<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Albertech.net &#187; security</title>
	<atom:link href="http://albertech.net/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://albertech.net</link>
	<description>Tips, Tricks, and Reviews in Linux, Apache, MySQL, PHP</description>
	<lastBuildDate>Fri, 03 Sep 2010 17:40:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>CodeIgniter 1.7.2 Security Patch</title>
		<link>http://albertech.net/2010/08/codeigniter-1-7-2-patch/</link>
		<comments>http://albertech.net/2010/08/codeigniter-1-7-2-patch/#comments</comments>
		<pubDate>Sat, 14 Aug 2010 06:33:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Frameworks]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[codeigniter]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://albertech.net/?p=440</guid>
		<description><![CDATA[If you are running CodeIgniter 1.7.2, there is a security flaw with the file upload class. (fixed on July 12, 2010)  The easiest way to install the patch is to use the standalone patch <a href="http://codeigniter.com/download_files/CI_1.7.2_201007_sec_patch.zip">http://codeigniter.com/download_files/CI_1.7.2_201007_sec_patch.zip</a> and unzip the file to the Code Igniter system/libraries folder.]]></description>
			<content:encoded><![CDATA[<p>If you are running CodeIgniter 1.7.2, there is a security flaw with the file upload class. (fixed on July 12, 2010)  The easiest way to install the patch is to use the standalone patch <a href="http://codeigniter.com/download_files/CI_1.7.2_201007_sec_patch.zip">http://codeigniter.com/download_files/CI_1.7.2_201007_sec_patch.zip</a> and unzip the file to the Code Igniter system/libraries folder.</p>
]]></content:encoded>
			<wfw:commentRss>http://albertech.net/2010/08/codeigniter-1-7-2-patch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMWARE Server 2.02 Update</title>
		<link>http://albertech.net/2009/11/vmware-server-2-02-update/</link>
		<comments>http://albertech.net/2009/11/vmware-server-2-02-update/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 19:29:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[VMWARE]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vmware server]]></category>

		<guid isPermaLink="false">http://albertech.net/?p=317</guid>
		<description><![CDATA[VMWARE Server 2.02 has been released October 27, 2009. It includes a few important security updates for VMWARE Server. If you are running a Linux server with VMWARE server 2.01, I strongly suggest to upgrade due to the "Directory Traversal Vulnerability" -- which may allow for remote retrieval of any file from the host system.]]></description>
			<content:encoded><![CDATA[<p>VMWARE Server 2.02 has been released October 27, 2009. It includes a few important security updates for VMWARE Server. If you are running a Linux server with VMWARE server 2.01, I strongly suggest to upgrade due to the &#8220;Directory Traversal Vulnerability&#8221; &#8212; which may allow for remote retrieval of any file from the host system.</p>
<h3>Security Fixes with VMWARE 2.02</h3>
<ul><!--DevPR:463465 DocPR:--></p>
<li><span style="color: red;"><strong>New:</strong></span> <strong>Exception handling privilege escalation on Guest Operating System</strong> This release addresses a security vulnerability in exception handling. Improper setting of the exception code on page faults might allow for local privilege escalation on the guest. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2267" target="_blank">CVE-2009-2267</a> to this issue.</li>
<p><!--DevPR:406973 DocPR:--></p>
<li><span style="color: red;"><strong>New:</strong></span> <strong>Directory Traversal Vulnerability on Linux-based hosts</strong> This release addresses a directory traversal vulnerability that is present on host systems and that may allow for remote retrieval of any file from the host system. In order to send a malicious request, the attacker will need to have access to the network on which the host resides. The issue is present on Linux-based hosts only, not on Windows-based hosts. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3733" target="_blank">CVE-2009-3733</a> to this issue.</li>
</ul>
<p>There&#8217;s a number of workarounds listed in the <a href="http://www.vmware.com/support/server2/doc/releasenotes_vmserver202.html" target="_blank">VMWARE Server 2.02 Release notes</a></p>
<p><a href="https://www.vmware.com/tryvmware/?p=server20&amp;lp=1"><strong>Download the latest version of VMware Server 2</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://albertech.net/2009/11/vmware-server-2-02-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.8.2 Released</title>
		<link>http://albertech.net/2009/07/wordpress-2-8-2-released/</link>
		<comments>http://albertech.net/2009/07/wordpress-2-8-2-released/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 17:11:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://albertech.net/?p=220</guid>
		<description><![CDATA[<strong>WordPress 2.8.2 has been released. This affects both WordPress and WordPress MU. I recommend upgrading your current version since it contains a security fix. </strong>
<blockquote>WordPress 2.8.2 fixes an XSS vulnerability. Comment author URLs were not fully sanitized when displayed in the admin. This could be exploited to redirect you away from the admin to another site.</blockquote>
<strong>For more details, visit:</strong>
<a href="http://wordpress.org/development/2009/07/wordpress-2-8-2/" target="_blank">http://wordpress.org/development/2009/07/wordpress-2-8-2/
</a>
You can automatically upgrade WordPress within your control panel, or manually upgrade via:
<a href="http://wordpress.org/download/" target="_blank">http://wordpress.org/download/</a>

WordPress MU download:<a href=" http://mu.wordpress.org/download/" target="_blank">
http://mu.wordpress.org/download/</a>]]></description>
			<content:encoded><![CDATA[<p><strong>WordPress 2.8.2 has been released. This affects both WordPress and WordPress MU. I recommend upgrading your current version since it contains a security fix. </strong></p>
<blockquote><p>WordPress 2.8.2 fixes an XSS vulnerability. Comment author URLs were not fully sanitized when displayed in the admin. This could be exploited to redirect you away from the admin to another site.</p></blockquote>
<p><strong>For more details, visit:</strong><br />
<a href="http://wordpress.org/development/2009/07/wordpress-2-8-2/" target="_blank">http://wordpress.org/development/2009/07/wordpress-2-8-2/<br />
</a><br />
You can automatically upgrade WordPress within your control panel, or manually upgrade via:<br />
<a href="http://wordpress.org/download/" target="_blank">http://wordpress.org/download/</a></p>
<p>WordPress MU download:<a href=" http://mu.wordpress.org/download/" target="_blank"></p>
<p>http://mu.wordpress.org/download/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://albertech.net/2009/07/wordpress-2-8-2-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
