newsletter/26&quot;&gt;here&lt;/a&gt;. We hope you like it!</description>
	<pubDate>Sat, 21 Jun 2008 12:51:35 +0000</pubDate>
</item>
<item>
	<title>Miklos: non-public scm for free software</title>
	<guid>http://blogs.frugalware.org/xmlsrv/332@http://blogs.frugalware.org</guid>
	<link>http://blogs.frugalware.org/vmiklos/2008/06/16/non_public_scm_for_free_software</link>
	<description>&lt;p&gt;i find it really interesting that some people think that the scm for free software doesn't matter that much. just think about the &quot;open&quot;suse buildscripts, where the svn (in which they are tracked) is closed, or about &quot;free&quot;bsd, where the perforce repos (where _real_ development happens) is not checkoutable anonymously.&lt;/p&gt;
	&lt;p&gt;and no, i'm not rms who says you must use a free scm to develop free software, i just think a public access to it would be nice.&lt;/p&gt;
	&lt;p&gt;of course there are other projects like archlinux as well (no anonsvn), but i didn't wanted to start with it, since this post is not (just) about distro war..&lt;/p&gt;
	&lt;p&gt;ah and yes, the best of these is Debian where many maintainer use just a single huge generated diff and the real scm where they develop such diffs isn't public, either.&lt;/p&gt;
	&lt;p&gt;(finally a bad example is Ubuntu where the whole webapp behind the distro where all the bzr code and bugs are stored is closed source as well.)&lt;/p&gt;
	&lt;p&gt;so at the end it'll turn out that we're more free, without having any &quot;open&quot; or &quot;free&quot; in our name, without having a frugalware-legal@ and such? &lt;img src=&quot;http://blogs.frugalware.org/img/smilies/icon_wink.gif&quot; alt=&quot;;)&quot; class=&quot;middle&quot; /&gt;
&lt;/p&gt;</description>
	<pubDate>Mon, 16 Jun 2008 09:40:25 +0000</pubDate>
</item>
<item>
	<title>Miklos: new in git-1.5.6: git cvsexportcommit -W</title>
	<guid>http://blogs.frugalware.org/xmlsrv/331@http://blogs.frugalware.org</guid>
	<link>http://blogs.frugalware.org/vmiklos/2008/06/14/new_in_git_1_5_6_git_cvsexportcommit_w</link>
	<description>&lt;p&gt;git-1.5.6 will be released soon (probably in a few weeks) and there are some interesting news in it.&lt;/p&gt;
	&lt;p&gt;one of them is the new git cvsimport -W switch which makes it easy to do bi-directional changes between git and cvs.&lt;/p&gt;
	&lt;p&gt;to set up your local repo:&lt;/p&gt;
&lt;pre&gt;$ CVSROOT=$URL cvs co module
$ cd module
$ git cvsimport&lt;/pre&gt;	&lt;p&gt;
this will do a fresh checkout of the cvs module and will import it to git. you will have two interesting git branch: origin is the &quot;reference&quot; one, you should not touch it, and you can work in master.&lt;/p&gt;
	&lt;p&gt;you can commit to master, etc.&lt;/p&gt;
	&lt;p&gt;then there are two tricky operations:&lt;/p&gt;
	&lt;p&gt;first, you may want to commit back your local commits.&lt;/p&gt;
	&lt;p&gt;to do this:&lt;/p&gt;
&lt;pre&gt;$ for i in $(git rev-list --reverse origin..master)
do
        git cvsexportcommit -W -c -p -u $i
done&lt;/pre&gt;	&lt;p&gt;
second, you may want to fetch upstream changes and rebase your local changes on top of them:&lt;/p&gt;
&lt;pre&gt;$ git cvsimport -i
$ git rebase origin&lt;/pre&gt;	&lt;p&gt;
that's all.&lt;/p&gt;
	&lt;p&gt;cookies goes to Dscho in commit &lt;a href=&quot;http://git.kernel.org/?p=git/git.git;a=commit;h=d775734c40afed216160437c59a45c93bdf28689&quot;&gt;d775734&lt;/a&gt;. &lt;img src=&quot;http://blogs.frugalware.org/img/smilies/icon_smile.gif&quot; alt=&quot;:)&quot; class=&quot;middle&quot; /&gt;
&lt;/p&gt;</description>
	<pubDate>Sat, 14 Jun 2008 01:38:47 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA478 - xdvik</title>
	<guid>http://frugalware.org/security/478#top</guid>
	<link>http://frugalware.org/security/478</link>
	<description>A security issue has been reported in xdvik, which can be exploited by malicious, local users.
			The vulnerability is caused by creating predictably named temporary files by using mktemp.Vulnerable version: 22.84.12-1, Unaffected version: 22.84.14-1kalgan1, CVEs: There is no CVE for this issue, see http://xdvi.sourceforge.net/releases.html#22.84.14</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA477 - graphicsmagick</title>
	<guid>http://frugalware.org/security/477#top</guid>
	<link>http://frugalware.org/security/477</link>
	<description>Some vulnerabilities have been reported in GraphicsMagick, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
			1) Two boundary errors exist within the &quot;ReadPALMImage()&quot; function in coders/palm.c. These can be exploited to cause a heap-based buffer underflow via a specially crafted PALM image.
			2) A boundary error exists within the &quot;DecodeImage()&quot; function in coders/pict.c. This can be exploited to cause a heap-based buffer overflow via a specially crafted PICT image.
			3) Multiple unspecified errors within the processing of XCF, DPX, and CINEON images can be exploited to crash the application.
			Successful exploitation may allow execution of arbitrary code.Vulnerable version: 1.1.12-1kalgan1, Unaffected version: 1.1.14-1kalgan1, CVEs: There is no CVE for this issue, see:
			http://sourceforge.net/project/shownotes.php?release_id=604785
			http://sourceforge.net/project/shownotes.php?release_id=604837</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA476 - asterisk-addons</title>
	<guid>http://frugalware.org/security/476#top</guid>
	<link>http://frugalware.org/security/476</link>
	<description>A vulnerability has been reported in Asterisk Addons, which can be exploited by malicious people to cause a DoS (Denial of Service).
			The problem is that the &quot;ooh323&quot; channel driver extracts memory addresses from incoming TCP packets and uses them in memory operations. This can be exploited to crash an affected application by sending a TCP packet containing invalid memory references.Vulnerable version: 1.4.4-1, Unaffected version: 1.4.7-1kalgan1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2543</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA475 - samba</title>
	<guid>http://frugalware.org/security/475#top</guid>
	<link>http://frugalware.org/security/475</link>
	<description>Secunia Research has discovered a vulnerability in Samba, which can be exploited by malicious people to compromise a vulnerable system.
			The vulnerability is caused due to a boundary error within the &quot;receive_smb_raw()&quot; function in lib/util_sock.c when parsing SMB packets. This can be exploited to cause a heap-based buffer overflow via an overly large SMB packet received in a client context.
			Successful exploitation allows execution of arbitrary code by tricking a user into connecting to a malicious server (e.g. by clicking an &quot;smb://&quot; link) or by sending specially crafted packets to an &quot;nmbd&quot; server configured as a local or domain master browser.Vulnerable version: 3.0.28-1, Unaffected version: 3.0.30-1kalgan1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1105</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA474 - blender</title>
	<guid>http://frugalware.org/security/474#top</guid>
	<link>http://frugalware.org/security/474</link>
	<description>Secunia Research has discovered a vulnerability in Blender, which can be exploited by malicious people to compromise a vulnerable system.
			The vulnerability is caused due to a boundary error within the &quot;imb_loadhdr()&quot; function in source/blender/imbuf/intern/radiance_hdr.c, which can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted Blender (*.blend) file containing a malicious Radiance RGBE image.
			Successful exploitation allows execution of arbitrary code.Vulnerable version: 2.45-1, Unaffected version: 2.45-2kalgan1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1102</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA473 - libvorbis</title>
	<guid>http://frugalware.org/security/473#top</guid>
	<link>http://frugalware.org/security/473</link>
	<description>Some vulnerabilities have been reported in libvorbis, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise an application using the library.
			1) An input validation error can be exploited to crash an application, cause an infinite loop, or to cause a heap overflow via a specially crafted OGG file containing a codebook dimension of &quot;0&quot;.
			2) An integer overflow error in the processing of residue partition values can be exploited to cause a heap-based buffer overflow via a specially crafted OGG file.
			3) An integer overflow error exists in the computation of &quot;quantvals&quot; and of required space for &quot;quantlist&quot;. This can be exploited to cause a heap-based buffer overflow via a specially crafted OGG file.
			Successful exploitation may allow execution of arbitrary code.Vulnerable version: 1.2.0-1, Unaffected version: 1.2.0-2kalgan1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1419
			http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1420
			http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1423</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA472 - emacs</title>
	<guid>http://frugalware.org/security/472#top</guid>
	<link>http://frugalware.org/security/472</link>
	<description>Morten Welinder has reported a vulnerability in GNU Emacs, which can be exploited by malicious people to compromise a user's system.
			The vulnerability is caused due to an error in the processing of fast-lock files (.flc) for corresponding source files. This can be exploited to execute arbitrary Emacs Lisp code when e.g. a source file is opened and a specially crafted fast-lock file exists in the same directory.
			Successful exploitation requires that &quot;font-lock-support-mode&quot; is set to &quot;fast-lock-mode&quot;.Vulnerable version: 22.1-3kalgan1, Unaffected version: 22.1-3kalgan2, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2142</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA471 - stunnel</title>
	<guid>http://frugalware.org/security/471#top</guid>
	<link>http://frugalware.org/security/471</link>
	<description>A security issue has been reported in Stunnel, which can be exploited by malicious people to bypass certain security restrictions.
			The security issue is caused due to an unspecified error in the OCSP functionality and can lead to a revoked certificate being successfully authenticated.Vulnerable version: 4.21-1, Unaffected version: 4.24-1kalgan1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2420</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA470 - imlib2</title>
	<guid>http://frugalware.org/security/470#top</guid>
	<link>http://frugalware.org/security/470</link>
	<description>Secunia Research has discovered two vulnerabilities in imlib2, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
			1) A boundary error exists within the &quot;load()&quot; function in src/modules/loaders/loader_pnm.c when processing the header of a PNM image file. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted PNM image in an application using the imlib2 library.
			Successful exploitation allows execution of arbitrary code.
			2) A boundary error exists within the &quot;load()&quot; function in src/modules/loader_xpm.c when processing an XPM image file. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted XPM image in an application using the imlib2 library.
			Successful exploitation may allow execution of arbitrary code.Vulnerable version: 1.4.0-1, Unaffected version: 1.4.0-2kalgan1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2426</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Security announcements: FSA478 - xdvik</title>
	<guid>http://bugs.frugalware.org/task/3127#top</guid>
	<link>http://bugs.frugalware.org/task/3127</link>
	<description>A security issue has been reported in xdvik, which can be exploited by malicious, local users.
			The vulnerability is caused by creating predictably named temporary files by using mktemp.Vulnerable version: 22.84.12-1, Unaffected version: 22.84.14-1kalgan1, CVEs: There is no CVE for this issue, see http://xdvi.sourceforge.net/releases.html#22.84.14</description>
	<pubDate>Thu, 12 Jun 2008 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Miklos: interesting git talk</title>
	<guid>http://blogs.frugalware.org/xmlsrv/330@http://blogs.frugalware.org</guid>
	<link>http://blogs.frugalware.org/vmiklos/2008/06/12/interesting_git_talk</link>
	<description>&lt;p&gt;yesterday somebody mentioned on #git &lt;a href=&quot;http://www.gitcasts.com/posts/railsconf-git-talk&quot;&gt;this talk&lt;/a&gt;. it's not a real video, just audio + slides but it's really nice. i would say if the &quot;Linus one&quot; made you say &quot;heh, this may worth to check out&quot; then this one will be the &quot;hey, this one prevented me from learning things the hard way&quot;.&lt;/p&gt;
	&lt;p&gt;it's just one hour and it describes so many important tricks that i haven't encountered elsewhere yet.&lt;/p&gt;
	&lt;p&gt;just watch it.
&lt;/p&gt;</description>
	<pubDate>Thu, 12 Jun 2008 16:54:48 +0000</pubDate>
</item>
<item>
	<title>Frugalware News: Frugalware Newsletter Issue 25</title>
	<guid>http://www.frugalware.org/news/100#top</guid>
	<link>http://www.frugalware.org/news/100</link>
	<description>The newsletter's aim is to keep you up to date with what's happened recently in the world of Frugalware.&lt;br /&gt;
            Features of this issue include:
            &lt;ul&gt;
                &lt;li&gt;Frugalware's developer are people too! - IroniQ&lt;/li&gt;
                &lt;li&gt;Tips and tricks - man - odd symbols appearing&lt;/li&gt;
                &lt;li&gt;ryuo is now a developer!&lt;/li&gt;
                &lt;li&gt;Users fight it out in IRC&lt;/li&gt;
            &lt;/ul&gt;
            You can read it &lt;a href=&quot;http://frugalware.org/newsletter/25&quot;&gt;here&lt;/a&gt;. We hope you like it!</description>
	<pubDate>Thu, 05 Jun 2008 11:46:39 +0000</pubDate>
</item>
<item>
	<title>Frugalware News: Frugalware Newsletter Issue 24</title>
	<guid>http://www.frugalware.org/news/99#top</guid>
	<link>http://www.frugalware.org/news/99</link>
	<description>The newsletter's aim is to keep you up to date with what's happened recently in the world of Frugalware.&lt;br /&gt;
            Features of this issue include:
            &lt;ul&gt;
                &lt;li&gt;Frugalware 0.9 &quot;Solaria&quot; pre1 released&lt;/li&gt;
                &lt;li&gt;Frugalware's developers are people too! - krix&lt;/li&gt;
                &lt;li&gt;Save money with pacman-g2, cron and wget&lt;/li&gt;
                &lt;li&gt;Focus On Package(s) - rxvt-unicode&lt;/li&gt;
            &lt;/ul&gt;
            You can read it &lt;a href=&quot;http://frugalware.org/newsletter/24&quot;&gt;here&lt;/a&gt;. We hope you like it!</description>
	<pubDate>Tue, 27 May 2008 12:57:50 +0000</pubDate>
</item>
<item>
	<title>Frugalware News: Frugalware 0.9pre1 (Solaria) released</title>
	<guid>http://www.frugalware.org/news/98#top</guid>
	<link>http://www.frugalware.org/news/98</link>
	<description>The Frugalware Developer Team is pleased to &lt;a href=&quot;http://frugalware.org/news/98&quot;&gt;announce&lt;/a&gt; the immediate availability of Frugalware 0.9pre1, the first technical preview of the upcoming 0.9 stable release.&lt;br /&gt;
            A short and incomplete list of changes since 0.8:&lt;br /&gt;
            &lt;ul&gt;
                &lt;li&gt;Improvements:
                    &lt;ul&gt;
                        &lt;li&gt;The network configuration utility now lists card details next to interface names, in case you would now know what is the interface name for your cards.&lt;/li&gt;
                        &lt;li&gt;The USB installer is now a plain image, you can copy it to your USB stick under any operating system (you needed a running Linux system to install the previous version).&lt;/li&gt;
												&lt;li&gt;Changed the CHOST variable to $arch-frugalware-linux from a mix of $arch-pc-linux-gnu / $arch-unknown-linux, which generally causes more consistency and helps reporting bugs for upstream developers.&lt;/li&gt;
												&lt;li&gt;Improved security and general user support. We work together with other Linux vendors to provide better security support, and now our forums are &lt;a href=&quot;http://frugalware.org/mailman/listinfo/frugalware-forums/&quot;&gt;mirrored&lt;/a&gt; on a mailing list, so more developers can help you.&lt;/li&gt;
												&lt;li&gt;More than 150 other minor features / bugs have been implemented / fixed resulting in more than 2400 changes since the last release.&lt;/li&gt;
                    &lt;/ul&gt;
                &lt;/li&gt;
                &lt;li&gt;Package updates:
                    &lt;ul&gt;
                        &lt;li&gt;Linux 2.6.25 + security fixes&lt;/li&gt;
                        &lt;li&gt;GCC 4.3.0&lt;/li&gt;
                        &lt;li&gt;GNOME 2.22&lt;/li&gt;
                        &lt;li&gt;More than 900 other package updates&lt;/li&gt;
                    &lt;/ul&gt;
                &lt;/li&gt;
                &lt;li&gt;New packages:
                    &lt;ul&gt;
                        &lt;li&gt;About 40 new Java library&lt;/li&gt;
                        &lt;li&gt;Several new Drupal modules&lt;/li&gt;
                        &lt;li&gt;Many new octave modules.&lt;/li&gt;
                        &lt;li&gt;More than 150 other new packages&lt;/li&gt;
                    &lt;/ul&gt;
                &lt;/li&gt;
            &lt;/ul&gt;
            Please refer to the Frugalware &lt;a href=&quot;http://ftp.frugalware.org/pub/frugalware/frugalware-testing/ChangeLog.txt&quot;&gt;Testing ChangeLog&lt;/a&gt; for more information.&lt;br /&gt;
						We now have a &lt;a href=&quot;http://bugs.frugalware.org/?do=roadmap&quot;&gt;feature schedule&lt;/a&gt; for new functionalities we plan to implement before we release Solaria as stable.&lt;br /&gt;
            Download for i686:&lt;br /&gt;
            &lt;b&gt;NOTE&lt;/b&gt;: Click &lt;a href=&quot;http://frugalware.org/docs/install#_choosing_installation_flavor&quot;&gt;here&lt;/a&gt; to read more about what media you need for the installation.&lt;br /&gt;
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/fwlive-0.9pre1-i686-full.iso&quot;&gt;livecd&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-net.iso&quot;&gt;netinstall&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-usb.img&quot;&gt;usb&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-tftp.img&quot;&gt;tftp&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd1.iso&quot;&gt;cd1&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd2.iso&quot;&gt;cd2&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd3.iso&quot;&gt;cd3&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd4.iso&quot;&gt;cd4&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd5.iso&quot;&gt;cd5&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd6.iso&quot;&gt;cd6&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd7.iso&quot;&gt;cd7&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd8.iso&quot;&gt;cd8&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd9.iso&quot;&gt;cd9&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd10.iso&quot;&gt;cd10&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd11.iso&quot;&gt;cd11&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd12.iso&quot;&gt;cd12&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd13.iso&quot;&gt;cd13&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-cd14.iso&quot;&gt;cd14&lt;/a&gt;,
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-dvd1.iso&quot;&gt;dvd1&lt;/a&gt; and
                &lt;a href=&quot;http://frugalware.org/download/frugalware-testing-iso/frugalware-0.9pre1-i686-dvd2.iso&quot;&gt;dvd2&lt;/a&gt;
                &lt;br /&gt;
            SHA1SUMS:
						&lt;pre&gt;
ab6a264297f1a3686804f81e779b8e20ade6efb4  frugalware-0.9pre1-i686-cd1.iso
14f3f4afc2661c87a7cc36ece684b069c283d12e  frugalware-0.9pre1-i686-cd2.iso
f5f0b234cd15a5708c34b6810d5c9a7960b50230  frugalware-0.9pre1-i686-cd3.iso
cc8cf8698d4da9eb10e00d27f11c33d8760353fc  frugalware-0.9pre1-i686-cd4.iso
7dd673e01a2dab93c84d5f2ca914db1ae427adbb  frugalware-0.9pre1-i686-cd5.iso
4708a26a47671ee06093f5ecb14d489a5c634049  frugalware-0.9pre1-i686-cd6.iso
36594e953cd230caf253ee3441e563fc4ce6ba58  frugalware-0.9pre1-i686-cd7.iso
0eb4ff1a316839a0291d408360d07226fcb91be5  frugalware-0.9pre1-i686-cd8.iso
1cbfefe44ec7a04ec5cf360714091b87ffbc0343  frugalware-0.9pre1-i686-cd9.iso
46148a9c0484f37c305170a01304be1b4e849202  frugalware-0.9pre1-i686-cd10.iso
a110e9b278cbafa5fd5de07da60b73a918736a0c  frugalware-0.9pre1-i686-cd11.iso
09c1eb7fd33e69461b55c478984e7ed1ec587813  frugalware-0.9pre1-i686-cd12.iso
c440e2a75df20876c9520f1f5fc831fd975e3109  frugalware-0.9pre1-i686-cd13.iso
e564bd70640f7533696da0cc7affd4e231b11542  frugalware-0.9pre1-i686-cd14.iso
bfdce2433553de2142bf7a17f9ed89f3fa77ef9c  frugalware-0.9pre1-i686-dvd1.iso
6e350eb8e5c57d2ac580a3e19ec6f558a2b7f504  frugalware-0.9pre1-i686-dvd2.iso
38f540c04ebda2f0bd5e7dc734275b2602784b4f  frugalware-0.9pre1-i686-net.iso
57259add044fcdef89ae5a21e0365d3dfff47e23  fwlive-0.9pre1-i686-full.iso
8914d8986865877e6dbebf1c992ba6be01075550  frugalware-0.9pre1-i686-tftp.img
f443ddfb61652ccde5f87135965e467e3bc660f7  frugalware-0.9pre1-i686-usb.img
            &lt;/pre&gt;</description>
	<pubDate>Mon, 12 May 2008 22:05:24 +0000</pubDate>
</item>
<item>
	<title>Frugalware News: Frugalware Newsletter Issue 23</title>
	<guid>http://www.frugalware.org/news/97#top</guid>
	<link>http://www.frugalware.org/news/97</link>
	<description>The newsletter's aim is to keep you up to date with what's happened recently in the world of Frugalware.&lt;br /&gt;
            Features of this issue include:
            &lt;ul&gt;
                &lt;li&gt;Frugalware newsletter issue 21, where are you?&lt;/li&gt;
                &lt;li&gt;New packagers are making progress&lt;/li&gt;
                &lt;li&gt;Krix is back!&lt;/li&gt;
                &lt;li&gt;Frugalware's developers are people too! - bouleetbil&lt;/li&gt;
                &lt;li&gt;Tip - How to mount an ISO image&lt;/li&gt;
            &lt;/ul&gt;
            You can read it &lt;a href=&quot;http://frugalware.org/newsletter/23&quot;&gt;here&lt;/a&gt;. We hope you like it!</description>
	<pubDate>Fri, 09 May 2008 11:53:54 +0000</pubDate>
</item>
<item>
	<title>Miklos: fop 0.9x</title>
	<guid>http://blogs.frugalware.org/xmlsrv/329@http://blogs.frugalware.org</guid>
	<link>http://blogs.frugalware.org/vmiklos/2008/05/04/fop_0_9x</link>
	<description>&lt;p&gt;uhm, this will be a long post, but i'll try to keep it short &lt;img src=&quot;http://blogs.frugalware.org/img/smilies/icon_smile.gif&quot; alt=&quot;:)&quot; class=&quot;middle&quot; /&gt;&lt;/p&gt;
	&lt;p&gt;a few words about fop. we write our documentation in asciidoc. asciidoc is plain text with a very simple markup, asciidoc can convert this to docbook. then docbook-xsl can convert this to .fo, finally fop can convert .fo to .pdf.&lt;/p&gt;
	&lt;p&gt;my problem with fop is that it's written in java and we just used the upstream binary. this is primarily a security problem.&lt;/p&gt;
	&lt;p&gt;so, about one and a half months ago got the crazy idea to compile fop from source. of course the correct way to do this is to package first the depends. this is really a avalanche, becase we didn't have too much generic java libs packaged, so i had to package many. namely:&lt;/p&gt;
	&lt;p&gt;jflex, piccolo, gnu.regexp, jarjar, jmock, qdox, easymock, hamcrest, iso-relax, relaxngdatatype, xsdlib, msv, xpp3, xpp2, gnu-crypto, apache-log4j, xmldb-api, ws-jaxme, dom4j, jdom, icu4j, jaxp, jaxp, xom, jaxen, rhino, batik, servletapi, jaf, gnuinetlib, gnumail, avalon-logkit, avalon-framework, commons-logging, commons-io and xmlgraphics-commons.&lt;/p&gt;
	&lt;p&gt;hm. that's 36. horrible &lt;img src=&quot;http://blogs.frugalware.org/img/smilies/icon_wink.gif&quot; alt=&quot;;)&quot; class=&quot;middle&quot; /&gt;&lt;/p&gt;
	&lt;p&gt;the nice thing is that all these (except xmlgraphics-commons because classpath still lacks jpeg support) are compiled with the ecj/gcj toolchain, without any sun blob.&lt;/p&gt;
	&lt;p&gt;the other benefits are:&lt;/p&gt;
	&lt;ul&gt;
	&lt;li&gt;a native fop binary:
&lt;/li&gt;&lt;/ul&gt;
&lt;pre&gt;$ file /usr/bin/fop
/usr/bin/fop: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), for GNU/Linux 2.6.0, dynamically linked (uses shared libs), stripped&lt;/pre&gt;	
	&lt;li&gt;now we got rid of fop-devel, since this version can both convert ttf fonts to xml ones (needed if you want to embed custom fonts into pdf) and convert fo documents to pdf ones.&lt;/li&gt;
	
	&lt;p&gt;yay!
&lt;/p&gt;</description>
	<pubDate>Sun, 04 May 2008 00:48:04 +0000</pubDate>
</item>
<item>
	<title>Frugalware News: Frugalware Newsletter Issue 22</title>
	<guid>http://www.frugalware.org/news/96#top</guid>
	<link>http://www.frugalware.org/news/96</link>
	<description>The newsletter's aim is to keep you up to date with what's happened recently in the world of Frugalware.&lt;br /&gt;
            Features of this issue include:
            &lt;ul&gt;
                &lt;li&gt;New Frugalware mirrors&lt;/li&gt;
                &lt;li&gt;&lt;b&gt;MANY&lt;/b&gt; Security fixes&lt;/li&gt;
                &lt;li&gt;Frugalware's developers are people too! - Boobaa&lt;/li&gt;
                &lt;li&gt;Focus On Package(s) - Openbox&lt;/li&gt;
            &lt;/ul&gt;
            You can read it &lt;a href=&quot;http://frugalware.org/newsletter/21&quot;&gt;here&lt;/a&gt;. We hope you like it!</description>
	<pubDate>Wed, 30 Apr 2008 11:08:56 +0000</pubDate>
</item>
<item>
	<title>Miklos: message-ids</title>
	<guid>http://blogs.frugalware.org/xmlsrv/328@http://blogs.frugalware.org</guid>
	<link>http://blogs.frugalware.org/vmiklos/2008/04/29/message_ids</link>
	<description>&lt;p&gt;ok, this post will be a big generic, but it seems this is still totally new to some people. so, the Message-ID header in an email is ideally unique and you can easily use it to refer to an email in an other discussion.&lt;/p&gt;
	&lt;p&gt;in this post i want to deal with 3 issues:&lt;/p&gt;
	&lt;p&gt;first, how to display it in your mail client. ok, this depends on your mue, in mutt, you need to add
&lt;/p&gt;
&lt;pre&gt;unignore message-id&lt;/pre&gt;	&lt;p&gt; to your muttrc.&lt;/p&gt;
	&lt;p&gt;second, if you want to search for a message-id in a folder, that's your mua's task as well. in mutt, you can do it by for example
&lt;/p&gt;
&lt;pre&gt;~i &lt;a href=&quot;mailto:200804281829.11866.henrikau@orakel.ntnu.no&quot;&gt;200804281829.11866.henrikau@orakel.ntnu.no&lt;/a&gt;&lt;/pre&gt;	&lt;p&gt;
the third trick isn't mua-specific. if you want to link the message, and the list is indexed by gmane, then you can just type
&lt;/p&gt;
&lt;pre&gt;http://mid.gmane.org/200804281829.11866.henrikau@orakel.ntnu.no&lt;/pre&gt;	&lt;p&gt; and it'll redirect to
&lt;/p&gt;
&lt;pre&gt;http://article.gmane.org/gmane.comp.version-control.git/80566&lt;/pre&gt;	&lt;p&gt;
ok, that's all for today &lt;img src=&quot;http://blogs.frugalware.org/img/smilies/icon_smile.gif&quot; alt=&quot;:)&quot; class=&quot;middle&quot; /&gt;
&lt;/p&gt;</description>
	<pubDate>Mon, 28 Apr 2008 22:38:09 +0000</pubDate>
</item>

</channel>
</rss>
