<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="4973eb5973396e499cfddb9eb2d236f3"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="mailman-2170"
    timestamp="1160780516"
    engine="1.0">
  <yum:name>mailman</yum:name>
  <summary lang="en">Security update for mailman</summary>
  <summary lang="de">Sicherheitsupdate für mailman</summary>
  <description lang="en">This update of mailman fixes the following security issues:
- A malicious user could visit a specially crafted URI and
  inject an apparent log message into Mailman's error log
  which might induce an unsuspecting administrator to visit
  a phishing site. This has been blocked. Thanks to Moritz
  Naumann for its discovery.
- Fixed denial of service attack which can be caused by
  some standards-breaking RFC 2231 formatted headers.
  CVE-2006-2941.
- Several cross-site scripting issues have been fixed.
  Thanks to Moritz Naumann for their discovery.
  CVE-2006-3636
- Fixed an unexploitable format string vulnerability.
  Discovery and fix by Karl Chen. Analysis of
  non-exploitability by Martin 'Joey' Schulze. Also thanks
  go to Lionel Elie Mamane. CVE-2006-2191.
</description>
  <description lang="de">Mit diesm Update von mailman wurden mehrere
Sicherheitsprobleme behoben:
- die Fehlerlogs können irreführende Einträge enthalten
- mögliche Denial-of-Service Angriffe, CVE-2006-2941
- mögliche Cross-Site-Scripting Probleme, CVE-2006-3636
- ein Format-String Fehler (nicht exploitbar), CVE-2006-2191
</description>
  <yum:version ver="2170" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="mailman" epoch="0" ver="2.1.7" rel="15.5" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mailman</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.1.7" rel="15.5"/>
      <checksum type="sha" pkgid="YES">e00799172b6cadb5f1b69b2f684b1722534eae4b</checksum>
      <time file="1161014871" build="1160780516"/>
      <size package="5527847" installed="27236187" archive="27591408"/>
      <location href="rpm/i586/mailman-2.1.7-15.5.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mailman" epoch="0" ver="2.1.7" rel="15.5" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mailman"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/mailman-2.1.7-15.5.i586.patch.rpm"/>
          <checksum type="sha">1954d8b7a72fbc39b73de754bfdeb2d2c0c74d55</checksum>
          <time file="1161017499" build="1160780516"/>
          <size package="527202" archive="1279212"/>
          <base-version epoch="0" ver="2.1.7" rel="15"/>
        </patchrpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mailman</name>
      <arch>ppc</arch>
      <version epoch="0" ver="2.1.7" rel="15.5"/>
      <checksum type="sha" pkgid="YES">aacd6bf9fdb26fd1910f5824b75f1af42421cb77</checksum>
      <time file="1161014988" build="1160767139"/>
      <size package="5528031" installed="27268691" archive="27623912"/>
      <location href="rpm/ppc/mailman-2.1.7-15.5.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mailman" epoch="0" ver="2.1.7" rel="15.5" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mailman"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/mailman-2.1.7-15.5.ppc.patch.rpm"/>
          <checksum type="sha">7ee14c2f4f53e75fd2ea545058800205c9f531bd</checksum>
          <time file="1161017518" build="1160767139"/>
          <size package="529794" archive="1311716"/>
          <base-version epoch="0" ver="2.1.7" rel="15"/>
        </patchrpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mailman</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.1.7" rel="15.5"/>
      <checksum type="sha" pkgid="YES">ae83468a1f1f8e51eeaffb944a872eef9048e024</checksum>
      <time file="1161014962" build="1160779854"/>
      <size package="5526733" installed="27274215" archive="27629436"/>
      <location href="rpm/x86_64/mailman-2.1.7-15.5.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mailman" epoch="0" ver="2.1.7" rel="15.5" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mailman"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/mailman-2.1.7-15.5.x86_64.patch.rpm"/>
          <checksum type="sha">51367e2ec84d964f266ed18b9988a36f360c1b2f</checksum>
          <time file="1161017536" build="1160779854"/>
          <size package="528706" archive="1317240"/>
          <base-version epoch="0" ver="2.1.7" rel="15"/>
        </patchrpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
