<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="9fc2c5a4de44f225a0a6359cd98eb972"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="java-1_4_2-sun-3843"
    timestamp="1183637404"
    engine="1.0">
  <yum:name>java-1_4_2-sun</yum:name>
  <summary lang="en">java-1_4_2-sun: Security update to 1.4.2 patchlevel 15</summary>
  <summary lang="de">java-1_4_2-sun: Security update auf 1.4.2 Patchlevel 15</summary>
  <description lang="en">The Sun JAVA JDK 1.4.2 was upgraded to release 15 to fix
various bugs, including the following security bugs:

CVE-2007-2788 / CVE-2007-3004: Integer overflow in the
embedded ICC profile image parser in Sun Java Development
Kit (JDK), allows remote attackers to execute arbitrary
code or cause a denial of service (JVM crash) via a crafted
JPEG or BMP file.

CVE-2007-2789 / CVE-2007-3005: The BMP image parser in Sun
Java Development Kit (JDK), on Unix/Linux systems, allows
remote attackers to trigger the opening of arbitrary local
files via a crafted BMP file, which causes a denial of
service (system hang) in certain cases such as /dev/tty,
and has other unspecified impact.

CVE-2007-0243: Buffer overflow in Sun JDK and Java Runtime
Environment (JRE) allows applets to gain privileges via a
GIF image with a block with a 0 width field, which triggers
memory corruption.
</description>
  <description lang="de">Das Sun JAVA JDK 1.4.2 wurde auf Release 15 gebracht, die
unter anderem folgende Sicherheitsprobleme behebt:

CVE-2007-2788 / CVE-2007-3004: Integerüberlauf im embedded
ICC Profil Parser erlaubt entfernten Angreifern potentiell
beliebigen Code auszuführen oder einen Absturz
hervorzurufen, in dem bestimmte JPEG oder BMP Dateien
bearbeitet werden.

CVE-2007-2789 / CVE-2007-3005: Der BMP Bildparser im Sun
JDK auf UNIX/Linux Systemen erlaubt entfernten Angreifern
das Öffnen einer lokalen Datei durch ein spezielles BMP
Bild, die zum Hängen der JVM oder ähnlichen Effekten führen
kann.

CVE-2007-0243: Pufferüberlauf im Sun JRE erlaubt entfernten
Angreifern durch ein präpariertes GIF Bild mit einem Block
mit Breite 0 Memory Corruption auszulösen, die evt zu einer
Privilege Escalation führen kann.
</description>
  <yum:version ver="3843" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="java-1_4_2-sun" epoch="0" ver="1.4.2.15" rel="2.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-alsa" epoch="0" ver="1.4.2.15" rel="2.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-demo" epoch="0" ver="1.4.2.15" rel="2.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-devel" epoch="0" ver="1.4.2.15" rel="2.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-jdbc" epoch="0" ver="1.4.2.15" rel="2.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-plugin" epoch="0" ver="1.4.2.15" rel="2.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-src" epoch="0" ver="1.4.2.15" rel="2.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.15" rel="2.1"/>
      <checksum type="sha" pkgid="YES">9e00f9af322ce6bb9887c43301c7ef706bfdc6bc</checksum>
      <time file="1183717494" build="1183637404"/>
      <size package="18783183" installed="59989161" archive="60114672"/>
      <location href="rpm/i586/java-1_4_2-sun-1.4.2.15-2.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun" epoch="0" ver="1.4.2.15" rel="2.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-1.4.2.15-2.1.i586.patch.rpm"/>
          <checksum type="sha">940d1208f6f56c8534597ca094d80e1349e9d264</checksum>
          <time file="1183720142" build="1183637404"/>
          <size package="18728081" archive="60053636"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-1.4.2.11_1.4.2.15-8_2.1.i586.delta.rpm"/>
          <checksum type="sha">d9d4f695d4fc9b19d50002358e09e3b6db09cf7b</checksum>
          <time file="1183720172" build="1183637404"/>
          <size package="1458556" archive="0"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8" md5sum="132e982597bcf31d810aa4c5ace1d3b3" buildtime="1146233451" sequence_info="java-1_4_2-sun-1.4.2.11-8-8f20a3929183f24b816b94b76abc066fbb21aa15cd66c1"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-1.4.2.13_1.4.2.15-0.2_2.1.i586.delta.rpm"/>
          <checksum type="sha">f613a47407ee936f0fb154b78bfa25a736f28df9</checksum>
          <time file="1183720206" build="1183637404"/>
          <size package="999049" archive="0"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2" md5sum="ab731afee0d28a896d684fa5216290a8" buildtime="1166717041" sequence_info="java-1_4_2-sun-1.4.2.13-0.2-033e8c21c073af98a7e2de88233b829be32bf11aa15fe6"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-alsa</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.15" rel="2.1"/>
      <checksum type="sha" pkgid="YES">e63a365fc189df3a9f141170c0aac823df9aabb5</checksum>
      <time file="1183717494" build="1183637404"/>
      <size package="21852" installed="26584" archive="26888"/>
      <location href="rpm/i586/java-1_4_2-sun-alsa-1.4.2.15-2.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-alsa" epoch="0" ver="1.4.2.15" rel="2.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-alsa"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-alsa-1.4.2.15-2.1.i586.patch.rpm"/>
          <checksum type="sha">d72b69ac80f8d783c318d2daa59ab39ae364ffb9</checksum>
          <time file="1183720221" build="1183637404"/>
          <size package="22003" archive="26888"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-alsa-1.4.2.11_1.4.2.15-8_2.1.i586.delta.rpm"/>
          <checksum type="sha">fc20ada8e10eab5b44e79bd39c28fce41143ede2</checksum>
          <time file="1183720222" build="1183637404"/>
          <size package="11084" archive="0"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8" md5sum="1c2f0c9d0e6048a878d160830b9ce6ba" buildtime="1146233451" sequence_info="java-1_4_2-sun-alsa-1.4.2.11-8-1db3cf409807390581071c3239d770f310"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-alsa-1.4.2.13_1.4.2.15-0.2_2.1.i586.delta.rpm"/>
          <checksum type="sha">e4ec171ccb376eee47cbb1f683b862ea08ade1bc</checksum>
          <time file="1183720222" build="1183637404"/>
          <size package="11079" archive="0"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2" md5sum="dbe701794214d79ae5bd5e85dc892e64" buildtime="1166717041" sequence_info="java-1_4_2-sun-alsa-1.4.2.13-0.2-fc952b2a68c7420b6a9c2b5cb7113f9810"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-demo</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.15" rel="2.1"/>
      <checksum type="sha" pkgid="YES">0eab54e017c7fe247f3d5b54f9e17ab1435d80e8</checksum>
      <time file="1183717495" build="1183637404"/>
      <size package="6318274" installed="9468096" archive="9650812"/>
      <location href="rpm/i586/java-1_4_2-sun-demo-1.4.2.15-2.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-demo" epoch="0" ver="1.4.2.15" rel="2.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-demo"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-demo-1.4.2.15-2.1.i586.patch.rpm"/>
          <checksum type="sha">cd374bc8909cff3c47d339238f8ca688ed019ff0</checksum>
          <time file="1183720231" build="1183637404"/>
          <size package="4501268" archive="4662808"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-demo-1.4.2.11_1.4.2.15-8_2.1.i586.delta.rpm"/>
          <checksum type="sha">54285bff145cb5585890064b86cbfe6b98b41189</checksum>
          <time file="1183720237" build="1183637404"/>
          <size package="131183" archive="0"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8" md5sum="3a1e9cb86b535ea653803231dd18294b" buildtime="1146233451" sequence_info="java-1_4_2-sun-demo-1.4.2.11-8-b41c10a6083449e44a034ee7f269ba0fecf1"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-demo-1.4.2.13_1.4.2.15-0.2_2.1.i586.delta.rpm"/>
          <checksum type="sha">510a65ad6ee9bf5550a40e526d5775229c8b00f2</checksum>
          <time file="1183720241" build="1183637404"/>
          <size package="131693" archive="0"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2" md5sum="5aac3f025f2f4a026fd29dd9fa3bb3f2" buildtime="1166717041" sequence_info="java-1_4_2-sun-demo-1.4.2.13-0.2-233b82c9148ccb70ba9fbfd34c4baf9cecf1"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.15" rel="2.1"/>
      <checksum type="sha" pkgid="YES">c0bceefd1dc3b4ffad3d4ccf059ab47dc941ecd0</checksum>
      <time file="1183717495" build="1183637404"/>
      <size package="2906358" installed="8021647" archive="8032060"/>
      <location href="rpm/i586/java-1_4_2-sun-devel-1.4.2.15-2.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-devel" epoch="0" ver="1.4.2.15" rel="2.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-devel-1.4.2.15-2.1.i586.patch.rpm"/>
          <checksum type="sha">649652f119316e64571003136ee884a9b65f4d4f</checksum>
          <time file="1183720249" build="1183637404"/>
          <size package="2812066" archive="7939152"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-devel-1.4.2.11_1.4.2.15-8_2.1.i586.delta.rpm"/>
          <checksum type="sha">285b9a0a83433a1838d964ae19891a8ad0f8921e</checksum>
          <time file="1183720254" build="1183637404"/>
          <size package="228883" archive="0"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8" md5sum="4923f5499ede7d839a42dbc107364006" buildtime="1146233451" sequence_info="java-1_4_2-sun-devel-1.4.2.11-8-5e4d9a91e2947d7dda1ec570e06efe35d55d10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-devel-1.4.2.13_1.4.2.15-0.2_2.1.i586.delta.rpm"/>
          <checksum type="sha">0756f37b402502fb0a6f90c3cfa9967698f0589a</checksum>
          <time file="1183720258" build="1183637404"/>
          <size package="284209" archive="0"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2" md5sum="43e6cf1a0c090b45a4a409bcdbd8f736" buildtime="1166717041" sequence_info="java-1_4_2-sun-devel-1.4.2.13-0.2-b76d46dac57e80ecac9f8c170f1b50a1d5"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-jdbc</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.15" rel="2.1"/>
      <checksum type="sha" pkgid="YES">c0c2a81d0b7a29e39c60799c62107b886c7ec84e</checksum>
      <time file="1183717495" build="1183637404"/>
      <size package="24081" installed="50016" archive="50316"/>
      <location href="rpm/i586/java-1_4_2-sun-jdbc-1.4.2.15-2.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-jdbc" epoch="0" ver="1.4.2.15" rel="2.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-jdbc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-jdbc-1.4.2.15-2.1.i586.patch.rpm"/>
          <checksum type="sha">fb6ed7a09c21d27384d9878aae5e6b4c7277453f</checksum>
          <time file="1183720261" build="1183637404"/>
          <size package="24230" archive="50316"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-jdbc-1.4.2.11_1.4.2.15-8_2.1.i586.delta.rpm"/>
          <checksum type="sha">edd4b12c949c698593948ffb5299d4dc52a4c3a0</checksum>
          <time file="1183720261" build="1183637404"/>
          <size package="11086" archive="0"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8" md5sum="5cc8dbfcfcd9e7264ef16e9baf0d24fc" buildtime="1146233451" sequence_info="java-1_4_2-sun-jdbc-1.4.2.11-8-51614a6cd22f0de9368279bc597a7cb310"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-jdbc-1.4.2.13_1.4.2.15-0.2_2.1.i586.delta.rpm"/>
          <checksum type="sha">7a7c95ffa6ba548e7cc882244fe57c5f63c99635</checksum>
          <time file="1183720261" build="1183637404"/>
          <size package="11088" archive="0"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2" md5sum="71e2ad7281293cd9618935496d61b5d3" buildtime="1166717041" sequence_info="java-1_4_2-sun-jdbc-1.4.2.13-0.2-6c23ae998c9da222545bc058cd95530d10"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-plugin</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.15" rel="2.1"/>
      <checksum type="sha" pkgid="YES">aabc0f1e6f278c82b5e520786fe3970538338280</checksum>
      <time file="1183717495" build="1183637404"/>
      <size package="796305" installed="2638599" archive="2644460"/>
      <location href="rpm/i586/java-1_4_2-sun-plugin-1.4.2.15-2.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-plugin" epoch="0" ver="1.4.2.15" rel="2.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-plugin"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-plugin-1.4.2.15-2.1.i586.patch.rpm"/>
          <checksum type="sha">1a87c6a93c79c4acef55fd3f24063715084b3c07</checksum>
          <time file="1183720265" build="1183637404"/>
          <size package="796532" archive="2644160"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-plugin-1.4.2.11_1.4.2.15-8_2.1.i586.delta.rpm"/>
          <checksum type="sha">1cd7f4053a8cf05bfc99ffc7209efb19e1274873</checksum>
          <time file="1183720266" build="1183637404"/>
          <size package="26348" archive="0"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8" md5sum="969bbef285e0217fe353eadc9e0d66e0" buildtime="1146233451" sequence_info="java-1_4_2-sun-plugin-1.4.2.11-8-c9ff66d58fb25d505736775630c5fd3fc312"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-plugin-1.4.2.13_1.4.2.15-0.2_2.1.i586.delta.rpm"/>
          <checksum type="sha">a4bd11108df13f1c188c4f88c84e5a0341090fef</checksum>
          <time file="1183720267" build="1183637404"/>
          <size package="20141" archive="0"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2" md5sum="c86d75d765c23e4d58de79d8bc1089df" buildtime="1166717041" sequence_info="java-1_4_2-sun-plugin-1.4.2.13-0.2-abd22a526d438da7b625d1cbfe0fc6b9c312"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-src</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.15" rel="2.1"/>
      <checksum type="sha" pkgid="YES">29972e54db3cb53b23006884ac0f64ee1f9fa02f</checksum>
      <time file="1183717497" build="1183637404"/>
      <size package="10945639" installed="11521827" archive="11522108"/>
      <location href="rpm/i586/java-1_4_2-sun-src-1.4.2.15-2.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-src" epoch="0" ver="1.4.2.15" rel="2.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-src"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-src-1.4.2.15-2.1.i586.patch.rpm"/>
          <checksum type="sha">16697a2c792eb420ea04dadd302ed98218e4aa28</checksum>
          <time file="1183720286" build="1183637404"/>
          <size package="10945753" archive="11522108"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-src-1.4.2.11_1.4.2.15-8_2.1.i586.delta.rpm"/>
          <checksum type="sha">b67678be12a18d06a965288c62a150feeb80bdd3</checksum>
          <time file="1183720296" build="1183637404"/>
          <size package="718648" archive="0"/>
          <base-version epoch="0" ver="1.4.2.11" rel="8" md5sum="88f239cf5b9712eb3b0652dd228e86d7" buildtime="1146233451" sequence_info="java-1_4_2-sun-src-1.4.2.11-8-f420a66a18700e86ceafb47eec96663f10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-src-1.4.2.13_1.4.2.15-0.2_2.1.i586.delta.rpm"/>
          <checksum type="sha">a3c0408f6c7298229961f8575d2e461e35e4f13f</checksum>
          <time file="1183720307" build="1183637404"/>
          <size package="521559" archive="0"/>
          <base-version epoch="0" ver="1.4.2.13" rel="0.2" md5sum="cd2debb1e6c4e9d11856db3fe519841a" buildtime="1166717041" sequence_info="java-1_4_2-sun-src-1.4.2.13-0.2-4a8c18ec88f51479d60ad84aa5cf9d7710"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
