<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ESISS</title>
	<atom:link href="http://www.esiss.ac.uk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.esiss.ac.uk</link>
	<description>EMMAN Shared Information Security Service</description>
	<lastBuildDate>Wed, 25 Aug 2010 11:59:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Apple Security Updates &#8211; August 2010</title>
		<link>http://www.esiss.ac.uk/general/apple-security-update-august-2010/</link>
		<comments>http://www.esiss.ac.uk/general/apple-security-update-august-2010/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 11:44:37 +0000</pubDate>
		<dc:creator>mohamedimran</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/?p=1138</guid>
		<description><![CDATA[Apple have released security updates for Mac OSX. A total of eight updates are available that addresses multiple vulnerabilities reported in key areas such as ClamAV, PHP, CFnetwork, libsecurity and Samba.
Products affected are: Mac OS X Server 10.5, Mac OS X 10.5.8 , Mac OS X Server 10.6 , Mac OS X 10.6.4
For further details [...]]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/general/apple-security-update-august-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remote code execution in itunes for windows</title>
		<link>http://www.esiss.ac.uk/microsoft/remote-code-execution-in-itunes-for-windows/</link>
		<comments>http://www.esiss.ac.uk/microsoft/remote-code-execution-in-itunes-for-windows/#comments</comments>
		<pubDate>Wed, 18 Aug 2010 19:24:06 +0000</pubDate>
		<dc:creator>paulwhitton</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/?p=1129</guid>
		<description><![CDATA[A &#8220;binary planting&#8221; vulnerability in Apple iTunes for Windows allows local or remote (even Internet-based) attackers to deploy and execute malicious code on Windows machines in the context of logged-on users.
Further details can be found here
HDMoore (Chief Security Officer at Rapid7) has also hinted that this vulnerability also affects 40+ Windows applications via this message.
]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/microsoft/remote-code-execution-in-itunes-for-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security advisory for vulnerability in Windows service isolation feature</title>
		<link>http://www.esiss.ac.uk/microsoft/security-advisory-for-vulnerability-in-windows-service-isolation-feature/</link>
		<comments>http://www.esiss.ac.uk/microsoft/security-advisory-for-vulnerability-in-windows-service-isolation-feature/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 22:30:06 +0000</pubDate>
		<dc:creator>mohamedimran</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/?p=1118</guid>
		<description><![CDATA[Microsoft have released a security advisory of a potential threat arising from the Windows service isolation feature. This feature enables windows to secure objects such as registry entry used by a service by applying an access control with a unique security ID without having to use a super-administrator account. The current vulnerability in the service [...]]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/microsoft/security-advisory-for-vulnerability-in-windows-service-isolation-feature/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Updates Summary &#8211; August 2010</title>
		<link>http://www.esiss.ac.uk/microsoft/microsoft-security-updates-summary-august-2010/</link>
		<comments>http://www.esiss.ac.uk/microsoft/microsoft-security-updates-summary-august-2010/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 21:13:33 +0000</pubDate>
		<dc:creator>mohamedimran</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/?p=1110</guid>
		<description><![CDATA[A summary of Microsoft&#8217;s security patches released on 10-August-2010.



Bulletin Number
Products Affected
Description
Exploits
Platforms Affected


MS10-047
Windows Kernel
Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege
No Known Exploits
Client - Important
Server &#8211; Important


MS10-048
Windows Kernel
Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege
Active exploits publicly available
Client - Important
Server &#8211; Important


MS10-049
IIS and SChannel
Vulnerabilities in SChannel could allow Remote Code Execution
No Known Exploits
Client [...]]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/microsoft/microsoft-security-updates-summary-august-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Out-of-band Security update for Adobe</title>
		<link>http://www.esiss.ac.uk/general/out-of-band-security-update-for-adobe/</link>
		<comments>http://www.esiss.ac.uk/general/out-of-band-security-update-for-adobe/#comments</comments>
		<pubDate>Mon, 09 Aug 2010 10:57:53 +0000</pubDate>
		<dc:creator>mohamedimran</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/?p=1107</guid>
		<description><![CDATA[Adobe will be releasing an out-of-band security update addressing vulnerabilities reported in Adobe and Adobe reader on W/c 16 August 2010. This also includes update for the recently announced vulnerability in the &#8216;Truetype&#8217; font which could allow remote attackers to execute arbitrary code and affects the above products. Please refer the original post for further [...]]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/general/out-of-band-security-update-for-adobe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple Vulnerabilities reported in Cisco Security Products</title>
		<link>http://www.esiss.ac.uk/cisco/multiple-vulnerabilities-reported-in-cisco-security-products/</link>
		<comments>http://www.esiss.ac.uk/cisco/multiple-vulnerabilities-reported-in-cisco-security-products/#comments</comments>
		<pubDate>Thu, 05 Aug 2010 13:55:43 +0000</pubDate>
		<dc:creator>mohamedimran</dc:creator>
				<category><![CDATA[Cisco]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/?p=1103</guid>
		<description><![CDATA[A range of vulnerabilities have been reported affecting the Cisco ASA 5500 and FWSM (Firewall Services Module). A brief description of these are as follows:
Sun RPC Inspection Denial of Service Vulnerability:
A total of three DoS vulnerabilities exist in the Sun RPC inspection feature of both ASA and FWSM. This could be triggered by specially crafted [...]]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/cisco/multiple-vulnerabilities-reported-in-cisco-security-products/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WPA2 not so secure after all&#8230;</title>
		<link>http://www.esiss.ac.uk/general/wpa2-not-so-secure-after-all/</link>
		<comments>http://www.esiss.ac.uk/general/wpa2-not-so-secure-after-all/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 10:32:58 +0000</pubDate>
		<dc:creator>mohamedimran</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/?p=1093</guid>
		<description><![CDATA[The wireless security protocol WPA2, considered to be the most robust protocol for wireless security may not be so secure after all. Wireless security researchers at AirTight networks have discovered a vulnerability in the 802.11 encryption specifications which could allow an authenticated user to capture traffic over the air and inject malicious traffic onwards in [...]]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/general/wpa2-not-so-secure-after-all/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Widespread Common Flaw Among VxWorks Devices</title>
		<link>http://www.esiss.ac.uk/general/widespread-common-flaw-among-vxworks-devices/</link>
		<comments>http://www.esiss.ac.uk/general/widespread-common-flaw-among-vxworks-devices/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 22:48:45 +0000</pubDate>
		<dc:creator>paulwhitton</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/general/widespread-common-flaw-among-vxworks-devices/</guid>
		<description><![CDATA[Security researcher HD Moore has found how a misconfiguration by developers using the VxWorks operating system could lead to the ability to read and write memory and power cycle the device.
The flaw is found on 100+ vendors products and includes VOIP equipment and switches, DSL concentrators, industrial automation systems for SCADA environments, and Fiber Channel [...]]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/general/widespread-common-flaw-among-vxworks-devices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability in iTunes Podcast URL handler</title>
		<link>http://www.esiss.ac.uk/general/vulnerability-in-itunes-podcast-url-handler/</link>
		<comments>http://www.esiss.ac.uk/general/vulnerability-in-itunes-podcast-url-handler/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 12:49:46 +0000</pubDate>
		<dc:creator>mohamedimran</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/?p=1075</guid>
		<description><![CDATA[A buffer overflow vulnerability has been reported in iTunes in the way it handles URL&#8217;s for podcasts. This can be exploited if a user visits a specially crafted website, triggering a arbitrary code to execute or cause the application to crash.
More information on this can be found on Apple&#8217;s website here.
]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/general/vulnerability-in-itunes-podcast-url-handler/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remote code execution vulnerability in Windows Shell</title>
		<link>http://www.esiss.ac.uk/microsoft/remote-code-execution-vulnerability-in-windows-shell/</link>
		<comments>http://www.esiss.ac.uk/microsoft/remote-code-execution-vulnerability-in-windows-shell/#comments</comments>
		<pubDate>Sat, 17 Jul 2010 17:36:25 +0000</pubDate>
		<dc:creator>mohamedimran</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.esiss.ac.uk/?p=1056</guid>
		<description><![CDATA[Microsoft have released a security advisory addressing a vulnerability in Windows Shell that can be exploited through specially crafted shortcut links. Successful attack allows execution of arbitrary code allowing the attacker to gain user privileges on the compromised machine.
The following risks of the exploit being executed automatically exist:
a) Removable device containing the malicious shortcut link [...]]]></description>
		<wfw:commentRss>http://www.esiss.ac.uk/microsoft/remote-code-execution-vulnerability-in-windows-shell/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
