<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="404881c4f387b76a37ae3785e08035f5"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="openssh-2183"
    timestamp="1161281548"
    engine="1.0">
  <yum:name>openssh</yum:name>
  <summary lang="en">openssh: Security update for security problems solved in OpenSSH 4.4</summary>
  <summary lang="de">openssh: Sicherheitsupdate für Probleme die in OpenSSH 4.4 behoben sind</summary>
  <description lang="en">Several security problems were fixed in OpenSSH:

- CVE-2006-4924: A denial of service problem has been fixed
  in OpenSSH which could be used to cause lots of CPU
  consumption on a remote openssh server.
- CVE-2006-4925: If a remote attacker is able to inject
  network traffic this could be used to cause a client
  connection to close.
- CVE-2006-5051: Fixed an unsafe signal hander reported by
  Mark Dowd. The signal handler was vulnerable to a race
  condition that could be exploited to perform a
  pre-authentication denial of service. This vulnerability
  could theoretically lead to pre-authentication remote
  code execution if GSSAPI authentication is enabled, but
  the likelihood of successful exploitation appears remote.
- CVE-2006-5052: Fixed a GSSAPI authentication abort that
  could be used to determine the validity of usernames on
  some platforms.
</description>
  <description lang="de">Mehrere Sicherheitsprobleme in OpenSSH wurden behoben:

- CVE-2006-4924: Ein entfernter Angreifer konnte hohen CPU
  Verbrauch im openssh Server auslösen.
- CVE-2006-4925: Weiterhin konnte ein Angreifer, der
  Netzwerk Verkehr einschleusen kann, eine Clientverbindung
  beenden.
- CVE-2006-5051: Eine unsichere Signalbehandlungsroutine
  wurde verbessert. Diese konnte zu eine Race Condition
  führen, die potentiell zu einem pre-authentication Denial
  of Service Angriff benutzt werden konnte.
- CVE-2006-5052: Ein GSSAPI Authentifizierungsabbruch wurde
  angepasst, der dazu benutzt werden konnte, um zu
  erkennen, welche Benutzer auf dem System existieren.
</description>
  <yum:version ver="2183" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="openssh" epoch="0" ver="4.2p1" rel="18.9" flags="EQ"/>
    <rpm:entry kind="atom" name="openssh-askpass" epoch="0" ver="4.2p1" rel="18.9" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh</name>
      <arch>i586</arch>
      <version epoch="0" ver="4.2p1" rel="18.9"/>
      <checksum type="sha" pkgid="YES">c04530455a7a51896c4345775be49b952edbb5c0</checksum>
      <time file="1161342438" build="1161281548"/>
      <size package="675639" installed="1935893" archive="1943076"/>
      <location href="rpm/i586/openssh-4.2p1-18.9.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh" epoch="0" ver="4.2p1" rel="18.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/openssh-4.2p1-18.9.i586.patch.rpm"/>
          <checksum type="sha">4ddc4d0c6dec1e6e5ee4b9ac28774de61edda851</checksum>
          <time file="1161343837" build="1161281548"/>
          <size package="525321" archive="1486688"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/openssh-4.2p1-18_18.9.i586.delta.rpm"/>
          <checksum type="sha">7160873446f21cc23501894f12a57f93bed25fcf</checksum>
          <time file="1161343839" build="1161281548"/>
          <size package="169796" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="510ba3217de274e582389fc1b614c8c7" buildtime="1146556672" sequence_info="openssh-4.2p1-18-04087317dd33db803d104b33a6c4a51f0233829192"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh</name>
      <arch>ppc</arch>
      <version epoch="0" ver="4.2p1" rel="18.9"/>
      <checksum type="sha" pkgid="YES">2b1cc9bfef616ad4610c2557dc0db00390e7f821</checksum>
      <time file="1161342827" build="1161281101"/>
      <size package="731075" installed="2241189" archive="2248372"/>
      <location href="rpm/ppc/openssh-4.2p1-18.9.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh" epoch="0" ver="4.2p1" rel="18.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/openssh-4.2p1-18.9.ppc.patch.rpm"/>
          <checksum type="sha">1bbeadca702b04e4cf6820ea3662a35c134eaae1</checksum>
          <time file="1161343845" build="1161281101"/>
          <size package="568457" archive="1791984"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/openssh-4.2p1-18_18.9.ppc.delta.rpm"/>
          <checksum type="sha">04eba4fa51fbaae0b351e88d6bd46ca33b27d6eb</checksum>
          <time file="1161343850" build="1161281101"/>
          <size package="169364" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="faf6127c53215d2001b2982f925e9f28" buildtime="1146555781" sequence_info="openssh-4.2p1-18-b427542b00a46d259d2da080875d74d60233829192"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="4.2p1" rel="18.9"/>
      <checksum type="sha" pkgid="YES">c9173d28169373ed2c517d6e743212eba9a9efc1</checksum>
      <time file="1161342757" build="1161281195"/>
      <size package="733243" installed="2049835" archive="2057032"/>
      <location href="rpm/x86_64/openssh-4.2p1-18.9.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh" epoch="0" ver="4.2p1" rel="18.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/openssh-4.2p1-18.9.x86_64.patch.rpm"/>
          <checksum type="sha">b272b2b016897c58b1d5f842ad3ff5d422e8c7f4</checksum>
          <time file="1161343852" build="1161281195"/>
          <size package="577810" archive="1600636"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/openssh-4.2p1-18_18.9.x86_64.delta.rpm"/>
          <checksum type="sha">848d83e717c2e6261f0c887159ce9c2dc9416c5b</checksum>
          <time file="1161343854" build="1161281195"/>
          <size package="191181" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="aa98efbfb3e68bca46f337058e781948" buildtime="1146557832" sequence_info="openssh-4.2p1-18-1d12de853d1cdb42a8d10a160d21dffb0233829192"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh-askpass</name>
      <arch>i586</arch>
      <version epoch="0" ver="4.2p1" rel="18.9"/>
      <checksum type="sha" pkgid="YES">e8d73e1a98b306868742fffeffb781a2462ce97f</checksum>
      <time file="1161342438" build="1161281548"/>
      <size package="40734" installed="35745" archive="36636"/>
      <location href="rpm/i586/openssh-askpass-4.2p1-18.9.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh-askpass" epoch="0" ver="4.2p1" rel="18.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh-askpass"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/openssh-askpass-4.2p1-18.9.i586.patch.rpm"/>
          <checksum type="sha">3d2ad2e455253421a5cfd7134c751c3b8a75cab4</checksum>
          <time file="1161343856" build="1161281548"/>
          <size package="34757" archive="28232"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/openssh-askpass-4.2p1-18_18.9.i586.delta.rpm"/>
          <checksum type="sha">a4fe40410573336d1ec5e04f6b95771fb0ec5925</checksum>
          <time file="1161343856" build="1161281548"/>
          <size package="23859" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="2777fa4c4d4f463c193f81cfe761bd46" buildtime="1146556672" sequence_info="openssh-askpass-4.2p1-18-b6c0707789589ce4a0783b9fa92685320140"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh-askpass</name>
      <arch>ppc</arch>
      <version epoch="0" ver="4.2p1" rel="18.9"/>
      <checksum type="sha" pkgid="YES">3368aec0d48fb488ba29f40cf732b177927b55a4</checksum>
      <time file="1161342827" build="1161281101"/>
      <size package="44101" installed="43677" archive="44568"/>
      <location href="rpm/ppc/openssh-askpass-4.2p1-18.9.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh-askpass" epoch="0" ver="4.2p1" rel="18.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh-askpass"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/openssh-askpass-4.2p1-18.9.ppc.patch.rpm"/>
          <checksum type="sha">2b52e53e908fab814c31a97524336f4354fc0924</checksum>
          <time file="1161343857" build="1161281101"/>
          <size package="38049" archive="36164"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/openssh-askpass-4.2p1-18_18.9.ppc.delta.rpm"/>
          <checksum type="sha">cbc03916ee59b737bc925a5884ef6189b40094a3</checksum>
          <time file="1161343858" build="1161281101"/>
          <size package="24120" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="0bb769aba68acafc6b668b96e3de4444" buildtime="1146555781" sequence_info="openssh-askpass-4.2p1-18-8f83205233a71a79bddac4d5474ec4b80140"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh-askpass</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="4.2p1" rel="18.9"/>
      <checksum type="sha" pkgid="YES">b3c381227289dd8970ce4414b47aeff7e04522d1</checksum>
      <time file="1161342757" build="1161281195"/>
      <size package="43094" installed="44389" archive="45288"/>
      <location href="rpm/x86_64/openssh-askpass-4.2p1-18.9.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh-askpass" epoch="0" ver="4.2p1" rel="18.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh-askpass"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/openssh-askpass-4.2p1-18.9.x86_64.patch.rpm"/>
          <checksum type="sha">9bfbae71c13b9bc07d016085ad09540ca892e348</checksum>
          <time file="1161343859" build="1161281195"/>
          <size package="37082" archive="36876"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/openssh-askpass-4.2p1-18_18.9.x86_64.delta.rpm"/>
          <checksum type="sha">0237df9d452af57fe684ae94b29655d0ca15dc32</checksum>
          <time file="1161343859" build="1161281195"/>
          <size package="23855" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="2e303949008cc76aa3a862feeb64ae9c" buildtime="1146557832" sequence_info="openssh-askpass-4.2p1-18-62b32fb7d422dea9265f77a59e0d74740140"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
