<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Exploit This</title>
	<atom:link href="http://www.exploitthis.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.exploitthis.com</link>
	<description>The latest in security news, current exploits and vulnerabilities.</description>
	<lastBuildDate>Sat, 25 May 2013 20:16:06 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Reports: Liberty Reserve Founder Arrested, Site Shuttered</title>
		<link>http://www.exploitthis.com/2013/05/reports-liberty-reserve-founder-arrested-site-shuttered.html</link>
		<comments>http://www.exploitthis.com/2013/05/reports-liberty-reserve-founder-arrested-site-shuttered.html#comments</comments>
		<pubDate>Sat, 25 May 2013 20:16:06 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=20723</guid>
		<description><![CDATA[The founder of Liberty Reserve, a digital currency that has evolved as perhaps the most popular form of payment in the cybercrime underground, was reportedly arrested in Spain this week on suspicion of money laundering. News of the law enforcement action may help explain an ongoing three-day outage at libertyreserve.com: On Friday, the domain registration records for that site and for several other digital currency exchanges began pointing to Shadowserver.org, a volunteer organization dedicated to combating global computer crime.]]></description>
				<content:encoded><![CDATA[<p>The founder of <strong>Liberty Reserve</strong>, a digital currency that has evolved as perhaps the most popular form of payment in the cybercrime underground, was reportedly arrested in Spain this week on suspicion of money laundering. News of the law enforcement action may help explain an ongoing three-day outage at <strong>libertyreserve.com</strong>: On Friday, the domain registration records for that site and for several other digital currency exchanges began pointing to <strong>Shadowserver.org</strong>, a volunteer organization dedicated to combating global computer crime.</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2013/05/lricon.png"><img class="alignright size-medium wp-image-20733" alt="lricon" src="http://krebsonsecurity.com/wp-content/uploads/2013/05/lricon-285x95.png" width="285" height="95" /></a>According to separate reports in <a title="http://www.ticotimes.net/More-news/News-Briefs/Costa-Rican-arrested-in-Spain-for-alleged-financial-crimes_Friday-May-24-2013" href="http://www.ticotimes.net/More-news/News-Briefs/Costa-Rican-arrested-in-Spain-for-alleged-financial-crimes_Friday-May-24-2013" ><em>The Tico Times</em></a> and <a title="http://translate.google.com/translate?act=url&amp;depth=1&amp;hl=en&amp;ie=UTF8&amp;prev=_t&amp;rurl=translate.google.com&amp;sl=auto&amp;tl=en&amp;u=http://www.nacion.com/(F(ETT6Nwk_uE5acfPC7kWHCvXAFy_kLwAmniwWw5asi9Z88AlwF-EjZOnOy15_X0vRcDZEgNDiLr4C0voktA66CBOODIt0f7tltSIG5OaapkvtXcvR8qoZFLUYgYNrCHNgkRT1FWW2zxCtiKsR5umAc3dfX850RPSnWExTbyqV3ki1Iyo_a-zQ0mIBR89NPsXxKyaK_Q2))/2013-05-25/Sucesos/espana-captura-a-costarricense-por-lavado-de-dinero-a-pedido-de-estados-unidos.aspx" href="http://translate.google.com/translate?act=url&amp;depth=1&amp;hl=en&amp;ie=UTF8&amp;prev=_t&amp;rurl=translate.google.com&amp;sl=auto&amp;tl=en&amp;u=http://www.nacion.com/(F(ETT6Nwk_uE5acfPC7kWHCvXAFy_kLwAmniwWw5asi9Z88AlwF-EjZOnOy15_X0vRcDZEgNDiLr4C0voktA66CBOODIt0f7tltSIG5OaapkvtXcvR8qoZFLUYgYNrCHNgkRT1FWW2zxCtiKsR5umAc3dfX850RPSnWExTbyqV3ki1Iyo_a-zQ0mIBR89NPsXxKyaK_Q2))/2013-05-25/Sucesos/espana-captura-a-costarricense-por-lavado-de-dinero-a-pedido-de-estados-unidos.aspx" ><em>La Nacion</em></a>, two Costa Rican daily newspapers, police in Spain arrested <strong>Arthur Budovsky Belanchuk</strong>, 39, as part of a money laundering investigation jointly run by authorities in New York and Costa Rica.</p>
<p>The papers cited Costa Rican prosecutor <strong>José Pablo González</strong> saying that Budovsky, a Costa Rican citizen of Ukrainian origin, has been under investigation since 2011 for money laundering using Liberty Reserve, a company he created in Costa Rica. &#8220;Local investigations began after a request from a prosecutor’s office in New York,&#8221; Tico Times reporter L. Arias wrote. &#8220;On Friday, San José prosecutors conducted raids in Budovsky&#8217;s house and offices in Escazá, Santa Ana, southwest of San José, and in the province of Heredia, north of the capital. Budovsky&#8217;s businesses in Costa Rica apparently were financed by using money from child pornography websites and drug trafficking.&#8221;</p>
<p>For those Spanish-speaking readers out there, Gonzalez can be seen announcing the raids in a news conference documented in <a title="https://www.youtube.com/watch?v=UH1ryOM-iyk" href="https://www.youtube.com/watch?v=UH1ryOM-iyk" >this youtube.com video</a> (the subtitles option for English do a decent job of translation as well).</p>
<p>Liberty Reserve is a largely unregulated money transfer business that allows customers to open accounts using little more than a valid email address, and this relative anonymity has attracted a huge number of customers from underground economies, particularly cybercrime.</p>
<div id="attachment_20728" class="wp-caption alignleft" style="width: 295px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2013/05/lost50k.png"><img class="size-medium wp-image-20728" alt="In a now 10-page thread on this crime forum, many members are facing steep losses." src="http://krebsonsecurity.com/wp-content/uploads/2013/05/lost50k-285x181.png" width="285" height="181" /></a><p class="wp-caption-text">In a now 10-page thread on this crime forum, many members are facing steep losses.</p></div>
<p>The trouble started on Thursday, when libertyreserve.com inexplicably went offline. The outage set off increasingly anxious discussions on several major cybercrime forums online, as many that work and ply their trade in malicious software and banking fraud found themselves unable to access their funds. For example, a bulletproof hosting provider on Darkode.com known as &#8220;off-sho.re&#8221; (a hacker <a title="http://krebsonsecurity.com/2013/05/conversations-with-a-bulletproof-hoster/" href="http://krebsonsecurity.com/2013/05/conversations-with-a-bulletproof-hoster/" >profiled in this blog last week</a>) said he stood to lose $25,000, and that the Liberty Reserve shutdown &#8220;could be the most massive ownage in the history of e-currency.&#8221;</p>
<p>That concern turned to dread for some after it became apparent that this was no ordinary outage. On Friday, the domain name servers for Libertyreserve.com were changed and pointed to <strong>ns1.sinkhole.shadowserver.org</strong> and <strong>ns2.sinkhole.shadowserver.org</strong>. Shadowserver is an all-volunteer nonprofit organization that works to help Internet service providers and hosting firms <a title="http://www.washingtonpost.com/wp-dyn/content/article/2006/03/21/AR2006032100279.html" href="http://www.washingtonpost.com/wp-dyn/content/article/2006/03/21/AR2006032100279.html" >eradicate malware infections and botnets located on their servers</a>.</p>
<p>In computer security lexicon, a <a title="http://en.wikipedia.org/wiki/DNS_Sinkhole" href="http://en.wikipedia.org/wiki/DNS_Sinkhole" >sinkhole</a> is basically a way of redirecting malicious Internet traffic so that it can be captured and analyzed by experts and/or law enforcement officials. In its <a title="http://krebsonsecurity.com/2011/04/u-s-government-takes-down-coreflood-botnet/" href="http://krebsonsecurity.com/2011/04/u-s-government-takes-down-coreflood-botnet/" >2011 takedown of the Coreflood botnet</a>, for example, the U.S. Justice Department relied on sinkholes maintained by the nonprofit <strong>Internet Systems Consortium (ISC)</strong>. Sinkholes are most often used to seize control of botnets, by interrupting the DNS names the botnet is programmed to use. Ironically, as of this writing Shadowserver.org is not resolving, possibly because the Web site is under a botnet attack (hackers from <a title="http://krebsonsecurity.com/wp-content/uploads/2013/05/hf-lr.png" href="http://krebsonsecurity.com/wp-content/uploads/2013/05/hf-lr.png" >at least one forum</a> threatened to attack Shadowserver.org in retaliation for losing access to their funds).</p>
<p>Reached via Twitter, a representative from Shadowserver declined to comment on the outage or about Liberty Reserve, saying &#8220;We are not able to provide public comment at this time.&#8221; I could find no official statement from the U.S. Justice Department on this matter either.</p>
<p>Libertyreserve.com is not the only virtual currency exchange that has been redirected to Shadowserver&#8217;s DNS servers. According to passive DNS data collected by the ISC, at least five digital currency exchanges &#8211;<a href="http://milenia-finance.com/">milenia-finance<wbr />.com</a>, <a href="http://asianagold.com/">asianagold.com</a>, <a href="http://exchangezone.com/">exchangezone.co<wbr />m</a>, <a href="http://moneycentralmarket.com/">moneycentralmar<wbr />ket.com</a> and <a href="http://swiftexchanger.com/">swiftexchanger.<wbr />com</a> &#8211; also went offline this week, their DNS records changed to the same sinkhole entries at shadowserver.org.</p>
<p><span id="more-20723"></span></p>
<p>Assuming the reports at The Tico Times and El Nacion are accurate, this would not be the first time Mr. Budovsky has attracted attention from authorities for money laundering. According to the Justice Department, on July 27, 2006, Arthur Budovsky and a man named Vladimir Kats were indicted by the state of New York on charges of operating an illegal money transmittal business, GoldAge Inc., from their Brooklyn apartments. From <a title="http://www.justice.gov/archive/ndic/pubs28/28675/sub.htm" href="http://www.justice.gov/archive/ndic/pubs28/28675/sub.htm" >a Justice Department account of that case</a>:</p>
<p>&#8220;The defendants had transmitted at least $30 million to digital currency accounts worldwide since beginning operations in 2002. The digital currency exchanger, GoldAge, received and transmitted $4 million between January 1, 2006, and June 30, 2006, as part of the money laundering scheme. Customers opened online GoldAge accounts with limited documentation of identity, then GoldAge purchased digital gold currency through those accounts; the defendants&#8217; fees sometimes exceeded $100,000. Customers could choose their method of payment to GoldAge: wire remittances, cash deposits, postal money orders, or checks. Finally, the customers could withdraw the money by requesting wire transfers to accounts anywhere in the world or by having checks sent to any identified individual.&#8221;</p>
<p>From the U.S. government&#8217;s description, Liberty Reserve sounds virtually indistinguishable from GoldAge, except for having been based in Costa Rica. If Liberty Reseve stays offline, this could cause a major upheaval in the cybercrime economy. I will be following this case closely, and would expect to hear more about this apparently coordinated takedown following the Memorial Day holiday in the U.S. on Monday.</p>
<p>For now, however, many in the underground would rather believe almost any other explanation than a law enforcement takedown. The administrator of cybercrime forum <strong>Carder.pro</strong>, for example, has been telling forum members that the entire incident is the work of professional hackers working for Liberty Reserve&#8217;s competitors.</p>
<div id="attachment_20751" class="wp-caption aligncenter" style="width: 610px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2013/05/lr-ninja.png"><img class="size-large wp-image-20751" alt="Carder.pro administrator &quot;Ninja&quot; isn't buying the news being reported by Costa Rican media." src="http://krebsonsecurity.com/wp-content/uploads/2013/05/lr-ninja-600x229.png" width="600" height="229" /></a><p class="wp-caption-text">Carder.pro administrator &#8220;Ninja&#8221; isn&#8217;t buying the news being reported by Costa Rican media.</p></div>
<img src="http://feeds.feedburner.com/~r/KrebsOnSecurity/~4/z6S4ebLqHYA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/reports-liberty-reserve-founder-arrested-site-shuttered.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
		<item>
		<title>Skype Beta Plugs IP Resolver Privacy Leak</title>
		<link>http://www.exploitthis.com/2013/05/skype-beta-plugs-ip-resolver-privacy-leak.html</link>
		<comments>http://www.exploitthis.com/2013/05/skype-beta-plugs-ip-resolver-privacy-leak.html#comments</comments>
		<pubDate>Fri, 24 May 2013 21:01:25 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=20707</guid>
		<description><![CDATA[A few months ago, I warned readers that a glaring privacy weakness in voice-over-IP telephony service Skype allows anyone using the network to quickly learn the Internet address of any other Skype user. A new beta version of the popular Microsoft program appears to have nixed that privacy leak with a setting that restricts this capability to connections in your Skype contacts only.]]></description>
				<content:encoded><![CDATA[<p>A few months ago, I warned readers that <a title="http://krebsonsecurity.com/2013/03/privacy-101-skype-leaks-your-location/" href="http://krebsonsecurity.com/2013/03/privacy-101-skype-leaks-your-location/" >a glaring privacy weakness</a> in voice-over-IP telephony service <strong>Skype</strong> allows anyone using the network to quickly learn the Internet address of any other Skype user. A new beta version of the popular Microsoft program appears to have nixed that privacy leak with a setting that restricts this capability to connections in your Skype contacts only.</p>
<div id="attachment_20716" class="wp-caption alignright" style="width: 295px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2013/05/skypesavebeta.png"><img class="size-medium wp-image-20716" alt="A new privacy feature in Skype Beta 6.5 for Windows and Mac 6.4" src="http://krebsonsecurity.com/wp-content/uploads/2013/05/skypesavebeta-285x230.png" width="285" height="230" /></a><p class="wp-caption-text">A new privacy feature in Skype Beta 6.5 for Windows and Mac 6.4</p></div>
<p>As I wrote on March 21, 2013,  number of services have emerged to help snoops and ne’er-do-wells exploit this vulnerability to track and harass others online. For example, an online search for “skype resolver” returns dozens of results that point to services (of variable reliability) that allow users to look up the Internet address of any Skype user, just by supplying the target’s Skype account name.</p>
<p>The resolvers can look up the IP address of any Skype user &#8212; whether or not that user is in your contacts list or even online at the time of the lookup. What&#8217;s more, resolver services frequently are offered in tandem with &#8220;booter&#8221; or &#8220;stresser&#8221; services, essentially sites that will launch denial-of-service attacks against a target of your choosing.</p>
<p>Apparently in response to this problem, Microsoft has added a new option to its <a title="http://blogs.skype.com/2013/04/30/skype-video-messaging-preview-for-windows-desktop-users/" href="http://blogs.skype.com/2013/04/30/skype-video-messaging-preview-for-windows-desktop-users/" >Skype 6.5 Beta</a>, released April 30, that allows users to allow direct connections to your contacts only. The information tab on this option, found under Skype-&gt;Options-&gt;Connection, says &#8220;When you call someone who isn&#8217;t a contact, we&#8217;ll keep your IP address hidden.&#8221;</p>
<p><span id="more-20707"></span></p>
<p>I pinged Microsoft for an answer as to whether this feature was designed to plug the privacy leak exposed by resolver services. The company declined to say specifically what it may have changed about the Skype network and/or its software to address this problem, but it attributed the following emailed statement to a &#8220;Skype spokesperson;&#8221;</p>
<p>&#8220;Skype for Windows Beta 6.5 and Mac 6.4 now offer the option to prevent people not on your contact list from viewing your IP address. With this beta program, only your contacts will be able to access this information. We are allowing users to test this new security function and welcome any feedback as we continue to improve the communication experiences on Skype.&#8221;</p>
<p>I tested this beta version of Skype against <a title="http://skypegrab.com/?voteno" href="http://skypegrab.com/?voteno" >a free Skype resolver service</a> that has been reliable in the past at looking up IP addresses tied to specific Skype accounts. When I ran it against my everyday account using and older version of Skype, it successfully found my home IP. When I created a new Skype account with the Skype 6.5 beta on a separate machine, enabled the privacy feature and then tried the lookup again, it failed to locate my IP.</p>
<p>I should note that some Skype resolvers will cache previous lookups. That means if your Skype username has previously been looked up at a Skype resolver service, that service may show the correct IP for your Skype username if your IP address hasn&#8217;t changed since the last lookup.</p>
<img src="http://feeds.feedburner.com/~r/KrebsOnSecurity/~4/w_SF-zOKvMM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/skype-beta-plugs-ip-resolver-privacy-leak.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
		<item>
		<title>USN-1834-1: Linux kernel (Quantal HWE) vulnerabilities</title>
		<link>http://www.exploitthis.com/2013/05/usn-1834-1-linux-kernel-quantal-hwe-vulnerabilities.html</link>
		<comments>http://www.exploitthis.com/2013/05/usn-1834-1-linux-kernel-quantal-hwe-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 24 May 2013 10:45:07 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Ubuntu Security Advisories]]></category>

		<guid isPermaLink="false">http://www.ubuntu.com/usn/usn-1834-1/</guid>
		<description><![CDATA[<h2>Ubuntu Security Notice USN-1834-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux-lts-quantal vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul><li>Ubuntu 12.04 LTS</li>

</ul><h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul><li>linux-lts-quantal 
    - Linux hardware enablement kernel from Quantal
    
    </li>
  

</ul><h3>Details</h3>
<p>A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet<br />driver for the Linux kernel. A local user could exploit this flaw to cause<br />a denial of service (crash the system) or potentially escalate privileges<br />on the system. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>)</p>

<p>A flaw was discovered in the Linux kernel's ftrace subsystem interface. A<br />local user could exploit this flaw to cause a denial of service (system<br />crash). (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl><dt>Ubuntu 12.04 LTS:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux-lts-quantal">linux-image-3.5.0-31-generic</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-31.52~precise1">3.5.0-31.52~precise1</a>
    </span>
  </dd>
    
  

</dl><p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>
        

</p>]]></description>
				<content:encoded><![CDATA[

<h2>Ubuntu Security Notice USN-1834-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux-lts-quantal vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul>

    <li>Ubuntu 12.04 LTS</li>

</ul>


<h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul>

  
    <li>linux-lts-quantal 
    - Linux hardware enablement kernel from Quantal
    
    </li>
  

</ul>


<h3>Details</h3>
<p>A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet<br />driver for the Linux kernel. A local user could exploit this flaw to cause<br />a denial of service (crash the system) or potentially escalate privileges<br />on the system. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>)</p>

<p>A flaw was discovered in the Linux kernel&#39;s ftrace subsystem interface. A<br />local user could exploit this flaw to cause a denial of service (system<br />crash). (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl>

<dt>Ubuntu 12.04 LTS:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux-lts-quantal">linux-image-3.5.0-31-generic</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-31.52~precise1">3.5.0-31.52~precise1</a>
    </span>
  </dd>
    
  

</dl>
<p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>
        

</p>





]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/usn-1834-1-linux-kernel-quantal-hwe-vulnerabilities.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
		<item>
		<title>USN-1835-1: Linux kernel vulnerabilities</title>
		<link>http://www.exploitthis.com/2013/05/usn-1835-1-linux-kernel-vulnerabilities.html</link>
		<comments>http://www.exploitthis.com/2013/05/usn-1835-1-linux-kernel-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 24 May 2013 10:45:07 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Ubuntu Security Advisories]]></category>

		<guid isPermaLink="false">http://www.ubuntu.com/usn/usn-1835-1/</guid>
		<description><![CDATA[<h2>Ubuntu Security Notice USN-1835-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul><li>Ubuntu 12.10</li>

</ul><h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul><li>linux 
    - Linux kernel
    
    </li>
  

</ul><h3>Details</h3>
<p>A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet<br />driver for the Linux kernel. A local user could exploit this flaw to cause<br />a denial of service (crash the system) or potentially escalate privileges<br />on the system. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>)</p>

<p>A flaw was discovered in the Linux kernel's ftrace subsystem interface. A<br />local user could exploit this flaw to cause a denial of service (system<br />crash). (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl><dt>Ubuntu 12.10:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-generic</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-powerpc-smp</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-highbank</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-powerpc64-smp</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-omap</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  

</dl><p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>
        

</p>]]></description>
				<content:encoded><![CDATA[

<h2>Ubuntu Security Notice USN-1835-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul>

    <li>Ubuntu 12.10</li>

</ul>


<h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul>

  
    <li>linux 
    - Linux kernel
    
    </li>
  

</ul>


<h3>Details</h3>
<p>A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet<br />driver for the Linux kernel. A local user could exploit this flaw to cause<br />a denial of service (crash the system) or potentially escalate privileges<br />on the system. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>)</p>

<p>A flaw was discovered in the Linux kernel&#39;s ftrace subsystem interface. A<br />local user could exploit this flaw to cause a denial of service (system<br />crash). (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl>

<dt>Ubuntu 12.10:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-generic</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-powerpc-smp</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-highbank</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-powerpc64-smp</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.5.0-31-omap</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.5.0-31.52">3.5.0-31.52</a>
    </span>
  </dd>
    
  

</dl>
<p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>
        

</p>





]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/usn-1835-1-linux-kernel-vulnerabilities.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
		<item>
		<title>USN-1836-1: Linux kernel (OMAP4) vulnerabilities</title>
		<link>http://www.exploitthis.com/2013/05/usn-1836-1-linux-kernel-omap4-vulnerabilities.html</link>
		<comments>http://www.exploitthis.com/2013/05/usn-1836-1-linux-kernel-omap4-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 24 May 2013 10:45:07 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Ubuntu Security Advisories]]></category>

		<guid isPermaLink="false">http://www.ubuntu.com/usn/usn-1836-1/</guid>
		<description><![CDATA[<h2>Ubuntu Security Notice USN-1836-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux-ti-omap4 vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul><li>Ubuntu 12.10</li>

</ul><h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul><li>linux-ti-omap4 
    - Linux kernel for OMAP4
    
    </li>
  

</ul><h3>Details</h3>
<p>An flaw was discovered in the Linux kernel's perf_events interface. A local<br />user could exploit this flaw to escalate privileges on the system.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-2094">CVE-2013-2094</a>)</p>

<p>A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet<br />driver for the Linux kernel. A local user could exploit this flaw to cause<br />a denial of service (crash the system) or potentially escalate privileges<br />on the system. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>)</p>

<p>A flaw was discovered in the Linux kernel's ftrace subsystem interface. A<br />local user could exploit this flaw to cause a denial of service (system<br />crash). (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl><dt>Ubuntu 12.10:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux-ti-omap4">linux-image-3.5.0-225-omap4</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-225.36">3.5.0-225.36</a>
    </span>
  </dd>
    
  

</dl><p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-2094">CVE-2013-2094</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>
        

</p>]]></description>
				<content:encoded><![CDATA[

<h2>Ubuntu Security Notice USN-1836-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux-ti-omap4 vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul>

    <li>Ubuntu 12.10</li>

</ul>


<h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul>

  
    <li>linux-ti-omap4 
    - Linux kernel for OMAP4
    
    </li>
  

</ul>


<h3>Details</h3>
<p>An flaw was discovered in the Linux kernel&#39;s perf_events interface. A local<br />user could exploit this flaw to escalate privileges on the system.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-2094">CVE-2013-2094</a>)</p>

<p>A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet<br />driver for the Linux kernel. A local user could exploit this flaw to cause<br />a denial of service (crash the system) or potentially escalate privileges<br />on the system. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>)</p>

<p>A flaw was discovered in the Linux kernel&#39;s ftrace subsystem interface. A<br />local user could exploit this flaw to cause a denial of service (system<br />crash). (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl>

<dt>Ubuntu 12.10:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux-ti-omap4">linux-image-3.5.0-225-omap4</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-225.36">3.5.0-225.36</a>
    </span>
  </dd>
    
  

</dl>
<p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-2094">CVE-2013-2094</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>
        

</p>





]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/usn-1836-1-linux-kernel-omap4-vulnerabilities.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
		<item>
		<title>USN-1837-1: Linux kernel vulnerabilities</title>
		<link>http://www.exploitthis.com/2013/05/usn-1837-1-linux-kernel-vulnerabilities.html</link>
		<comments>http://www.exploitthis.com/2013/05/usn-1837-1-linux-kernel-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 24 May 2013 10:45:05 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Ubuntu Security Advisories]]></category>

		<guid isPermaLink="false">http://www.ubuntu.com/usn/usn-1837-1/</guid>
		<description><![CDATA[<h2>Ubuntu Security Notice USN-1837-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul><li>Ubuntu 13.04</li>

</ul><h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul><li>linux 
    - Linux kernel
    
    </li>
  

</ul><h3>Details</h3>
<p>An information leak was discovered in the Linux kernel's crypto API. A<br />local user could exploit this flaw to examine potentially sensitive<br />information from the kernel's stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3076">CVE-2013-3076</a>)</p>

<p>An information leak was discovered in the Linux kernel's rcvmsg path for<br />ATM (Asynchronous Transfer Mode). A local user could exploit this flaw to<br />examine potentially sensitive information from the kernel's stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3222">CVE-2013-3222</a>)</p>

<p>An information leak was discovered in the Linux kernel's recvmsg path for<br />ax25 address family. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel's stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3223">CVE-2013-3223</a>)</p>

<p>An information leak was discovered in the Linux kernel's recvmsg path for<br />the bluetooth address family. A local user could exploit this flaw to<br />examine potentially sensitive information from the kernel's stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3224">CVE-2013-3224</a>)</p>

<p>An information leak was discovered in the Linux kernel's bluetooth rfcomm<br />protocol support. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel's stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3225">CVE-2013-3225</a>)</p>

<p>An information leak was discovered in the Linux kernel's bluetooth SCO<br />sockets implementation. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel's stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3226">CVE-2013-3226</a>)</p>

<p>An information leak was discovered in the Linux kernel's CAIF protocol<br />implementation. A local user could exploit this flaw to examine potentially<br />sensitive information from the kernel's stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3227">CVE-2013-3227</a>)</p>

<p>An information leak was discovered in the Linux kernel's IRDA (infrared)<br />support subsystem. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel's stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3228">CVE-2013-3228</a>)</p>

<p>An information leak was discovered in the Linux kernel's s390 - z/VM<br />support. A local user could exploit this flaw to examine potentially<br />sensitive information from the kernel's stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3229">CVE-2013-3229</a>)</p>

<p>An information leak was discovered in the Linux kernel's l2tp (Layer Two<br />Tunneling Protocol) implementation. A local user could exploit this flaw to<br />examine potentially sensitive information from the kernel's stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3230">CVE-2013-3230</a>)</p>

<p>An information leak was discovered in the Linux kernel's llc (Logical Link<br />Layer 2) support. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel's stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3231">CVE-2013-3231</a>)</p>

<p>An information leak was discovered in the Linux kernel's nfc (near field<br />communication) support. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel's stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3233">CVE-2013-3233</a>)</p>

<p>An information leak was discovered in the Linux kernel's Rose X.25 protocol<br />layer. A local user could exploit this flaw to examine potentially<br />sensitive information from the kernel's stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3234">CVE-2013-3234</a>)</p>

<p>An information leak was discovered in the Linux kernel's TIPC (Transparent<br />Inter Process Communication) protocol implementation. A local user could<br />exploit this flaw to examine potentially sensitive information from the<br />kernel's stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3235">CVE-2013-3235</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl><dt>Ubuntu 13.04:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.8.0-22-generic</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.8.0-22.33">3.8.0-22.33</a>
    </span>
  </dd>
    
  

</dl><p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3076">CVE-2013-3076</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3222">CVE-2013-3222</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3223">CVE-2013-3223</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3224">CVE-2013-3224</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3225">CVE-2013-3225</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3226">CVE-2013-3226</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3227">CVE-2013-3227</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3228">CVE-2013-3228</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3229">CVE-2013-3229</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3230">CVE-2013-3230</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3231">CVE-2013-3231</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3233">CVE-2013-3233</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3234">CVE-2013-3234</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3235">CVE-2013-3235</a>
        

</p>]]></description>
				<content:encoded><![CDATA[

<h2>Ubuntu Security Notice USN-1837-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul>

    <li>Ubuntu 13.04</li>

</ul>


<h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul>

  
    <li>linux 
    - Linux kernel
    
    </li>
  

</ul>


<h3>Details</h3>
<p>An information leak was discovered in the Linux kernel&#39;s crypto API. A<br />local user could exploit this flaw to examine potentially sensitive<br />information from the kernel&#39;s stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3076">CVE-2013-3076</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s rcvmsg path for<br />ATM (Asynchronous Transfer Mode). A local user could exploit this flaw to<br />examine potentially sensitive information from the kernel&#39;s stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3222">CVE-2013-3222</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s recvmsg path for<br />ax25 address family. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel&#39;s stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3223">CVE-2013-3223</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s recvmsg path for<br />the bluetooth address family. A local user could exploit this flaw to<br />examine potentially sensitive information from the kernel&#39;s stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3224">CVE-2013-3224</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s bluetooth rfcomm<br />protocol support. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel&#39;s stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3225">CVE-2013-3225</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s bluetooth SCO<br />sockets implementation. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel&#39;s stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3226">CVE-2013-3226</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s CAIF protocol<br />implementation. A local user could exploit this flaw to examine potentially<br />sensitive information from the kernel&#39;s stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3227">CVE-2013-3227</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s IRDA (infrared)<br />support subsystem. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel&#39;s stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3228">CVE-2013-3228</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s s390 - z/VM<br />support. A local user could exploit this flaw to examine potentially<br />sensitive information from the kernel&#39;s stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3229">CVE-2013-3229</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s l2tp (Layer Two<br />Tunneling Protocol) implementation. A local user could exploit this flaw to<br />examine potentially sensitive information from the kernel&#39;s stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3230">CVE-2013-3230</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s llc (Logical Link<br />Layer 2) support. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel&#39;s stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3231">CVE-2013-3231</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s nfc (near field<br />communication) support. A local user could exploit this flaw to examine<br />potentially sensitive information from the kernel&#39;s stack memory.<br />(<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3233">CVE-2013-3233</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s Rose X.25 protocol<br />layer. A local user could exploit this flaw to examine potentially<br />sensitive information from the kernel&#39;s stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3234">CVE-2013-3234</a>)</p>

<p>An information leak was discovered in the Linux kernel&#39;s TIPC (Transparent<br />Inter Process Communication) protocol implementation. A local user could<br />exploit this flaw to examine potentially sensitive information from the<br />kernel&#39;s stack memory. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3235">CVE-2013-3235</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl>

<dt>Ubuntu 13.04:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.8.0-22-generic</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.8.0-22.33">3.8.0-22.33</a>
    </span>
  </dd>
    
  

</dl>
<p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3076">CVE-2013-3076</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3222">CVE-2013-3222</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3223">CVE-2013-3223</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3224">CVE-2013-3224</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3225">CVE-2013-3225</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3226">CVE-2013-3226</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3227">CVE-2013-3227</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3228">CVE-2013-3228</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3229">CVE-2013-3229</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3230">CVE-2013-3230</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3231">CVE-2013-3231</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3233">CVE-2013-3233</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3234">CVE-2013-3234</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3235">CVE-2013-3235</a>
        

</p>





]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/usn-1837-1-linux-kernel-vulnerabilities.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
		<item>
		<title>USN-1833-1: Linux kernel vulnerabilities</title>
		<link>http://www.exploitthis.com/2013/05/usn-1833-1-linux-kernel-vulnerabilities.html</link>
		<comments>http://www.exploitthis.com/2013/05/usn-1833-1-linux-kernel-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 24 May 2013 09:45:04 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Ubuntu Security Advisories]]></category>

		<guid isPermaLink="false">http://www.ubuntu.com/usn/usn-1833-1/</guid>
		<description><![CDATA[<h2>Ubuntu Security Notice USN-1833-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul><li>Ubuntu 12.04 LTS</li>

</ul><h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul><li>linux 
    - Linux kernel
    
    </li>
  

</ul><h3>Details</h3>
<p>Andy Lutomirski discover an error in the Linux kernel's credential handling<br />on unix sockets. A local user could exploit this flaw to gain<br />administrative privileges. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1979">CVE-2013-1979</a>)</p>

<p>A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet<br />driver for the Linux kernel. A local user could exploit this flaw to cause<br />a denial of service (crash the system) or potentially escalate privileges<br />on the system. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>)</p>

<p>A flaw was discovered in the Linux kernel's ftrace subsystem interface. A<br />local user could exploit this flaw to cause a denial of service (system<br />crash). (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl><dt>Ubuntu 12.04 LTS:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-highbank</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-omap</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-generic-pae</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-powerpc64-smp</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-virtual</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-generic</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-powerpc-smp</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  

</dl><p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1979">CVE-2013-1979</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>
        

</p>]]></description>
				<content:encoded><![CDATA[

<h2>Ubuntu Security Notice USN-1833-1</h2>
<p><em>24th May, 2013</em></p>
<h3>linux vulnerabilities</h3>
<p>A security issue affects these releases of Ubuntu and its 
    derivatives:</p>
<ul>

    <li>Ubuntu 12.04 LTS</li>

</ul>


<h3>Summary</h3>
<p>Several security issues were fixed in the kernel.
</p>



<h3>Software description</h3>
<ul>

  
    <li>linux 
    - Linux kernel
    
    </li>
  

</ul>


<h3>Details</h3>
<p>Andy Lutomirski discover an error in the Linux kernel&#39;s credential handling<br />on unix sockets. A local user could exploit this flaw to gain<br />administrative privileges. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1979">CVE-2013-1979</a>)</p>

<p>A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet<br />driver for the Linux kernel. A local user could exploit this flaw to cause<br />a denial of service (crash the system) or potentially escalate privileges<br />on the system. (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>)</p>

<p>A flaw was discovered in the Linux kernel&#39;s ftrace subsystem interface. A<br />local user could exploit this flaw to cause a denial of service (system<br />crash). (<a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>)<br /></p>

<h3>Update instructions</h3>
<p> The problem can be corrected by updating your system to the following
package version:</p>
<dl>

<dt>Ubuntu 12.04 LTS:</dt>
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-highbank</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-omap</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-generic-pae</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-powerpc64-smp</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-virtual</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-generic</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  
    
  <dd>
    <a href="https://launchpad.net/ubuntu/+source/linux">linux-image-3.2.0-44-powerpc-smp</a>
    <span>
        <a href="https://launchpad.net/ubuntu/+source/linux/3.2.0-44.69">3.2.0-44.69</a>
    </span>
  </dd>
    
  

</dl>
<p>To update your system, please follow these instructions:
<a href="https://wiki.ubuntu.com/Security/Upgrades">https://wiki.ubuntu.com/Security/Upgrades</a>.
</p>
<p>After a standard system update you need to reboot your computer to make<br />all the necessary changes.</p>

<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br />been given a new version number, which requires you to recompile and<br />reinstall all third party kernel modules you might have installed. If<br />you use linux-restricted-modules, you have to update that package as<br />well to get modules which work with the new kernel version. Unless you<br />manually uninstalled the standard kernel metapackages (e.g. linux-generic,<br />linux-server, linux-powerpc), a standard system upgrade will automatically<br />perform this as well.<br /></p>



<h3>References</h3>
<p>

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1929">CVE-2013-1929</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-1979">CVE-2013-1979</a>, 

        <a href="http://people.ubuntu.com/~ubuntu-security/cve/CVE-2013-3301">CVE-2013-3301</a>
        

</p>





]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/usn-1833-1-linux-kernel-vulnerabilities.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
		<item>
		<title>Microsoft says new Kinect for Windows sensor coming in 2014</title>
		<link>http://www.exploitthis.com/2013/05/microsoft-says-new-kinect-for-windows-sensor-coming-in-2014.html</link>
		<comments>http://www.exploitthis.com/2013/05/microsoft-says-new-kinect-for-windows-sensor-coming-in-2014.html#comments</comments>
		<pubDate>Fri, 24 May 2013 01:25:54 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.exploitthis.com/?guid=f947231927578591485ad2f03ff3785f</guid>
		<description><![CDATA[Microsoft will make available a new Kinect sensor for Windows in 2014, officials said on May 23.
The new Kinect for Windows sensor will include many of the technologies that Microsoft showed off in the Kinect for Xbox One product earlier this week. Mic...]]></description>
				<content:encoded><![CDATA[<div class="field field-name-field-image field-type-image field-label-hidden"><div class="field-items"><div class="field-item even" rel="og:image rdfs:seeAlso" resource="http://news.hitb.org/sites/default/files/styles/medium/public/field/image/newkinectwindows-200x111.png?itok=T4F9D47d"><a href="http://news.hitb.org/content/microsoft-says-new-kinect-windows-sensor-coming-2014"><img typeof="foaf:Image" src="http://news.hitb.org/sites/default/files/styles/medium/public/field/image/newkinectwindows-200x111.png?itok=T4F9D47d" width="220" height="122" alt="http://cdn-static.zdnet.com/i/r/story/70/00/015821/newkinectwindows-200x111.png" title="Credit: ZDNet" /></a></div></div></div><div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Microsoft will make available a new Kinect sensor for Windows in 2014, officials said on May 23.</p>
<p>The new Kinect for Windows sensor will include many of the technologies that Microsoft showed off in the Kinect for Xbox One product earlier this week. Microsoft is promising the Kinect for Windows sensor also will include higher fidelity, an expanded field of view, skeletal tracking and new active infrared -- all features of the Kinect for Xbox One.</p></div></div></div><div class="field field-name-field-tags field-type-taxonomy-term-reference field-label-inline clearfix"><div class="field-label">Tags:&nbsp;</div><div class="field-items"><div class="field-item even" rel="dc:subject"><a href="http://news.hitb.org/tags/microsoft" typeof="skos:Concept" property="rdfs:label skos:prefLabel" datatype="">Microsoft</a></div><div class="field-item odd" rel="dc:subject"><a href="http://news.hitb.org/tags/kinect" typeof="skos:Concept" property="rdfs:label skos:prefLabel" datatype="">Kinect</a></div><div class="field-item even" rel="dc:subject"><a href="http://news.hitb.org/tags/hardware" typeof="skos:Concept" property="rdfs:label skos:prefLabel" datatype="">Hardware</a></div></div></div>]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/microsoft-says-new-kinect-for-windows-sensor-coming-in-2014.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
		<item>
		<title>Google Said to Consider Buying Waze Presaging Bidding War</title>
		<link>http://www.exploitthis.com/2013/05/google-said-to-consider-buying-waze-presaging-bidding-war.html</link>
		<comments>http://www.exploitthis.com/2013/05/google-said-to-consider-buying-waze-presaging-bidding-war.html#comments</comments>
		<pubDate>Fri, 24 May 2013 01:22:05 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.exploitthis.com/?guid=cbd064298e454dd35162f8bb5a4aedfe</guid>
		<description><![CDATA[Google Inc. (GOOG), maker of the Android operating system, is considering buying map-software provider Waze Inc., setting up a possible bidding war with Facebook Inc., people familiar with the matter said.
Waze is fielding expressions of interest from ...]]></description>
				<content:encoded><![CDATA[<div class="field field-name-field-image field-type-image field-label-hidden"><div class="field-items"><div class="field-item even" rel="og:image rdfs:seeAlso" resource="http://news.hitb.org/sites/default/files/styles/medium/public/field/image/iMLlRLJKqHng.jpg?itok=_3Z0LzQ7"><a href="http://news.hitb.org/content/google-said-consider-buying-waze-presaging-bidding-war"><img typeof="foaf:Image" src="http://news.hitb.org/sites/default/files/styles/medium/public/field/image/iMLlRLJKqHng.jpg?itok=_3Z0LzQ7" width="220" height="164" alt="http://www.bloomberg.com/image/iMLlRLJKqHng.jpg" title="Credit: Bloomberg" /></a></div></div></div><div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Google Inc. (GOOG), maker of the Android operating system, is considering buying map-software provider Waze Inc., setting up a possible bidding war with Facebook Inc., people familiar with the matter said.</p>
<p>Waze is fielding expressions of interest from multiple parties and is seeking more than $1 billion, said one of the people, who asked not to be identified because the talks are private. The Palo Alto, California-based startup might also remain independent, instead seeking to raise a round of venture capital financing, the people said. </p></div></div></div><div class="field field-name-field-tags field-type-taxonomy-term-reference field-label-inline clearfix"><div class="field-label">Tags:&nbsp;</div><div class="field-items"><div class="field-item even" rel="dc:subject"><a href="http://news.hitb.org/tags/google" typeof="skos:Concept" property="rdfs:label skos:prefLabel" datatype="">Google</a></div><div class="field-item odd" rel="dc:subject"><a href="http://news.hitb.org/tags/waze" typeof="skos:Concept" property="rdfs:label skos:prefLabel" datatype="">Waze</a></div><div class="field-item even" rel="dc:subject"><a href="http://news.hitb.org/tags/industry-news" typeof="skos:Concept" property="rdfs:label skos:prefLabel" datatype="">Industry News</a></div></div></div>]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/google-said-to-consider-buying-waze-presaging-bidding-war.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
		<item>
		<title>FiOS customer discovers the limits of &#8220;unlimited&#8221; data: 77TB a month</title>
		<link>http://www.exploitthis.com/2013/05/fios-customer-discovers-the-limits-of-unlimited-data-77tb-a-month.html</link>
		<comments>http://www.exploitthis.com/2013/05/fios-customer-discovers-the-limits-of-unlimited-data-77tb-a-month.html#comments</comments>
		<pubDate>Fri, 24 May 2013 01:19:06 +0000</pubDate>
		<dc:creator>News Bot</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.exploitthis.com/?guid=8cabbdeabc1e2b00bb49ee595d9008af</guid>
		<description><![CDATA[<div><div><div><a href="http://news.hitb.org/content/fios-customer-discovers-limits-unlimited-data-77tb-month"><img src="http://news.hitb.org/sites/default/files/styles/medium/public/field/image/fullish_rack_2-small.jpg?itok=PjViL4Z4" width="146" height="220" alt="http://cdn.arstechnica.net/wp-content/uploads/2013/05/fullish_rack_2-small.jpg" title="Credit: Arstechnica"></a></div></div></div><div><div><div><p>Yes, Virginia, there is a limit to what Verizon will let you do with FiOS' "unlimited" data plan. And a California man discovered that limit when he got a phone call from a Verizon representative wanting to know what, exactly, he was doing to create more than 50 terabytes of traffic on average per month&#8212;hitting a peak of 77TB in March alone.</p></div></div></div><div><div>Tags:&#160;</div><div><div><a href="http://news.hitb.org/tags/networking">Networking</a></div><div><a href="http://news.hitb.org/tags/fiber">Fiber</a></div><div><a href="http://news.hitb.org/tags/industry-news">Industry News</a></div></div></div>]]></description>
				<content:encoded><![CDATA[<div class="field field-name-field-image field-type-image field-label-hidden"><div class="field-items"><div class="field-item even" rel="og:image rdfs:seeAlso" resource="http://news.hitb.org/sites/default/files/styles/medium/public/field/image/fullish_rack_2-small.jpg?itok=PjViL4Z4"><a href="http://news.hitb.org/content/fios-customer-discovers-limits-unlimited-data-77tb-month"><img typeof="foaf:Image" src="http://news.hitb.org/sites/default/files/styles/medium/public/field/image/fullish_rack_2-small.jpg?itok=PjViL4Z4" width="146" height="220" alt="http://cdn.arstechnica.net/wp-content/uploads/2013/05/fullish_rack_2-small.jpg" title="Credit: Arstechnica" /></a></div></div></div><div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Yes, Virginia, there is a limit to what Verizon will let you do with FiOS' "unlimited" data plan. And a California man discovered that limit when he got a phone call from a Verizon representative wanting to know what, exactly, he was doing to create more than 50 terabytes of traffic on average per month—hitting a peak of 77TB in March alone.</p></div></div></div><div class="field field-name-field-tags field-type-taxonomy-term-reference field-label-inline clearfix"><div class="field-label">Tags:&nbsp;</div><div class="field-items"><div class="field-item even" rel="dc:subject"><a href="http://news.hitb.org/tags/networking" typeof="skos:Concept" property="rdfs:label skos:prefLabel" datatype="">Networking</a></div><div class="field-item odd" rel="dc:subject"><a href="http://news.hitb.org/tags/fiber" typeof="skos:Concept" property="rdfs:label skos:prefLabel" datatype="">Fiber</a></div><div class="field-item even" rel="dc:subject"><a href="http://news.hitb.org/tags/industry-news" typeof="skos:Concept" property="rdfs:label skos:prefLabel" datatype="">Industry News</a></div></div></div>]]></content:encoded>
			<wfw:commentRss>http://www.exploitthis.com/2013/05/fios-customer-discovers-the-limits-of-unlimited-data-77tb-a-month.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="" length="" type="" />
		</item>
	</channel>
</rss>
