<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="d1ef3186c44b878b7bcdc2247e89d743"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="asterisk-2272"
    timestamp="1163584782"
    engine="1.0">
  <yum:name>asterisk</yum:name>
  <summary lang="en">asterisk: Security update to fix problems in CISCO SCCP and SIP channel driver.</summary>
  <summary lang="de">asterisk: Sicherheitsupdate um Problen in CISCO SCCP und SIP Kanaltreiber zu beheben.</summary>
  <description lang="en">This update fixes 2 security problem in the PBX software
Asterisk.

CVE-2006-5444: Integer overflow in the get_input function
in the Skinny channel driver (chan_skinny.c) as used by
Cisco SCCP phones, allows remote attackers to execute
arbitrary code via a certain dlen value that passes a
signed integer comparison and leads to a heap-based buffer
overflow.

CVE-2006-5445: A vulnerability in the SIP channel driver
(channels/chan_sip.c) in Asterisk on SUSE Linux 10.1 allows
remote attackers to cause a denial of service (resource
consumption) via unspecified vectors that result in the
creation of &quot;a real pvt structure&quot; that uses more resources
than necessary.
</description>
  <description lang="de">Dieses Update behebt 2 Sicherheitsproblem in der PBX
Software Asterisk.

CVE-2006-5444: Ein Integerüberlauf in der get_input
Funktion im Skinny Kanaltreiber (chan_skinny.c) der zB von
Cisco SCCP Telefonen benutzt wird, erlaubt entfernten
Angreifern potentiell Schadcode auszuführen durch Pakete
mit einem spezifischen dlen Wert der einen
vorzeichenbehafteten Test besteht, aber zu einem
Heapüberlauf führt.

CVE-2006-5445: Ein Problem im SIP Kanaltreiber (chan_sip.c)
in Asterisk auf SUSE Linux 10.1 erlaubt entfernten
Angreifern einen Denial of Service  Angriff mittels
Allozieren aller Systemresourcen.
</description>
  <yum:version ver="2272" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="asterisk" epoch="0" ver="1.2.5" rel="12.8" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>asterisk</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.2.5" rel="12.8"/>
      <checksum type="sha" pkgid="YES">5db2d65f4ea1b1bdca5135017a584cf878485282</checksum>
      <time file="1163606876" build="1163584782"/>
      <size package="3092342" installed="6581099" archive="6226624"/>
      <location href="rpm/i586/asterisk-1.2.5-12.8.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="asterisk" epoch="0" ver="1.2.5" rel="12.8" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="asterisk"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/asterisk-1.2.5-12.8.i586.patch.rpm"/>
          <checksum type="sha">e70ab418d85764335c9e1f3548d316fd5f77a10c</checksum>
          <time file="1163608909" build="1163584782"/>
          <size package="1338265" archive="3562364"/>
          <base-version epoch="0" ver="1.2.5" rel="12"/>
          <base-version epoch="0" ver="1.2.5" rel="12.4"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/asterisk-1.2.5-12_12.8.i586.delta.rpm"/>
          <checksum type="sha">2a95ff0211b46972dba5e748e745396c0e92c70a</checksum>
          <time file="1163608915" build="1163584782"/>
          <size package="573765" archive="0"/>
          <base-version epoch="0" ver="1.2.5" rel="12" md5sum="c0e756f9a513558ca0e4f905b98c456a" buildtime="1146664486" sequence_info="asterisk-1.2.5-12-037ab03f080cc2d1acf33efb170e69cd1d59b3a6e860"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/asterisk-1.2.5-12.4_12.8.i586.delta.rpm"/>
          <checksum type="sha">894d04b0d7cec82be5714d2bfb861f026fedb845</checksum>
          <time file="1163608918" build="1163584782"/>
          <size package="456918" archive="0"/>
          <base-version epoch="0" ver="1.2.5" rel="12.4" md5sum="2c53c87783fe1463f8f01f4041db9978" buildtime="1150725973" sequence_info="asterisk-1.2.5-12.4-a821a2f3d218ebecd4274519da0fa6cf1d59b3e6a860"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>asterisk</name>
      <arch>ppc</arch>
      <version epoch="0" ver="1.2.5" rel="12.8"/>
      <checksum type="sha" pkgid="YES">d8128eab1785895c5033d5e4850a9f3b8242abc8</checksum>
      <time file="1163607230" build="1163584591"/>
      <size package="3303658" installed="7595857" archive="7173272"/>
      <location href="rpm/ppc/asterisk-1.2.5-12.8.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="asterisk" epoch="0" ver="1.2.5" rel="12.8" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="asterisk"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/asterisk-1.2.5-12.8.ppc.patch.rpm"/>
          <checksum type="sha">76b1858ce4e5c4abe3cd43b792142d4a0096af44</checksum>
          <time file="1163608926" build="1163584591"/>
          <size package="1538966" archive="4450944"/>
          <base-version epoch="0" ver="1.2.5" rel="12"/>
          <base-version epoch="0" ver="1.2.5" rel="12.4"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/asterisk-1.2.5-12_12.8.ppc.delta.rpm"/>
          <checksum type="sha">a41751a7bf45d5fac03b3adefd155ad03265b846</checksum>
          <time file="1163608931" build="1163584591"/>
          <size package="288068" archive="0"/>
          <base-version epoch="0" ver="1.2.5" rel="12" md5sum="36e129ee301fca8b5e5713fcdaf10220" buildtime="1146661962" sequence_info="asterisk-1.2.5-12-d72f5f61603a4bf101a907f8425664de1d59b3a6e860"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/asterisk-1.2.5-12.4_12.8.ppc.delta.rpm"/>
          <checksum type="sha">556b565dd5fbc6b4a6fd970d56ee98f1c556eb22</checksum>
          <time file="1163608935" build="1163584591"/>
          <size package="274845" archive="0"/>
          <base-version epoch="0" ver="1.2.5" rel="12.4" md5sum="8147d5622c1d8921ad2f853ca89a88ee" buildtime="1150725905" sequence_info="asterisk-1.2.5-12.4-c1130743ca41ca38622965f279b5c01d1d59b3e6a860"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>asterisk</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.2.5" rel="12.8"/>
      <checksum type="sha" pkgid="YES">51437db49707a17716d14d40d83a048d053ba9f8</checksum>
      <time file="1163606594" build="1163587082"/>
      <size package="3199939" installed="7018639" archive="6643888"/>
      <location href="rpm/x86_64/asterisk-1.2.5-12.8.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="asterisk" epoch="0" ver="1.2.5" rel="12.8" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="asterisk"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/asterisk-1.2.5-12.8.x86_64.patch.rpm"/>
          <checksum type="sha">2f44f487700ef622c4469a0d83069d263e70b99e</checksum>
          <time file="1163608942" build="1163587082"/>
          <size package="1443113" archive="3979628"/>
          <base-version epoch="0" ver="1.2.5" rel="12"/>
          <base-version epoch="0" ver="1.2.5" rel="12.4"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/asterisk-1.2.5-12_12.8.x86_64.delta.rpm"/>
          <checksum type="sha">2eae9df81d40695951758c1ee19bb24943c40149</checksum>
          <time file="1163608946" build="1163587082"/>
          <size package="285592" archive="0"/>
          <base-version epoch="0" ver="1.2.5" rel="12" md5sum="b549f45829f4c99deeb2c9d9af29d0dc" buildtime="1146665447" sequence_info="asterisk-1.2.5-12-08e6816792596e57e788cccfed63aa9b1d59b3a6e860"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/asterisk-1.2.5-12.4_12.8.x86_64.delta.rpm"/>
          <checksum type="sha">e193b62ab27ef75ceefe5a8e0385dea825d416c7</checksum>
          <time file="1163608949" build="1163587082"/>
          <size package="338767" archive="0"/>
          <base-version epoch="0" ver="1.2.5" rel="12.4" md5sum="d1af724ac544cea4694950315d57e57b" buildtime="1150725939" sequence_info="asterisk-1.2.5-12.4-20513fa58f2721e76b304510ec1af0691d59b3e6a860"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
