<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>openSUSE Spotlight &#187; Security</title>
	<atom:link href="http://zonker.opensuse.org/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://zonker.opensuse.org</link>
	<description>Shining a spotlight on the openSUSE Community</description>
	<lastBuildDate>Wed, 09 Dec 2009 19:41:31 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>openSUSE Infrastructure Security</title>
		<link>http://zonker.opensuse.org/2009/03/23/opensuse-infrastructure-security/</link>
		<comments>http://zonker.opensuse.org/2009/03/23/opensuse-infrastructure-security/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 19:02:03 +0000</pubDate>
		<dc:creator>Zonker</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://zonker.opensuse.org/?p=349</guid>
		<description><![CDATA[Another nice shout-out for the openSUSE community here: The USENIX association magazine, ;login, has recognized openSUSE as having the same level of protection against some of the recently discovered package management vulnerabilities as enterprise-class distros. Says Federico Lucifredi:
What&#8217;s more, the openSUSE and SUSE Linux Enterprise distros not only secure packages and package metadata with cryptographic [...]]]></description>
			<content:encoded><![CDATA[<p>Another nice shout-out for the openSUSE community here: The USENIX association magazine, <em>;login</em>, <a href="http://www.novell.com/communities/node/7026/usenix-magazine-research-recognizes-opensuse-infrastructure-security">has recognized openSUSE</a> as having the same level of protection against some of the recently discovered package management vulnerabilities as enterprise-class distros. Says Federico Lucifredi:</p>
<blockquote><p>What&#8217;s more, the openSUSE and SUSE Linux Enterprise distros not only secure packages and package metadata with cryptographic signatures, but have addressed the more exotic attacks described by the paper as well, with the slow-data fix currently in Factory completing the picture. The upshot of this is that users can deploy updates safely whether they&#8217;re obtaining updates from a centralized network or through a decentralized system of community maintained mirrors.</p></blockquote>
<p>The full article is <a href="http://www.usenix.org/publications/login/2009-02/openpdfs/samuel.pdf">available as a PDF</a>. Definitely worth a read!</p>
]]></content:encoded>
			<wfw:commentRss>http://zonker.opensuse.org/2009/03/23/opensuse-infrastructure-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DNS cache poisoning fix</title>
		<link>http://zonker.opensuse.org/2008/07/11/dns-cache-poisoning-fix/</link>
		<comments>http://zonker.opensuse.org/2008/07/11/dns-cache-poisoning-fix/#comments</comments>
		<pubDate>Fri, 11 Jul 2008 14:18:21 +0000</pubDate>
		<dc:creator>Zonker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[bind]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[openSUSE]]></category>
		<category><![CDATA[sle]]></category>
		<category><![CDATA[sled]]></category>
		<category><![CDATA[sles]]></category>

		<guid isPermaLink="false">http://zonker.opensuse.org/?p=164</guid>
		<description><![CDATA[If you&#8217;re running Bind on openSUSE or SUSE Linux Enterprise, you want to install the update that was pushed out recently. This was pushed out on opensuse-security-announce (which I&#8217;m sure everybody is subscribed to, right? Cause these announcements are very infrequent and fairly important&#8230;) but I wanted to mention it here as well&#8230;
In case you [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re running Bind on openSUSE or SUSE Linux Enterprise, you want to <a href="http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00003.html">install the update that was pushed out recently</a>. This was pushed out on opensuse-security-announce (which I&#8217;m sure everybody is <a href="http://en.opensuse.org/Mailing_Lists">subscribed to</a>, right? Cause these announcements are very infrequent and fairly important&#8230;) but I wanted to mention it here as well&#8230;</p>
<p>In case you hadn&#8217;t read about it already, there&#8217;s a <a title="Researcher offers insight into DNS flaw" href="http://news.cnet.com/8301-10789_3-9985815-57.html">major DNS flaw that leaves DNS implementations vulnerable to cache poisoning</a> (essentially giving the wrong IP address for a domain name, which makes it possible to redirect queries to the wrong host &#8212; which opens up a whole slew of possible mischief).</p>
<p>We&#8217;ve issued a fix for openSUSE 10.2, 10.3, and 11.0, as well as SLES/SLED 10, and a <a href="http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00003.html">number of other versions</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://zonker.opensuse.org/2008/07/11/dns-cache-poisoning-fix/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
