<?xml version="1.0" encoding="windows-1252"?>
<rss version="2.0">
                        <channel>
                                <title>SecurityLab.ru - Advisories</title>
                                <link>http://en.securitylab.ru/notification/</link>
                                <description>Network Security</description>

                                                                <image>
                                        <url>http://en.securitylab.ru/_SecurityLab.Images/Logo/Logo_Top.gif</url>
                                        <title>SecurityLab.ru - Advisories</title>
                                        <link>http://en.securitylab.ru/notification/</link>
                                </image>
                                
                                                      
                                        <item>
                                                <title>Oracle Critical Patch Update Advisory - January 2012</title> 
                                                <link>http://en.securitylab.ru/notification/413591.php</link> 
                                                <description>A Critical Patch Update is a collection of patches for multiple security vulnerabilities. </description> 
                                                <category>Advisories</category> 
                                                <pubDate>Thu, 19 Jan 2012 15:39:48 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413591.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS12-007: Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664)</title> 
                                                <link>http://en.securitylab.ru/notification/413311.php</link> 
                                                <description>This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. </description> 
                                                <category>Advisories</category> 
                                                <pubDate>Tue, 10 Jan 2012 21:41:34 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413311.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS12-006: Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)</title> 
                                                <link>http://en.securitylab.ru/notification/413310.php</link> 
                                                <description>This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. </description> 
                                                <category>Advisories</category> 
                                                <pubDate>Tue, 10 Jan 2012 21:41:02 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413310.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS12-005: Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146)</title> 
                                                <link>http://en.securitylab.ru/notification/413309.php</link> 
                                                <description>This security update resolves a privately reported vulnerability in Microsoft Windows.</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Tue, 10 Jan 2012 21:40:30 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413309.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS12-004: Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)</title> 
                                                <link>http://en.securitylab.ru/notification/413308.php</link> 
                                                <description>This security update resolves two privately reported vulnerabilities in Microsoft Windows.</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Tue, 10 Jan 2012 21:39:52 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413308.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS12-003: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524)</title> 
                                                <link>http://en.securitylab.ru/notification/413307.php</link> 
                                                <description>This security update resolves one privately reported vulnerability in Microsoft Windows.</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Tue, 10 Jan 2012 21:39:06 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413307.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS12-002: Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381)</title> 
                                                <link>http://en.securitylab.ru/notification/413306.php</link> 
                                                <description>This security update resolves a privately reported vulnerability in Microsoft Windows.</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Tue, 10 Jan 2012 21:38:28 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413306.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS12-001: Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615)</title> 
                                                <link>http://en.securitylab.ru/notification/413305.php</link> 
                                                <description>This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. </description> 
                                                <category>Advisories</category> 
                                                <pubDate>Tue, 10 Jan 2012 21:37:49 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413305.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS11-100: Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420)</title> 
                                                <link>http://en.securitylab.ru/notification/413141.php</link> 
                                                <description>This security update resolves one publicly disclosed vulnerability and three privately reported vulnerabilities in Microsoft .NET Framework. </description> 
                                                <category>Advisories</category> 
                                                <pubDate>Fri, 30 Dec 2011 09:44:00 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413141.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>FreeBSD-SA-11:10.pam: pam_start() does not validate service names</title> 
                                                <link>http://en.securitylab.ru/notification/413014.php</link> 
                                                <description>If an application that runs with root privileges allows the user to specify the name of the PAM policy to load, users who are permitted to run that application will be able to execute arbitrary code with root privileges.
</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Mon, 26 Dec 2011 11:28:21 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413014.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>FreeBSD-SA-11:09.pam_ssh: pam_ssh improperly grants access when user account has unencrypted SSH private keys</title> 
                                                <link>http://en.securitylab.ru/notification/413013.php</link> 
                                                <description>If the pam_ssh module is enabled, attackers may be able to gain access to user accounts which have unencrypted SSH private keys.
</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Mon, 26 Dec 2011 11:27:48 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413013.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>FreeBSD-SA-11:08.telnetd: telnetd code execution vulnerability</title> 
                                                <link>http://en.securitylab.ru/notification/413012.php</link> 
                                                <description>An attacker who can connect to the telnetd daemon can execute arbitrary code with the privileges of the daemon (which is usually the &quot;root&quot; superuser).
</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Mon, 26 Dec 2011 11:26:44 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413012.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>FreeBSD-SA-11:07.chroot: Code execution via chrooted ftpd</title> 
                                                <link>http://en.securitylab.ru/notification/413011.php</link> 
                                                <description>If ftpd is configured to place a user in a chroot environment, then an attacker who can log in as that user may be able to run arbitrary code with elevated (&quot;root&quot;) privileges.
</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Mon, 26 Dec 2011 11:26:06 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413011.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>FreeBSD-SA-11:06.bind: Remote packet Denial of Service against named(8) servers</title> 
                                                <link>http://en.securitylab.ru/notification/413010.php</link> 
                                                <description>A remote attacker could cause the BIND resolver to cache an invalid record, which could cause the BIND daemon to crash when that record is being queried.
</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Mon, 26 Dec 2011 11:25:07 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/413010.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS11-099: Cumulative Security Update for Internet Explorer (2618444)</title> 
                                                <link>http://en.securitylab.ru/notification/412411.php</link> 
                                                <description>This security update resolves three privately reported vulnerabilities in Internet Explorer. </description> 
                                                <category>Advisories</category> 
                                                <pubDate>Wed, 14 Dec 2011 00:31:34 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/412411.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS11-098: Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171)</title> 
                                                <link>http://en.securitylab.ru/notification/412409.php</link> 
                                                <description>This security update resolves a privately reported vulnerability in Microsoft Windows.</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Wed, 14 Dec 2011 00:28:55 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/412409.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS11-097: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2620712)</title> 
                                                <link>http://en.securitylab.ru/notification/412406.php</link> 
                                                <description>This security update resolves a privately reported vulnerability in Microsoft Windows.</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Wed, 14 Dec 2011 00:12:08 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/412406.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS11-096: Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241)</title> 
                                                <link>http://en.securitylab.ru/notification/412405.php</link> 
                                                <description>This security update resolves a privately reported vulnerability in Microsoft Office. </description> 
                                                <category>Advisories</category> 
                                                <pubDate>Wed, 14 Dec 2011 00:10:08 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/412405.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS11-095: Vulnerability in Active Directory Could Allow Remote Code Execution (2640045)</title> 
                                                <link>http://en.securitylab.ru/notification/412395.php</link> 
                                                <description>The vulnerability could allow remote code execution if an attacker logs on to an Active Directory domain and runs a specially crafted application. </description> 
                                                <category>Advisories</category> 
                                                <pubDate>Tue, 13 Dec 2011 23:49:04 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/412395.php</guid> 
                                        </item>
                                                              
                                        <item>
                                                <title>MS11-094: Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2639142)</title> 
                                                <link>http://en.securitylab.ru/notification/412394.php</link> 
                                                <description>This security update resolves two privately reported vulnerabilities in Microsoft Office.</description> 
                                                <category>Advisories</category> 
                                                <pubDate>Tue, 13 Dec 2011 23:43:47 +0300</pubDate> 
                                                                                                <guid isPermaLink="true">http://en.securitylab.ru/notification/412394.php</guid> 
                                        </item>
                                                                </channel>
                </rss>
                
