<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="fc7a75b43d64f7c9a558c87eafa9d7bb"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="imlib2-loaders-2265"
    timestamp="1163497360"
    engine="1.0">
  <yum:name>imlib2-loaders</yum:name>
  <summary lang="en">imlib2: Fixed various security problems in imlib2-loaders</summary>
  <summary lang="de">imlib2: Behebt einige Probleme in den imlib2-loaders</summary>
  <description lang="en">Various security problems have been fixed in the imlib2
image loaders:

CVE-2006-4809: A stack buffer overflow in loader_pnm.c
could be used by attackers to execute code by supplying a
handcrafted PNM image.

CVE-2006-4808: A heap buffer overflow in loader_tga.c could
potentially be used by attackers to execute code by
supplying a handcrafted TGA image.

CVE-2006-4807: A out of bounds memory read in loader_tga.c
could be used to crash the imlib2 using application with a
handcrafted TGA image.

CVE-2006-4806: Various integer overflows in width*height
calculations could lead to heap overflows which could
potentially be used to execute code. Affected here are the
ARGB, PNG, LBM, JPEG and TIFF loaders.

Additionaly loading of TIFF images on 64bit systems is now
possible.

This update obsoletes the previous one, which had problems
with JPEG loading.
</description>
  <description lang="de">Mehrere Sicherheitsproblem wurden in den Bildladeroutinen
der imlib2 Bibliothek gefunden:

CVE-2006-4809: Ein Stacküberlauf in loader_pnm.c konnte
durch Angreifer benutzt werden um Code auszuführen durch
Laden eines präparierten PNM Bildes.

CVE-2006-4808: Ein Heapüberlauf in loader_tga.c konnte
potentiell von einem Angreifer benutzt werden um Code
auszuführen durch Laden eines präparierten TGA Bildes.

CVE-2006-4807: Ein ausserhalb von Arraygrenzen Lesen in
loader_tga.c konnte von einem Angreifer zum Absturzbringen
eines Programmes das TGA Bilder lädt benutzt werden.

CVE-2006-4806: Verschiedene Integerüberläufe in Höhe*Breite
Berechnungen konnten zu Heapüberläufen führen, die
potentielle zum Ausführen von Code benutzt werden können.
Betroffen hier sind die Laderoutinen von  ARGB, PNG, LBM,
JPEG und TIFF Bildern.

Weiterhin ist jetzt das Laden von TIFF Bildern auf 64bit
Systemen möglich.

Dieses Update behebt Probleme des vorherigen mit JPEG
Bildern.
</description>
  <yum:version ver="2265" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="imlib2-loaders" epoch="0" ver="1.2.1" rel="17.9" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>imlib2-loaders</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.2.1" rel="17.9"/>
      <checksum type="sha" pkgid="YES">81412894d5e8ee50d6786606403b082ab3e475ab</checksum>
      <time file="1163583132" build="1163497360"/>
      <size package="41892" installed="109101" archive="112956"/>
      <location href="rpm/i586/imlib2-loaders-1.2.1-17.9.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="imlib2-loaders" epoch="0" ver="1.2.1" rel="17.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="imlib2-loaders"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/imlib2-loaders-1.2.1-17.9.i586.patch.rpm"/>
          <checksum type="sha">64d49590294ed3e8ba2017711d3e89e12489750f</checksum>
          <time file="1163589231" build="1163497360"/>
          <size package="40724" archive="100656"/>
          <base-version epoch="0" ver="1.2.1" rel="17"/>
          <base-version epoch="0" ver="1.2.1" rel="17.7"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/imlib2-loaders-1.2.1-17_17.9.i586.delta.rpm"/>
          <checksum type="sha">50b3ca35c2881b06d91bde5ad0461b328ab01e0a</checksum>
          <time file="1163589232" build="1163497360"/>
          <size package="16926" archive="0"/>
          <base-version epoch="0" ver="1.2.1" rel="17" md5sum="35df13922d1f74fca0a7bfb4446243e8" buildtime="1146556219" sequence_info="imlib2-loaders-1.2.1-17-282b137a10bcfa3c004ee41e9fa9c650a3"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/imlib2-loaders-1.2.1-17.7_17.9.i586.delta.rpm"/>
          <checksum type="sha">6efeb007d7081413503dfb084e8e37fe8876008b</checksum>
          <time file="1163589232" build="1163497360"/>
          <size package="8502" archive="0"/>
          <base-version epoch="0" ver="1.2.1" rel="17.7" md5sum="fd712b4aedc4778798f97a890a102edf" buildtime="1163003559" sequence_info="imlib2-loaders-1.2.1-17.7-d6366ec3d0ba0fd47d0b2bf1eb99aa9ca3"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>imlib2-loaders</name>
      <arch>ppc</arch>
      <version epoch="0" ver="1.2.1" rel="17.9"/>
      <checksum type="sha" pkgid="YES">0d0c251e512e81b7cb994835bbe560ae5d4bef6d</checksum>
      <time file="1163583149" build="1163498321"/>
      <size package="52986" installed="170037" archive="173892"/>
      <location href="rpm/ppc/imlib2-loaders-1.2.1-17.9.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="imlib2-loaders" epoch="0" ver="1.2.1" rel="17.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="imlib2-loaders"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/imlib2-loaders-1.2.1-17.9.ppc.patch.rpm"/>
          <checksum type="sha">a745cb5a684e517254835589a7f29f9d7a9ea766</checksum>
          <time file="1163589235" build="1163498321"/>
          <size package="50020" archive="150748"/>
          <base-version epoch="0" ver="1.2.1" rel="17"/>
          <base-version epoch="0" ver="1.2.1" rel="17.7"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/imlib2-loaders-1.2.1-17_17.9.ppc.delta.rpm"/>
          <checksum type="sha">961044d9315ee4c5b6a7a1cc3a0d8eff60c8ef98</checksum>
          <time file="1163589235" build="1163498321"/>
          <size package="17128" archive="0"/>
          <base-version epoch="0" ver="1.2.1" rel="17" md5sum="d3c456130eeff4cb665409e81d3ddbc0" buildtime="1146556427" sequence_info="imlib2-loaders-1.2.1-17-08409ce5d59ef53d527795546cddace0a3"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/imlib2-loaders-1.2.1-17.7_17.9.ppc.delta.rpm"/>
          <checksum type="sha">0122e7c2b50d8e1f453a43f396808bcf2d31519f</checksum>
          <time file="1163589236" build="1163498321"/>
          <size package="8126" archive="0"/>
          <base-version epoch="0" ver="1.2.1" rel="17.7" md5sum="b86e954c9d638d3a46bd267d673b3058" buildtime="1163003472" sequence_info="imlib2-loaders-1.2.1-17.7-7b0c30b8b5c88e3920958381d1e2cf39a3"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>imlib2-loaders</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.2.1" rel="17.9"/>
      <checksum type="sha" pkgid="YES">df4dfb1d0fa0d2567edc12438ad16374051e16d1</checksum>
      <time file="1163583000" build="1163497527"/>
      <size package="42241" installed="128729" archive="132624"/>
      <location href="rpm/x86_64/imlib2-loaders-1.2.1-17.9.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="imlib2-loaders" epoch="0" ver="1.2.1" rel="17.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="imlib2-loaders"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/imlib2-loaders-1.2.1-17.9.x86_64.patch.rpm"/>
          <checksum type="sha">c28d641726065eef2ea28de2a990ff4c9534bb30</checksum>
          <time file="1163589238" build="1163497527"/>
          <size package="40938" archive="120196"/>
          <base-version epoch="0" ver="1.2.1" rel="17"/>
          <base-version epoch="0" ver="1.2.1" rel="17.7"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/imlib2-loaders-1.2.1-17_17.9.x86_64.delta.rpm"/>
          <checksum type="sha">961889b10dbfe09e1cf0d844ba19fe4e53ac2e89</checksum>
          <time file="1163589239" build="1163497527"/>
          <size package="16354" archive="0"/>
          <base-version epoch="0" ver="1.2.1" rel="17" md5sum="5f31e71e722f4da784f039cb5c24f657" buildtime="1146557596" sequence_info="imlib2-loaders-1.2.1-17-299792fd77930dae7f85c0c7486d3539a3"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/imlib2-loaders-1.2.1-17.7_17.9.x86_64.delta.rpm"/>
          <checksum type="sha">55b32cf07bc7f64935ff400c36e206a4b469af8c</checksum>
          <time file="1163589239" build="1163497527"/>
          <size package="8242" archive="0"/>
          <base-version epoch="0" ver="1.2.1" rel="17.7" md5sum="e0ac390abc3a408b5c481e4b41f44362" buildtime="1163003475" sequence_info="imlib2-loaders-1.2.1-17.7-bbb1ca8609941b690440e8951f50ae42a3"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
