<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
	<title>Frugalware Linux Security</title>
	<description>Security announcements for Frugalware stable releases</description>
	<link>http://frugalware.org/security</link>
<item>
<title>FSA642 - drupal6-i18n</title>
<link>http://frugalware.org/security/642</link>
<guid>http://frugalware.org/security/642#top</guid>
<description>See FSA641 for details.Vulnerable version: 6.x_1.2-1, Unaffected version: 6.x_1.3-1locris1, CVEs: No CVE references, see http://drupal.org/node/731632.</description>
<pubDate>Fri, 12 Mar 2010 00:00:00 +0100</pubDate>
</item>
<item>
<title>FSA641 - drupal-i18n</title>
<link>http://frugalware.org/security/641</link>
<guid>http://frugalware.org/security/641#top</guid>
<description>A vulnerability has been reported in the Internationalization module for Drupal, which can be exploited by malicious users to compromise a vulnerable system.
			Certain unspecified input is not properly sanitised before being used to translate the text. This can be exploited to execute arbitrary PHP code by passing a malicious string to the input filter.Vulnerable version: 5.x_2.5-1, Unaffected version: 5.x_2.6-1locris1, CVEs: No CVE references, see http://drupal.org/node/731632.</description>
<pubDate>Fri, 12 Mar 2010 00:00:00 +0100</pubDate>
</item>
<item>
<title>FSA640 - drupal6</title>
<link>http://frugalware.org/security/640</link>
<guid>http://frugalware.org/security/640#top</guid>
<description>See FSA639 for details.Vulnerable version: 6.15-1, Unaffected version: 6.16-1locris1, CVEs: No CVE references, see http://drupal.org/node/731710.</description>
<pubDate>Thu, 11 Mar 2010 00:00:00 +0100</pubDate>
</item>
<item>
<title>FSA639 - drupal</title>
<link>http://frugalware.org/security/639</link>
<guid>http://frugalware.org/security/639#top</guid>
<description>Some vulnerabilities have been reported in Drupal, which can be exploited by malicious users to conduct script insertion attacks and bypass certain security restrictions.
			1) Input passed via the &quot;langcode&quot;, &quot;name&quot;, and &quot;native&quot; parameters in the languages interface while using the Locale module is not properly sanitised before being displayed to the user. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed.
			Successful exploitation requires &quot;administer languages&quot; permissions.
			2) An error in the handling of certain sessions can be exploited to maintain an open session despite the user being blocked.Vulnerable version: 5.21-1, Unaffected version: 5.22-2locris1, CVEs: No CVE references, see http://drupal.org/node/731710.</description>
<pubDate>Thu, 11 Mar 2010 00:00:00 +0100</pubDate>
</item>
<item>
<title>FSA638 - wordpress</title>
<link>http://frugalware.org/security/638</link>
<guid>http://frugalware.org/security/638#top</guid>
<description>A vulnerability has been discovered in WordPress, which can be exploited by malicious users to bypass certain security restrictions.
			The vulnerability is caused due to WordPress not properly restricting access to trashed posts, which can be exploited to e.g. view a trashed post by accessing it's page directly.
			Successful exploitation requires a valid user account.Vulnerable version: 2.9.1-1, Unaffected version: 2.9.2-1locris1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0682</description>
<pubDate>Wed, 10 Mar 2010 00:00:00 +0100</pubDate>
</item>
<item>
<title>FSA637 - xar</title>
<link>http://frugalware.org/security/637</link>
<guid>http://frugalware.org/security/637#top</guid>
<description>Braden Thomas from Apple has discovered a signature verification bypass issue in xar.  The issue is that xar_open assumes that the checksum is stored at offset 0, but xar_signature_copy_signed_data uses xar property &quot;checksum/offset&quot; to find the offset to the checksum when validating the signature.  As a result, a modified xar archive can pass signature validation by putting the checksum for the modified TOC at offset 0, pointing &quot;checksum/offset&quot; at the non-modified checksum at a higher offset, and using the original non-modified signature.Vulnerable version: 1.5.2-1, Unaffected version: 1.5.2-2locris1, CVEs: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0055</description>
<pubDate>Tue, 09 Mar 2010 00:00:00 +0100</pubDate>
</item>
<item>
<title>FSA - </title>
<link>http://frugalware.org/security/</link>
<guid>http://frugalware.org/security/#top</guid>
<description>Vulnerable version: , Unaffected version: , CVEs: </description>
<pubDate>Thu, 01 Jan 1970 01:00:00 +0100</pubDate>
</item>
<item>
<title>FSA - </title>
<link>http://frugalware.org/security/</link>
<guid>http://frugalware.org/security/#top</guid>
<description>Vulnerable version: , Unaffected version: , CVEs: </description>
<pubDate>Thu, 01 Jan 1970 01:00:00 +0100</pubDate>
</item>
<item>
<title>FSA - </title>
<link>http://frugalware.org/security/</link>
<guid>http://frugalware.org/security/#top</guid>
<description>Vulnerable version: , Unaffected version: , CVEs: </description>
<pubDate>Thu, 01 Jan 1970 01:00:00 +0100</pubDate>
</item>
<item>
<title>FSA - </title>
<link>http://frugalware.org/security/</link>
<guid>http://frugalware.org/security/#top</guid>
<description>Vulnerable version: , Unaffected version: , CVEs: </description>
<pubDate>Thu, 01 Jan 1970 01:00:00 +0100</pubDate>
</item>
</channel>
</rss>