<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="bf8eb2985655ba162113d8c4bd34eb1a"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="ethereal-3885"
    timestamp="1184254608"
    engine="1.0">
  <yum:name>ethereal</yum:name>
  <summary lang="en">ethereal: Securityupdate to fix problems found in version 0.99.6</summary>
  <summary lang="de">ethereal: Sicherheitsupdate für Probleme gefunden in Version 0.99.6</summary>
  <description lang="en">Various security problems were fixed in the wireshark
0.99.6 release, which were backported to ethereal
(predecessor of wireshark):

CVE-2007-3389: Wireshark allowed remote attackers to cause
a denial of service (crash) via a crafted chunked encoding
in an HTTP response, possibly related to a zero-length
payload.

CVE-2007-3390: Wireshark when running on certain systems,
allowed remote attackers to cause a denial of service
(crash) via crafted iSeries capture files that trigger a
SIGTRAP.

CVE-2007-3391: Wireshark allowed remote attackers to cause
a denial of service (memory consumption) via a malformed
DCP ETSI packet that triggers an infinite loop.

CVE-2007-3392: Wireshark allowed remote attackers to cause
a denial of service via malformed (1) SSL or (2) MMS
packets that trigger an infinite loop.

CVE-2007-3393: Off-by-one error in the DHCP/BOOTP dissector
in Wireshark allowed remote attackers to cause a denial of
service (crash) via crafted DHCP-over-DOCSIS packets.
</description>
  <description lang="de">Mehrere Sicherheitsprobleme in Wireshark wurden in Version
0.99.6 behoben, die zurückportiert wurden auf Ethereal
(vorheriger Name von Wireshark):

CVE-2007-3389: Entfernte Angreifer konnten Wireshark zum
Absturz bringen durch eine spezielles &quot;chunked encoding&quot; in
einer HTTP Antwort, wahrscheinlich ausgelöst durch eine
leere Payload.

CVE-2007-3390: Entfernte Angreifer konnten Wireshark
potentiell zum Absturz bringen von bestimmten Systemen
durch spezielle iSeries capture Dateien.

CVE-2007-3391: Entfernte Angreifer konnten Wireshark zum
Verbrauchen des kompletten Speichers bringen indem sie ein
spezielles DCP ETSI Paket schicken das wiederum eine
Endlosschleife auslöst.

CVE-2007-3392: Entfernte Angreifer konnten in Wireshark
eine Endlosschleife auslösen, indem sie spezielle (1) SSL
oder (2) MMS Pakete schicken.

CVE-2007-3393: Ein Off-by-one Fehler im DHCP/BOOTP
Dissektor in Wireshark erlaubte entfernten Angreifern einen
Absturz auszulösen, in dem sie spezielle DHCP-over-DOCSIS
Pakete schicken.
</description>
  <yum:version ver="3885" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="ethereal" epoch="0" ver="0.10.14" rel="16.16" flags="EQ"/>
    <rpm:entry kind="atom" name="ethereal-devel" epoch="0" ver="0.10.14" rel="16.16" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>ethereal</name>
      <arch>i586</arch>
      <version epoch="0" ver="0.10.14" rel="16.16"/>
      <checksum type="sha" pkgid="YES">24933a54d8bf87c59c0fd28c1fc4c4871902ec0e</checksum>
      <time file="1184328674" build="1184254608"/>
      <size package="6838708" installed="22353637" archive="22379008"/>
      <location href="rpm/i586/ethereal-0.10.14-16.16.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="ethereal" epoch="0" ver="0.10.14" rel="16.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="ethereal"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/ethereal-0.10.14-16.16.i586.patch.rpm"/>
          <checksum type="sha">366526cd1a9fd101077aca41bc07858f7acc415a</checksum>
          <time file="1184330011" build="1184254608"/>
          <size package="6451513" archive="20770272"/>
          <base-version epoch="0" ver="0.10.14" rel="16"/>
          <base-version epoch="0" ver="0.10.14" rel="16.11"/>
          <base-version epoch="0" ver="0.10.14" rel="16.5"/>
          <base-version epoch="0" ver="0.10.14" rel="16.8"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/ethereal-0.10.14-16_16.16.i586.delta.rpm"/>
          <checksum type="sha">acfd908d7f43d8667ef73daa9ac4f9066ca1402d</checksum>
          <time file="1184330033" build="1184254608"/>
          <size package="1230582" archive="0"/>
          <base-version epoch="0" ver="0.10.14" rel="16" md5sum="d359152a507ba0c933dea8ddfd620b3f" buildtime="1146647308" sequence_info="ethereal-0.10.14-16-f5b6d23f46479cd2e09e1b4fc40a70bec5d1bd10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/ethereal-0.10.14-16.11_16.16.i586.delta.rpm"/>
          <checksum type="sha">c2a0c3056429d8831219f4da4c5cac7fa868a9bc</checksum>
          <time file="1184330050" build="1184254608"/>
          <size package="1236423" archive="0"/>
          <base-version epoch="0" ver="0.10.14" rel="16.11" md5sum="6aecc0deb29a6339f1fa941c65844c6d" buildtime="1163092537" sequence_info="ethereal-0.10.14-16.11-6bc133b19d18c77dcb4bcdf75f7ce2c2c5d1bc121320"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>ethereal</name>
      <arch>ppc</arch>
      <version epoch="0" ver="0.10.14" rel="16.16"/>
      <checksum type="sha" pkgid="YES">d183c5b5031aafd654af63b40200a188355ead35</checksum>
      <time file="1184328011" build="1184254727"/>
      <size package="7454111" installed="28534369" archive="28559740"/>
      <location href="rpm/ppc/ethereal-0.10.14-16.16.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="ethereal" epoch="0" ver="0.10.14" rel="16.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="ethereal"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/ethereal-0.10.14-16.16.ppc.patch.rpm"/>
          <checksum type="sha">c6fd42c4a4166590004a6858257c644d24e1cd58</checksum>
          <time file="1184330074" build="1184254727"/>
          <size package="6593131" archive="23305884"/>
          <base-version epoch="0" ver="0.10.14" rel="16"/>
          <base-version epoch="0" ver="0.10.14" rel="16.11"/>
          <base-version epoch="0" ver="0.10.14" rel="16.5"/>
          <base-version epoch="0" ver="0.10.14" rel="16.8"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/ethereal-0.10.14-16_16.16.ppc.delta.rpm"/>
          <checksum type="sha">d3afe1039b2dfaafad48f5b3b1a6a75ca8fb4f12</checksum>
          <time file="1184330095" build="1184254727"/>
          <size package="1735815" archive="0"/>
          <base-version epoch="0" ver="0.10.14" rel="16" md5sum="e147eb6ff8baa3bb71f7dd4803e77c01" buildtime="1146648323" sequence_info="ethereal-0.10.14-16-30be81d46327af4bfb4673773ac0946bc5d1bd10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/ethereal-0.10.14-16.11_16.16.ppc.delta.rpm"/>
          <checksum type="sha">dbd84346e038097cda30b9bd84bdb3e2656f3675</checksum>
          <time file="1184330111" build="1184254727"/>
          <size package="1703930" archive="0"/>
          <base-version epoch="0" ver="0.10.14" rel="16.11" md5sum="1c832fcde7f65332e9d0b47274229f69" buildtime="1163093871" sequence_info="ethereal-0.10.14-16.11-cd45ae13090801f225383f1fae52e806c5d1bc121320"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>ethereal</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.10.14" rel="16.16"/>
      <checksum type="sha" pkgid="YES">0d099db043d52d0019baf5b919ea1d30cbf99d6f</checksum>
      <time file="1184328734" build="1184254950"/>
      <size package="7838387" installed="28803229" archive="28828656"/>
      <location href="rpm/x86_64/ethereal-0.10.14-16.16.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="ethereal" epoch="0" ver="0.10.14" rel="16.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="ethereal"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/ethereal-0.10.14-16.16.x86_64.patch.rpm"/>
          <checksum type="sha">0da35f037ebea6995350d51511feed802e305b41</checksum>
          <time file="1184330131" build="1184254950"/>
          <size package="7474842" archive="27219916"/>
          <base-version epoch="0" ver="0.10.14" rel="16"/>
          <base-version epoch="0" ver="0.10.14" rel="16.11"/>
          <base-version epoch="0" ver="0.10.14" rel="16.5"/>
          <base-version epoch="0" ver="0.10.14" rel="16.8"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/ethereal-0.10.14-16_16.16.x86_64.delta.rpm"/>
          <checksum type="sha">1b574f5b663e834def9acad07285bf26b0683a11</checksum>
          <time file="1184330155" build="1184254950"/>
          <size package="2059463" archive="0"/>
          <base-version epoch="0" ver="0.10.14" rel="16" md5sum="39f6a77dd34e2bacdab35b4134c4371b" buildtime="1146647580" sequence_info="ethereal-0.10.14-16-c64d22aa6676c1f26e7098358c093341c5d1bd10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/ethereal-0.10.14-16.11_16.16.x86_64.delta.rpm"/>
          <checksum type="sha">163e253ccf19b7cba1b5ba632d82806bad4cbdb2</checksum>
          <time file="1184330179" build="1184254950"/>
          <size package="2035816" archive="0"/>
          <base-version epoch="0" ver="0.10.14" rel="16.11" md5sum="30ca5d51e0f3e889b31a59bad4611dfc" buildtime="1163092622" sequence_info="ethereal-0.10.14-16.11-3e34d195434109ba0ca39ef5c6a3240ac5d1bc121320"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>ethereal-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="0.10.14" rel="16.16"/>
      <checksum type="sha" pkgid="YES">9719e6cf34291fdf58a1c1ba355b0270597e1070</checksum>
      <time file="1184328676" build="1184254608"/>
      <size package="123585" installed="467013" archive="475232"/>
      <location href="rpm/i586/ethereal-devel-0.10.14-16.16.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="ethereal-devel" epoch="0" ver="0.10.14" rel="16.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="ethereal-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/ethereal-devel-0.10.14-16.16.i586.patch.rpm"/>
          <checksum type="sha">84da4ec959452ab23525e2caa3700f87d22a62f8</checksum>
          <time file="1184330183" build="1184254608"/>
          <size package="15590" archive="124"/>
          <base-version epoch="0" ver="0.10.14" rel="16"/>
          <base-version epoch="0" ver="0.10.14" rel="16.11"/>
          <base-version epoch="0" ver="0.10.14" rel="16.5"/>
          <base-version epoch="0" ver="0.10.14" rel="16.8"/>
        </patchrpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>ethereal-devel</name>
      <arch>ppc</arch>
      <version epoch="0" ver="0.10.14" rel="16.16"/>
      <checksum type="sha" pkgid="YES">0a28e6143d7bece71416fdc8e1eaadadd8198cc6</checksum>
      <time file="1184328013" build="1184254727"/>
      <size package="123884" installed="467010" archive="475228"/>
      <location href="rpm/ppc/ethereal-devel-0.10.14-16.16.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="ethereal-devel" epoch="0" ver="0.10.14" rel="16.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="ethereal-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/ethereal-devel-0.10.14-16.16.ppc.patch.rpm"/>
          <checksum type="sha">a2793f4038131f68f45a6512c7bbeb9c5ceb89be</checksum>
          <time file="1184330187" build="1184254727"/>
          <size package="15562" archive="124"/>
          <base-version epoch="0" ver="0.10.14" rel="16"/>
          <base-version epoch="0" ver="0.10.14" rel="16.11"/>
          <base-version epoch="0" ver="0.10.14" rel="16.5"/>
          <base-version epoch="0" ver="0.10.14" rel="16.8"/>
        </patchrpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>ethereal-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.10.14" rel="16.16"/>
      <checksum type="sha" pkgid="YES">bbf78803c59b312e94ba9da8c9f23b82d75537dd</checksum>
      <time file="1184328736" build="1184254950"/>
      <size package="123634" installed="467015" archive="475236"/>
      <location href="rpm/x86_64/ethereal-devel-0.10.14-16.16.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="ethereal-devel" epoch="0" ver="0.10.14" rel="16.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="ethereal-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/ethereal-devel-0.10.14-16.16.x86_64.patch.rpm"/>
          <checksum type="sha">2917e15de9a334fff1efc55f30d2fa27f2d134f6</checksum>
          <time file="1184330191" build="1184254950"/>
          <size package="15566" archive="124"/>
          <base-version epoch="0" ver="0.10.14" rel="16"/>
          <base-version epoch="0" ver="0.10.14" rel="16.11"/>
          <base-version epoch="0" ver="0.10.14" rel="16.5"/>
          <base-version epoch="0" ver="0.10.14" rel="16.8"/>
        </patchrpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
