<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.nessus.org/">
<title>Nessus.org Plugins</title>
<link>http://www.nessus.org/scripts.php</link>
<description>All the newest security checks for the Nessus scanner</description>

<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34095" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34094" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34093" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34092" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34091" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34090" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34089" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34088" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34087" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34086" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34085" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34084" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34083" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34082" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34081" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34080" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34079" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34078" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34077" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34076" />
</rdf:Seq>
</items>
</channel>

<image rdf:about="http://www.nessus.org/images/RssLogo.jpg">
<title>Nessus Plugins</title>
<url>http://www.nessus.org/images/RssLogo.jpg</url>
<link>http://www.nessus.org/</link>
</image>

<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34095">
<title>Moodle lib/kses.php Remote Code Execution Vulnerability</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote web server contains a PHP application that allows execution<br />
of arbitrary code remotely. <br />
<br />
Description :<br />
<br />
The version of Moodle on the remote host includes a version of the<br />
KSES HTML filtering library that does not safely call 'preg_replace()'<br />
in the function 'kses_bad_protocol_once()' in 'lib/kses.php'.  An<br />
unauthenticated remote attacker can leverage this issue to inject<br />
arbitrary PHP code that will be executed subject to the privileges of<br />
the web server user id. <br />
<br />
Note that there reportedly are also several cross-site scripting and<br />
HTML filtering bypass issues in the version of the KSES library in<br />
use, although Nessus has not tested for them explicitly. <br />
<br />
See also :<br />
<br />
<a href="http://cvs.moodle.org/moodle/lib/kses.php?r1=1.3.2.2&amp;r2=1.3.2.3" target="_blank">http://cvs.moodle.org/moodle/lib/kses.php?r1=1.3.2.2&amp;r2=1.3.2.3</a><br />
<a href="http://moodle.org/mod/forum/discuss.php?d=95031" target="_blank">http://moodle.org/mod/forum/discuss.php?d=95031</a><br />
<a href="http://docs.moodle.org/en/Release_Notes#Moodle_1.8.5" target="_blank">http://docs.moodle.org/en/Release_Notes#Moodle_1.8.5</a><br />
<br />
Solution :<br />
<br />
Upgrade to Moodle 1.8.5, 1.9, or any recent nightly 1.7.x or 1.6.x<br />
build. <br />
<br />
Risk factor : <br />
<br />
High / CVSS Base Score : 7.5<br />
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34095</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34094">
<title>USN640-1 : libxml2 vulnerability</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
These remote packages are missing security patches :<br />
- libxml2 <br />
- libxml2-dbg <br />
- libxml2-dev <br />
- libxml2-doc <br />
- libxml2-utils <br />
- python-libxml2 <br />
- python-libxml2-dbg <br />
- python2.4-libxml2 <br />
<br />
<br />
Description :<br />
<br />
Andreas Solberg discovered that libxml2 did not handle recursive entities<br />
safely.  If an application linked against libxml2 were made to process<br />
a specially crafted XML document, a remote attacker could exhaust the<br />
system's CPU resources, leading to a denial of service.<br />
<br />
Solution :<br />
<br />
Upgrade to : <br />
- libxml2-2.6.31.dfsg-2ubuntu1.1 (Ubuntu 8.04)<br />
- libxml2-dbg-2.6.31.dfsg-2ubuntu1.1 (Ubuntu 8.04)<br />
- libxml2-dev-2.6.31.dfsg-2ubuntu1.1 (Ubuntu 8.04)<br />
- libxml2-doc-2.6.31.dfsg-2ubuntu1.1 (Ubuntu 8.04)<br />
- libxml2-utils-2.6.31.dfsg-2ubuntu1.1 (Ubuntu 8.04)<br />
- python-libxml2-2.6.31.dfsg-2ubuntu1.1 (Ubuntu 8.04)<br />
- python-libxml2-dbg-2.6.31.dfsg-2ubuntu1.1 (Ubuntu 8.04)<br />
- python2.4-libxml2-2.6.24.dfsg-1ubuntu1.2 (Ubuntu 6.06)<br />
<br />
<br />
<br />
Risk factor : High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34094</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34093">
<title>[GLSA-200809-04] MySQL: Privilege bypass</title>
<description><![CDATA[The remote host is affected by the vulnerability described in GLSA-200809-04<br />
(MySQL: Privilege bypass)<br />
<br />
<br />
    Sergei Golubchik reported that MySQL imposes no restrictions on the<br />
    specification of &quot;DATA DIRECTORY&quot; or &quot;INDEX DIRECTORY&quot; in SQL &quot;CREATE<br />
    TABLE&quot; statements.<br />
  <br />
Impact<br />
<br />
    An authenticated remote attacker could create MyISAM tables, specifying<br />
    DATA or INDEX directories that contain future table files by other<br />
    database users, or existing table files in the MySQL data directory,<br />
    gaining access to those tables.<br />
  <br />
Workaround<br />
<br />
    There is no known workaround at this time.<br />
  <br />
References:<br />
    <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2079" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2079</a><br />
<br />
<br />
Solution: <br />
    All MySQL users should upgrade to the latest version:<br />
    # emerge --sync<br />
    # emerge --ask --oneshot --verbose &quot;&gt;=dev-db/mysql-5.0.60-r1&quot;<br />
  <br />
<br />
Risk factor : Medium<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34093</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34092">
<title>[GLSA-200809-03] RealPlayer: Buffer overflow</title>
<description><![CDATA[The remote host is affected by the vulnerability described in GLSA-200809-03<br />
(RealPlayer: Buffer overflow)<br />
<br />
<br />
    Dyon Balding of Secunia Research reported an unspecified heap-based<br />
    buffer overflow in the Shockwave Flash (SWF) frame handling.<br />
  <br />
Impact<br />
<br />
    By enticing a user to open a specially crafted SWF (Shockwave Flash)<br />
    file, a remote attacker could be able to execute arbitrary code with<br />
    the privileges of the user running the application.<br />
  <br />
Workaround<br />
<br />
    There is no known workaround at this time.<br />
  <br />
References:<br />
    <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5400" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5400</a><br />
<br />
<br />
Solution: <br />
    All RealPlayer users should upgrade to the latest version:<br />
    # emerge --sync<br />
    # emerge --ask --oneshot --verbose &quot;&gt;=media-video/realplayer-11.0.0.4028-r1&quot;<br />
  <br />
<br />
Risk factor : Medium<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34092</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34091">
<title>[GLSA-200809-02] dnsmasq: Denial of Service and DNS spoofing</title>
<description><![CDATA[The remote host is affected by the vulnerability described in GLSA-200809-02<br />
(dnsmasq: Denial of Service and DNS spoofing)<br />
<br />
<br />
    Dan Kaminsky of IOActive reported that dnsmasq does not randomize UDP<br />
    source ports when forwarding DNS queries to a recursing DNS server<br />
    (CVE-2008-1447).<br />
    Carlos Carvalho reported that dnsmasq in the 2.43 version does not<br />
    properly handle clients sending inform or renewal queries for unknown<br />
    DHCP leases, leading to a crash (CVE-2008-3350).<br />
  <br />
Impact<br />
<br />
    A remote attacker could send spoofed DNS response traffic to dnsmasq,<br />
    possibly involving generating queries via multiple vectors, and spoof<br />
    DNS replies, which could e.g. lead to the redirection of web or mail<br />
    traffic to malicious sites. Furthermore, an attacker could generate<br />
    invalid DHCP traffic and cause a Denial of Service.<br />
  <br />
Workaround<br />
<br />
    There is no known workaround at this time.<br />
  <br />
References:<br />
    <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3350" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3350</a><br />
    <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447</a><br />
<br />
<br />
Solution: <br />
    All dnsmasq users should upgrade to the latest version:<br />
    # emerge --sync<br />
    # emerge --ask --oneshot --verbose &quot;&gt;=net-dns/dnsmasq-2.45&quot;<br />
  <br />
<br />
Risk factor : Medium<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34091</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34090">
<title>[GLSA-200809-01] yelp: User-assisted execution of arbitrary code</title>
<description><![CDATA[The remote host is affected by the vulnerability described in GLSA-200809-01<br />
(yelp: User-assisted execution of arbitrary code)<br />
<br />
<br />
    Aaron Grattafiori reported a format string vulnerability in the<br />
    window_error() function in yelp-window.c.<br />
  <br />
Impact<br />
<br />
    A remote attacker can entice a user to open specially crafted &quot;man:&quot; or<br />
    &quot;ghelp:&quot; URIs in yelp, or an application using yelp such as Firefox or<br />
    Evolution, and execute arbitrary code with the privileges of that user.<br />
  <br />
Workaround<br />
<br />
    There is no known workaround at this time.<br />
  <br />
References:<br />
    <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3533" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3533</a><br />
<br />
<br />
Solution: <br />
    All yelp users running GNOME 2.22 should upgrade to the latest version:<br />
    # emerge --sync<br />
    # emerge --ask --oneshot --verbose &quot;&gt;=gnome-extra/yelp-2.22.1-r2&quot;<br />
    All yelp users running GNOME 2.20 should upgrade to the latest version:<br />
    # emerge --sync<br />
    # emerge --ask --oneshot --verbose &quot;&gt;=gnome-extra/yelp-2.20.0-r1&quot;<br />
  <br />
<br />
Risk factor : Medium<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34090</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34089">
<title>FreeBSD : php -- input validation error in safe_mode (1154)</title>
<description><![CDATA[<br />
The remote host is missing an update to the system<br />
<br />
The following package is affected: php5<br />
<br />
Solution : Update the package on the remote host<br />
See also : <br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34089</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34088">
<title>[DSA1634] DSA-1634-1 wordnet</title>
<description><![CDATA[<br />
Rob Holland discovered several programming errors in WordNet, an<br />
electronic lexical database of the English language. These flaws could<br />
allow arbitrary code execution when used with untrusted input, for<br />
example when WordNet is in use as a back end for a web application.<br />
For the stable distribution (etch), these problems have been fixed in<br />
version 1:2.1-4+etch1.<br />
<br />
<br />
Solution : <a href="http://www.debian.org/security/2008/dsa-1634" target="_blank">http://www.debian.org/security/2008/dsa-1634</a><br />
Risk factor : High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34088</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34087">
<title>[DSA1633] DSA-1633-1 slash</title>
<description><![CDATA[<br />
It has been discovered that Slash, the Slashdot Like Automated<br />
Storytelling Homepage suffers from two vulnerabilities related to<br />
insufficient input sanitation, leading to execution of SQL commands <br />
(CVE-2008-2231) and cross-site scripting (CVE-2008-2553).<br />
For the stable distribution (etch), these problems have been fixed in<br />
version 2.2.6-8etch1.<br />
<br />
<br />
Solution : <a href="http://www.debian.org/security/2008/dsa-1633" target="_blank">http://www.debian.org/security/2008/dsa-1633</a><br />
Risk factor : High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34087</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34086">
<title>SSA-2008-247-01 php </title>
<description><![CDATA[<br />
New php packages are available for Slackware 10.2 and 11.0 to fix security<br />
issues.  These releases are the last to contain PHP 4.4.x, which was upgraded<br />
to version 4.4.9 to fix PCRE issues and other bugs.<br />
<br />
Please note that this is the FINAL release of PHP4, and it has already passed<br />
the announced end-of-life.  Sites should seriously consider migrating to PHP5<br />
rather than upgrading to php-4.4.9.<br />
<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34086</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34085">
<title>Novell iPrint Client Buffer Overflow Vulnerability</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Windows host has an application that is affected by a<br />
buffer overflow vulnerability. <br />
<br />
Description :<br />
<br />
The installed version of Novell iPrint Client is affected by a buffer<br />
overflow vulnerability. <br />
<br />
By passing very long arguments to either 'GetPrinterURLList()',<br />
'GetPrinterURLList2()', or 'GetFileList2()' functions available in<br />
ActiveX control 'ienipp.ocx', it may be possible to cause a heap-based<br />
buffer overflow in function 'IppCreateServerRef()' provided by<br />
'nipplib.dll'. <br />
<br />
Successful exploitation of this issue may result in arbitrary code<br />
execution on the remote system. <br />
<br />
See also :<br />
<br />
<a href="http://secunia.com/secunia_research/2008-33/advisory/" target="_blank">http://secunia.com/secunia_research/2008-33/advisory/</a><br />
<a href="http://download.novell.com/Download?buildid=3q-_lVDVRFI~" target="_blank">http://download.novell.com/Download?buildid=3q-_lVDVRFI~</a><br />
<a href="http://download.novell.com/Download?buildid=dv_yn4TOPmQ~" target="_blank">http://download.novell.com/Download?buildid=dv_yn4TOPmQ~</a><br />
<br />
Solution :<br />
<br />
Upgrade to <br />
<br />
    - Novell iPrint Client for Vista   5.08  or  <br />
    - Novell iPrint Client for Windows 4.38 <br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 9.3<br />
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34085</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34084">
<title>Default password (trans) for 'trans' account</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
An account on the remote host uses a known password. <br />
<br />
Description :<br />
<br />
The account 'trans' on the remote host has the password 'trans'.  An<br />
attacker may leverage this issue to gain access to the affected system<br />
and launch further attacks against it. <br />
<br />
Solution :<br />
<br />
Change the password for this account or disable it. <br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 7.5<br />
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34084</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34083">
<title>Unpassworded 'r00t' account</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
An account on the remote host does not have a password. <br />
<br />
Description :<br />
<br />
The account 'r00t' on the remote host has no password.  An attacker<br />
may leverage this issue to gain access to the affected system and<br />
launch further attacks against it. <br />
<br />
Solution :<br />
<br />
Set a password for this account or disable it. <br />
<br />
Risk factor :<br />
<br />
Critical / CVSS Base Score : 10.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34083</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34082">
<title>Default password (bank) for 'bank' account</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
An account on the remote host uses a known password. <br />
<br />
Description :<br />
<br />
The account 'bank' on the remote host has the password 'bank'.  An<br />
attacker may leverage this issue to gain access to the affected system<br />
and launch further attacks against it. <br />
<br />
Solution :<br />
<br />
Change the password for this account or disable it. <br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 7.5<br />
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34082</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34081">
<title>Default password (admin) for 'admin' account</title>
<description><![CDATA[<br />
Synopsis : <br />
<br />
The remote system can be accessed with a default administrator<br />
account. <br />
<br />
Description :<br />
<br />
The account 'admin' on the remote host has the password 'admin'.  An<br />
attacker may leverage this issue to gain access to the affected system<br />
and launch further attacks against it. <br />
<br />
Solution :<br />
<br />
Change the password for this account or disable it. <br />
<br />
Risk factor :<br />
<br />
Critical / CVSS Base Score : 10.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34081</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34080">
<title>USN639-1 : tiff vulnerability</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
These remote packages are missing security patches :<br />
- libtiff-opengl <br />
- libtiff-tools <br />
- libtiff4 <br />
- libtiff4-dev <br />
- libtiffxx0c2 <br />
<br />
<br />
Description :<br />
<br />
Drew Yao discovered that the TIFF library did not correctly validate LZW<br />
compressed TIFF images.  If a user or automated system were tricked into<br />
processing a malicious image, a remote attacker could execute arbitrary<br />
code or cause an application linked against libtiff to crash, leading<br />
to a denial of service.<br />
<br />
Solution :<br />
<br />
Upgrade to : <br />
- libtiff-opengl-3.8.2-7ubuntu3.1 (Ubuntu 8.04)<br />
- libtiff-tools-3.8.2-7ubuntu3.1 (Ubuntu 8.04)<br />
- libtiff4-3.8.2-7ubuntu3.1 (Ubuntu 8.04)<br />
- libtiff4-dev-3.8.2-7ubuntu3.1 (Ubuntu 8.04)<br />
- libtiffxx0c2-3.8.2-7ubuntu3.1 (Ubuntu 8.04)<br />
<br />
<br />
<br />
Risk factor : High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34080</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34079">
<title>SuSE Security Update: Security update for vsftpd (vsftpd-5388)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch vsftpd-5388.<br />
<br />
Description :<br />
<br />
This update of vsftpd fixes a memory leak that can occur<br />
during authentication. (CVE-2008-2375) Additionally<br />
non-security bugs for SLES10 were fixed. There were some<br />
issues with simultaneous FTP PUT of the same file name that<br />
lead to a corrupted file on the server.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch vsftpd-5388.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34079</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34078">
<title>SuSE Security Update: Security update for opensc (opensc-5493)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch opensc-5493.<br />
<br />
Description :<br />
<br />
This update fix a security issues with opensc that occurs<br />
during initializing blank smart cards with Siemens CardOS<br />
M4. It allows to set the PIN of the smart card without<br />
authorization.  (CVE-2008-2235)<br />
<br />
NOTE: Already initialized cards are still vulnerable after<br />
this update. Please use the command-line tool pkcs15-tool<br />
with option --test-update and --update when necessary.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch opensc-5493.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34078</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34077">
<title>SuSE Security Update: libxslt: Fixed heap overflow (libxslt-5458)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch libxslt-5458.<br />
<br />
Description :<br />
<br />
A heap overflow in the RC4 cryptographic routines in<br />
libxslt was fixed which could be used by attackers to<br />
potentially execute code. (CVE-2008-2935)<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch libxslt-5458.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34077</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34076">
<title>SuSE Security Update: Security update for libxslt (libxslt-5457)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch libxslt-5457.<br />
<br />
Description :<br />
<br />
A heap overflow in the RC4 cryptographic routines in<br />
libxslt was fixed which could be used by attackers to<br />
potentially execute code. (CVE-2008-2935)<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch libxslt-5457.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34076</link>
<dc:date>?</dc:date>
</item>
</rdf:RDF>
