
Hello and welcome to Linux Security Weekly for October 14, 2012. Linux Security Weekly is the audio podcast which covers current and important security vulnerabilities in Linux and open source software for the past week.
Show Notes:
News
bind
https://kb.isc.org/article/AA-00801
Tomcat 5.5.x branch End of Life
http://www.mail-archive.com/announce@tomcat.apache.org/msg00088.html
Firefox 16.0.1
http://www.mozilla.org/en-US/firefox/16.0.1/releasenotes/
http://www.mozilla.org/en-US/firefox/10.0.9/releasenotes/
Nessus 5.0.2
http://blog.tenablesecurity.com/2012/10/nessus-502-available.html
Nessus HTML5 interface now available
http://blog.tenablesecurity.com/2012/10/nessus-html5-interface-beta.html
Distro Updates
Red Hat
kernel 5.6 EUS
http://rhn.redhat.com/errata/RHSA-2012-1347.html
thunderbird
http://rhn.redhat.com/errata/RHSA-2012-1351.html
http://rhn.redhat.com/errata/RHSA-2012-1362.html
firefox
http://rhn.redhat.com/errata/RHSA-2012-1350.html
xulrunner
http://rhn.redhat.com/errata/RHSA-2012-1361.html
libvirt
http://rhn.redhat.com/errata/RHSA-2012-1359.html
bind
http://rhn.redhat.com/errata/RHSA-2012-1365.html
http://rhn.redhat.com/errata/RHSA-2012-1364.html
http://rhn.redhat.com/errata/RHSA-2012-1363.html
Ubuntu
kernel
http://www.ubuntu.com/usn/usn-1598-1/
http://www.ubuntu.com/usn/usn-1606-1/
http://www.ubuntu.com/usn/usn-1607-1/
http://www.ubuntu.com/usn/usn-1610-1/
firefox
http://www.ubuntu.com/usn/usn-1600-1/
http://www.ubuntu.com/usn/usn-1608-1/
thunderbird
http://www.ubuntu.com/usn/usn-1611-1/
bind
http://www.ubuntu.com/usn/usn-1601-1/
ruby
http://www.ubuntu.com/usn/usn-1602-1/
http://www.ubuntu.com/usn/usn-1603-1/
Debian
icedove
http://www.debian.org/security/2012/dsa-2556
bacula
http://www.debian.org/security/2012/dsa-2558
hostapd
http://www.debian.org/security/2012/dsa-2557
Debian DNS vuln: CVE-2012-5166
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690118
http://security-tracker.debian.org/tracker/CVE-2012-5166
Extras
XSS Explained
http://theinsider.deep-ice.com/texts/xss_exposed.txt
http://en.wikipedia.org/wiki/Cross-site_scripting
