<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="323f23244f7c638bf1cdb7f8869c8e71"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="gpg-2995"
    timestamp="1174672325"
    engine="1.0">
  <yum:name>gpg</yum:name>
  <summary lang="en">gpg: Fixed mixed signed/unsigned text problem</summary>
  <summary lang="de">gpg: Behebt Problem bei Trennung von signiertem und nicht signiertem Text</summary>
  <description lang="en">When printing a text stream with a GPG signature it was
possible for an attacker to create a stream with &quot;unsigned
text, signed text&quot; where both unsigned and signed text
would be shown without distinction which one was signed and
which part wasn't.

This is tracked by the Mitre CVE ID CVE-2007-1263.

The update introduces a new option
--allow-multiple-messages to print out such messages in the
future, by default it only prints and handles the first one.
</description>
  <description lang="de">Wenn ein Textstream mit GPG geprüft und ausgegeben wird,
ist es möglich, dass dem Benutzer durch mehrere Bausteine,
darunter signierte und unsignierte, vorgegaukelt wird, auch
die unsignierten wären signiert. Dieses Update behebt das
Problem und führt eine Option --allow-multiple-messages
ein, die zum Ausdrucken solcher Nachrichten in Zukunft
benutzt werden muss.

Das Problem hat die Mitre CVE ID CVE-2007-1263.
</description>
  <yum:version ver="2995" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="gpg" epoch="0" ver="1.4.2" rel="23.16" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>gpg</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2" rel="23.16"/>
      <checksum type="sha" pkgid="YES">5f9781b4f805f52296c8f3f8899f1bd1f8a24f34</checksum>
      <time file="1174909282" build="1174672325"/>
      <size package="1567878" installed="4769939" archive="4779924"/>
      <location href="rpm/i586/gpg-1.4.2-23.16.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="gpg" epoch="0" ver="1.4.2" rel="23.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="gpg"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/gpg-1.4.2-23.16.i586.patch.rpm"/>
          <checksum type="sha">4ce9e23d06a613e23ac08c9e359c213996cb361b</checksum>
          <time file="1174914039" build="1174672325"/>
          <size package="667144" archive="1501256"/>
          <base-version epoch="0" ver="1.4.2" rel="23"/>
          <base-version epoch="0" ver="1.4.2" rel="23.12"/>
          <base-version epoch="0" ver="1.4.2" rel="23.4"/>
          <base-version epoch="0" ver="1.4.2" rel="23.7"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/gpg-1.4.2-23_23.16.i586.delta.rpm"/>
          <checksum type="sha">90854883e6c2391adc8400caf5ba4017c33a28bd</checksum>
          <time file="1174914041" build="1174672325"/>
          <size package="91120" archive="0"/>
          <base-version epoch="0" ver="1.4.2" rel="23" md5sum="a95e9cd9c7bacc1ef6c6616191101704" buildtime="1146558534" sequence_info="gpg-1.4.2-23-c43b6ec39082e68724f32c9f80b0f63da810"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/gpg-1.4.2-23.12_23.16.i586.delta.rpm"/>
          <checksum type="sha">15784fac4532c7d4215374d20825ce6915b19405</checksum>
          <time file="1174914043" build="1174672325"/>
          <size package="167233" archive="0"/>
          <base-version epoch="0" ver="1.4.2" rel="23.12" md5sum="714ad111277495f85fb4d75c07a436e1" buildtime="1165512657" sequence_info="gpg-1.4.2-23.12-243261adb5a3954f598861a50756a069842c30"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>gpg</name>
      <arch>ppc</arch>
      <version epoch="0" ver="1.4.2" rel="23.16"/>
      <checksum type="sha" pkgid="YES">771f680aa7474f10faf967602d4e0d3c00c8c204</checksum>
      <time file="1174906534" build="1174672785"/>
      <size package="1601023" installed="4977037" archive="4987024"/>
      <location href="rpm/ppc/gpg-1.4.2-23.16.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="gpg" epoch="0" ver="1.4.2" rel="23.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="gpg"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/gpg-1.4.2-23.16.ppc.patch.rpm"/>
          <checksum type="sha">6910b5420ec6dadb885696d8bc598eb64ed8c460</checksum>
          <time file="1174914053" build="1174672785"/>
          <size package="696417" archive="1708356"/>
          <base-version epoch="0" ver="1.4.2" rel="23"/>
          <base-version epoch="0" ver="1.4.2" rel="23.12"/>
          <base-version epoch="0" ver="1.4.2" rel="23.4"/>
          <base-version epoch="0" ver="1.4.2" rel="23.7"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/gpg-1.4.2-23_23.16.ppc.delta.rpm"/>
          <checksum type="sha">c90eeee703bd3de5e681c4502c00faff2f2490d3</checksum>
          <time file="1174914055" build="1174672785"/>
          <size package="92069" archive="0"/>
          <base-version epoch="0" ver="1.4.2" rel="23" md5sum="61b4a976e398ad620c660dd02fd3c387" buildtime="1146557792" sequence_info="gpg-1.4.2-23-abc456749c3dde7a58bc11f75ef04b2ba810"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/gpg-1.4.2-23.12_23.16.ppc.delta.rpm"/>
          <checksum type="sha">e4db4786f30f62a94b2421eb0f0cf4138cde9983</checksum>
          <time file="1174914058" build="1174672785"/>
          <size package="152804" archive="0"/>
          <base-version epoch="0" ver="1.4.2" rel="23.12" md5sum="87d3e2efab5fda6d0c0fb0228e8089eb" buildtime="1165536834" sequence_info="gpg-1.4.2-23.12-b88aec7edc1f243fb54141b5ad4b1145842c30"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>gpg</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.4.2" rel="23.16"/>
      <checksum type="sha" pkgid="YES">1efe70918f90ee26c5dcadd7dff99435641dd3fa</checksum>
      <time file="1174906587" build="1174672738"/>
      <size package="1608195" installed="4827648" archive="4837644"/>
      <location href="rpm/x86_64/gpg-1.4.2-23.16.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="gpg" epoch="0" ver="1.4.2" rel="23.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="gpg"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/gpg-1.4.2-23.16.x86_64.patch.rpm"/>
          <checksum type="sha">4fa3d55993828892f2d886ec1522309b8262c933</checksum>
          <time file="1174914063" build="1174672738"/>
          <size package="707824" archive="1558976"/>
          <base-version epoch="0" ver="1.4.2" rel="23"/>
          <base-version epoch="0" ver="1.4.2" rel="23.12"/>
          <base-version epoch="0" ver="1.4.2" rel="23.4"/>
          <base-version epoch="0" ver="1.4.2" rel="23.7"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/gpg-1.4.2-23_23.16.x86_64.delta.rpm"/>
          <checksum type="sha">0d0011d44af1491df00572894ea7ca3764c6f6b4</checksum>
          <time file="1174914066" build="1174672738"/>
          <size package="99104" archive="0"/>
          <base-version epoch="0" ver="1.4.2" rel="23" md5sum="04e4e1757cc48f1412722a748ae84f92" buildtime="1146559302" sequence_info="gpg-1.4.2-23-15adb6b058d2df8a6eeac257f316f23ca810"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/gpg-1.4.2-23.12_23.16.x86_64.delta.rpm"/>
          <checksum type="sha">c12350a605037833140217bf5ecb3a0e3ec7616f</checksum>
          <time file="1174914068" build="1174672738"/>
          <size package="172986" archive="0"/>
          <base-version epoch="0" ver="1.4.2" rel="23.12" md5sum="424104d7e79aa13997a9cd5bf48daaed" buildtime="1165511953" sequence_info="gpg-1.4.2-23.12-c8fe42a799becf60d53d96985f32e683842c30"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
