<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Armor &#187; YaSSL</title>
	<atom:link href="http://www.informationarmor.com/tag/yassl/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.informationarmor.com</link>
	<description>Protecting Your Data. A public service from Arizona IT Management LLC</description>
	<lastBuildDate>Tue, 22 Jun 2010 16:27:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Vulnerabilities</title>
		<link>http://www.informationarmor.com/2010/01/29/vulnerabilities/</link>
		<comments>http://www.informationarmor.com/2010/01/29/vulnerabilities/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 15:21:47 +0000</pubDate>
		<dc:creator>root</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Unified Meeting Place]]></category>
		<category><![CDATA[YaSSL]]></category>

		<guid isPermaLink="false">http://www.informationarmor.com/?p=59</guid>
		<description><![CDATA[Cisco disclosed multiple vulnerabilities in their Unified MeetingPlace product. These issues leave the product vulnerable to SQL injection attacks and could allow attackers to bypass authentication. Cisco has released patches to address these issues. http://www.cisco.com/warp/public/707/cisco-sa-20100127-mp.shtml http://secunia.com/advisories/38259/ The open source library YaSSL was found to have a security vulnerability related to the negotiation of SSL certificates. [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco disclosed multiple vulnerabilities in their Unified MeetingPlace product. These issues leave the product vulnerable to SQL injection attacks and could allow attackers to bypass authentication. Cisco has released patches to address these issues.<br />
<a href="http://www.cisco.com/warp/public/707/cisco-sa-20100127-mp.shtml " target="_blank">http://www.cisco.com/warp/public/707/cisco-sa-20100127-mp.shtml </a><br />
<a href="http://secunia.com/advisories/38259/" target="_blank">http://secunia.com/advisories/38259/</a></p>
<p>The open source library YaSSL was found to have a security vulnerability related to the negotiation of SSL certificates. The possibility of a buffer overflow exists under these conditions. There has been a patch released to address this vulnerability.<br />
<a href="http://secunia.com/advisories/38344/" target="_blank">http://secunia.com/advisories/38344/</a><br />
<a href="http://osvdb.org/show/osvdb/61956" target="_blank">http://osvdb.org/show/osvdb/61956</a><br />
<a href="http://yassl.com/news.html#yassl199 " target="_blank">http://yassl.com/news.html#yassl199 </a></p>
<p>A overflow vulnerability was found in the 1.3.xx Apache open source web server. This issue leaves the server open to remote unauthenticated access and denial of service attacks. Upgrading to version 1.3.42 resolves this issue.<br />
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0589.html " target="_blank">http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0589.html </a><br />
<a href="http://secunia.com/advisories/38319/2/ " target="_blank">http://secunia.com/advisories/38319/2/ </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.informationarmor.com/2010/01/29/vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
