<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="https://oss-security.openwall.org/wiki/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://oss-security.openwall.org/wiki/feed.php">
        <title>OSS-Security</title>
        <description></description>
        <link>https://oss-security.openwall.org/wiki/</link>
        <image rdf:resource="https://oss-security.openwall.org/wiki/lib/tpl/local/images/favicon.ico" />
       <dc:date>2026-05-19T06:44:35+02:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/about?rev=1211509210&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/code-reviews?rev=1289251721&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/development-guide?rev=1763187956&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/disclosure?rev=1382570917&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/distro-patches?rev=1562935543&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/exploit-mitigation?rev=1451737336&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/infrastructure?rev=1211910862&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/links?rev=1763188318&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/mailing-lists?rev=1691579083&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/mailinglists?rev=1211510187&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/software?rev=1743529256&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/tools?rev=1773410965&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/vendors?rev=1744252593&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/welcome?rev=1536326729&amp;do=diff"/>
                <rdf:li rdf:resource="https://oss-security.openwall.org/wiki/whattodo?rev=1382571011&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://oss-security.openwall.org/wiki/lib/tpl/local/images/favicon.ico">
        <title>OSS-Security</title>
        <link>https://oss-security.openwall.org/wiki/</link>
        <url>https://oss-security.openwall.org/wiki/lib/tpl/local/images/favicon.ico</url>
    </image>
    <item rdf:about="https://oss-security.openwall.org/wiki/about?rev=1211509210&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-05-23T04:20:10+02:00</dc:date>
        <title>about</title>
        <link>https://oss-security.openwall.org/wiki/about?rev=1211509210&amp;do=diff</link>
        <description>The Open Source Security (oss-security) wiki and mailing list are a product of co-operation amongst various open source software vendors, projects, and researchers. The purpose of the oss-security group is to encourage public discussion of security flaws, concepts, and practices in the Open Source community.</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/code-reviews?rev=1289251721&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2010-11-08T22:28:41+02:00</dc:date>
        <title>code-reviews</title>
        <link>https://oss-security.openwall.org/wiki/code-reviews?rev=1289251721&amp;do=diff</link>
        <description>This page will hopefully soon consist of many code review reports with
proper description of project/version/architecture/possible flaws and
security relevant patches.

As a start, I will add some packages which are common across a lot of Linux distributions
and have been identified as a potential risk since they either run privileged or
with network input.
Feel free to add other OS's or move to another, separate, page. The intention is NOT to enumerate
all possibly problematic packages such as …</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/development-guide?rev=1763187956&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-11-15T07:25:56+02:00</dc:date>
        <title>development-guide</title>
        <link>https://oss-security.openwall.org/wiki/development-guide?rev=1763187956&amp;do=diff</link>
        <description>Introduction

Welcome to the Secure OSS Development Guide.  The goal of this wiki is to provide a list of best practices that are recommended for securely developing an open source project.

Note: This development guide is currently a work in progress.  At this point the guide should not be considered complete, and current content will not necessarily be included in the final draft.</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/disclosure?rev=1382570917&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2013-10-24T01:28:37+02:00</dc:date>
        <title>disclosure</title>
        <link>https://oss-security.openwall.org/wiki/disclosure?rev=1382570917&amp;do=diff</link>
        <description>Flaw Disclosure

Anytime an individual discovers a security flaw, there are certain steps that should be taken to ensure that the details of the flaw are disclosed in a responsible and acceptable manner.  Reporting a flaw in open source software poses a number of unique challenges compared to the closed source counterparts.</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/distro-patches?rev=1562935543&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2019-07-12T14:45:43+02:00</dc:date>
        <title>distro-patches</title>
        <link>https://oss-security.openwall.org/wiki/distro-patches?rev=1562935543&amp;do=diff</link>
        <description>This page lists how to find and extract patches from various open source-providing vendors, such as distributors of Linux, *BSD, and other related operating systems.  See the general Vendor information page for details on where to find security announcements.</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/exploit-mitigation?rev=1451737336&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2016-01-02T13:22:16+02:00</dc:date>
        <title>exploit-mitigation</title>
        <link>https://oss-security.openwall.org/wiki/exploit-mitigation?rev=1451737336&amp;do=diff</link>
        <description>There are a number of exploit mitigation techniques to reduce the impact of common C vulnerabilities. Unfortunately they are not as widely used as they should in free operating systems.

For ASLR to work properly Linux needs position independent code and position independent executables (CFLAGS -fpic and -pie). Currently most Linux distributions don't enable pie by default.</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/infrastructure?rev=1211910862&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-05-27T19:54:22+02:00</dc:date>
        <title>infrastructure</title>
        <link>https://oss-security.openwall.org/wiki/infrastructure?rev=1211910862&amp;do=diff</link>
        <description>This page lists security contacts, status links, etc. for various open source-providing infrastructure folks.

When adding to this page, please include the following vendor information:

	*  email address for the security contact
	*  link to FAQ
	*  link to network/service status information (i.e. scheduled down-times)
	*  link to issue tracker (i.e. Bugzilla)</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/links?rev=1763188318&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-11-15T07:31:58+02:00</dc:date>
        <title>links</title>
        <link>https://oss-security.openwall.org/wiki/links?rev=1763188318&amp;do=diff</link>
        <description>Here is a list of other websites with OSS-security-related information (be it articles, tutorials, general information, etc.)

Vulnerability databases and security advisory archives

	*  &lt;http://cve.mitre.org&gt; - MITRE's CVE (Common Vulnerabilities and Exposures) dictionary
	*  &lt;http://nvd.nist.gov&gt; - NIST's NVD (National Vulnerability Database)
	*  &lt;http://osvdb.org&gt; - OSVDB (The Open Source Vulnerability Database)
	*  &lt;http://www.linuxsecurity.com/content/section/3/170/&gt; - LinuxSecurity.com adv…</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/mailing-lists?rev=1691579083&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-08-09T13:04:43+02:00</dc:date>
        <title>mailing-lists</title>
        <link>https://oss-security.openwall.org/wiki/mailing-lists?rev=1691579083&amp;do=diff</link>
        <description>This page provides links to a number of security-related mailing list resources.

Public Lists

	*  &lt;oss-security@lists.openwall.com&gt;: The open source software security mailing list (oss-security), which is a counter-part to this wiki.  This is a public mailing list for anyone to subscribe to.  Non-members may post to the list, however their messages will be moderated before release.  This list is an open list for open source software authors and vendors to discuss public security issues.
		*  o…</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/mailinglists?rev=1211510187&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-05-23T04:36:27+02:00</dc:date>
        <title>mailinglists</title>
        <link>https://oss-security.openwall.org/wiki/mailinglists?rev=1211510187&amp;do=diff</link>
        <description>This page has moved.</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/software?rev=1743529256&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-04-01T19:40:56+02:00</dc:date>
        <title>software</title>
        <link>https://oss-security.openwall.org/wiki/software?rev=1743529256&amp;do=diff</link>
        <description>This is a list of various open source software projects with links to security contacts for the project.  Please only list those projects that do have a security contact to list!  The contact may be an email address or a web page with more information.</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/tools?rev=1773410965&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-03-13T15:09:25+02:00</dc:date>
        <title>tools</title>
        <link>https://oss-security.openwall.org/wiki/tools?rev=1773410965&amp;do=diff</link>
        <description>This page will give you some hints about various tools that might be used
to uncover security vulnerabilities and perform code reviews.

Please note that the tools listed here have been recommended by various individuals who participate in the oss-security mailing list and there are no guarantees, so please take time to carefully evaluate any tools that you use.</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/vendors?rev=1744252593&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-04-10T04:36:33+02:00</dc:date>
        <title>vendors</title>
        <link>https://oss-security.openwall.org/wiki/vendors?rev=1744252593&amp;do=diff</link>
        <description>This page lists security contacts, bug tracker links, links to advisories, etc. for various open source-providing vendors, such as distributors of Linux, *BSD, and other related operating systems.

When adding to this page, please include the following vendor information:</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/welcome?rev=1536326729&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2018-09-07T15:25:29+02:00</dc:date>
        <title>welcome</title>
        <link>https://oss-security.openwall.org/wiki/welcome?rev=1536326729&amp;do=diff</link>
        <description>Welcome to the Open Source Software Security Wiki.  This wiki provides information on a variety of open source security resources and “best practices” information.  It is also the counterpart to the oss-security mailing list.  Please note that registration on this wiki is distinct from mailing list subscription; you're not automatically subscribed when you register on the wiki.</description>
    </item>
    <item rdf:about="https://oss-security.openwall.org/wiki/whattodo?rev=1382571011&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2013-10-24T01:30:11+02:00</dc:date>
        <title>whattodo</title>
        <link>https://oss-security.openwall.org/wiki/whattodo?rev=1382571011&amp;do=diff</link>
        <description>See also: disclosure

This page is designed to teach folks who may not be familiar with security what the generally accepted procedures are, and why they exist.

When a user or security researcher submits a bug to a maintainer of an open-source project, there are a number of factors that determine the proper course of action.  The most basic is who is known to consume the software.  If all your users obtain the code directly from your site, do not modify it, and are not known to redistribute it,…</description>
    </item>
</rdf:RDF>
