<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="9b16515b76321f08b714d3edc01316ec"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="openssh-4579"
    timestamp="1192668011"
    engine="1.0">
  <yum:name>openssh</yum:name>
  <summary lang="en">openssh: This update fixes a bug in ssh's cookie and signal handling code.</summary>
  <summary lang="de">openssh: Dieses Update behebt einen Fehler im Cookie-Code und mit der Signalmaske.</summary>
  <description lang="en">This update fixes a bug in ssh's cookie handling code. It
does not properly handle the situation when an untrusted
cookie cannot be created and uses a trusted X11 cookie
instead. This allows attackers to violate the intended
policy and gain privileges by causing an X client to be
treated as trusted. (CVE-2007-4752) Additionally this
update fixes a bug introduced with the last security update
for openssh. When the SSH daemon wrote to stderr (for
instance, to warn about the presence of a deprecated option
like PAMAuthenticationViaKbdInt in its configuration file),
SIGALRM was blocked for SSH sessions. This resulted in
problems with processes which rely on SIGALRM, such as
ntpdate.
</description>
  <description lang="de">Dieses Update behebt einen Fehler im Cookie-Code von ssh.
Wenn ein nichtvertrauenswürdiger Cookie nicht generiert
werden konnte, wurde ein vertrauenswürdiger X11 Cookie
benutzt. Dieses Vorgehen erlaubte es einem Angreifer die
vorgesehene Policy zu umgehen. (CVE-2007-4752) Zusätzlich
wurde ein Fehler bei der Handhabung der Signalmaske, der
durch das letzte Sicherheitsupdate entstanden ist. Das
Problem tritt auf bei der Verwendung der
Konfigurationsoption PAMAuthenticationViaKbdInt und führt
dazu, dass SIGALRM in der SSH-Session blockiert wird.
</description>
  <yum:version ver="4579" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="openssh" epoch="0" ver="4.2p1" rel="18.30" flags="EQ"/>
    <rpm:entry kind="atom" name="openssh-askpass" epoch="0" ver="4.2p1" rel="18.30" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh</name>
      <arch>i586</arch>
      <version epoch="0" ver="4.2p1" rel="18.30"/>
      <checksum type="sha" pkgid="YES">b85c696660a5f3689f7544926e50c7a6ba013f80</checksum>
      <time file="1193150516" build="1192668011"/>
      <size package="670929" installed="1930073" archive="1937668"/>
      <location href="rpm/i586/openssh-4.2p1-18.30.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh" epoch="0" ver="4.2p1" rel="18.30" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/openssh-4.2p1-18.30.i586.patch.rpm"/>
          <checksum type="sha">ab2f81e9924af43e98e80faab9faa9a9f5403a41</checksum>
          <time file="1190390450" build="1192668011"/>
          <size package="520868" archive="1481280"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12"/>
          <base-version epoch="0" ver="4.2p1" rel="18.9"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/openssh-4.2p1-18_18.30.i586.delta.rpm"/>
          <checksum type="sha">6d9022588b25308d7cb4f2ce1b6596361d3dc903</checksum>
          <time file="1193151649" build="1192668011"/>
          <size package="249579" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="510ba3217de274e582389fc1b614c8c7" buildtime="1146556672" sequence_info="openssh-4.2p1-18-04087317dd33db803d104b33a6c4a51f0233829192"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/openssh-4.2p1-18.12_18.30.i586.delta.rpm"/>
          <checksum type="sha">83ec7db5946ec0c05d921a9192f941b212e4abd0</checksum>
          <time file="1193151651" build="1192668011"/>
          <size package="296130" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12" md5sum="4b447d09124777f0625df25c7b25a166" buildtime="1163193101" sequence_info="openssh-4.2p1-18.12-228a75f09e7ed5ad4b4d3f6a4484b153023382b11c12"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh</name>
      <arch>ppc</arch>
      <version epoch="0" ver="4.2p1" rel="18.30"/>
      <checksum type="sha" pkgid="YES">051157be5fe4c9a2e4dcefb205c634c301005a95</checksum>
      <time file="1193150562" build="1192688910"/>
      <size package="725938" installed="2231325" archive="2238920"/>
      <location href="rpm/ppc/openssh-4.2p1-18.30.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh" epoch="0" ver="4.2p1" rel="18.30" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/openssh-4.2p1-18.30.ppc.patch.rpm"/>
          <checksum type="sha">1beb5fa460688753d6b7bc7e8fbae896636dea4d</checksum>
          <time file="1190390467" build="1192688910"/>
          <size package="563918" archive="1782532"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12"/>
          <base-version epoch="0" ver="4.2p1" rel="18.9"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/openssh-4.2p1-18_18.30.ppc.delta.rpm"/>
          <checksum type="sha">7e48dd49fdfba7184c24b588fb3513d3a0bb7956</checksum>
          <time file="1193151668" build="1192688910"/>
          <size package="380313" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="faf6127c53215d2001b2982f925e9f28" buildtime="1146555781" sequence_info="openssh-4.2p1-18-b427542b00a46d259d2da080875d74d60233829192"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/openssh-4.2p1-18.12_18.30.ppc.delta.rpm"/>
          <checksum type="sha">ca1df6da11007b1bc1e73b35a9b57b18b3692e6d</checksum>
          <time file="1193151671" build="1192688910"/>
          <size package="434572" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12" md5sum="74fce9a3889d9d5ee2f5c1b87acc3df0" buildtime="1163261737" sequence_info="openssh-4.2p1-18.12-36051aef759fd0897737191fcc08fd02023382b11c12"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="4.2p1" rel="18.30"/>
      <checksum type="sha" pkgid="YES">2c427eac3b0812d5df4ff352e2095b1e0b7c7818</checksum>
      <time file="1193150613" build="1192684647"/>
      <size package="725778" installed="2045503" archive="2053112"/>
      <location href="rpm/x86_64/openssh-4.2p1-18.30.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh" epoch="0" ver="4.2p1" rel="18.30" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/openssh-4.2p1-18.30.x86_64.patch.rpm"/>
          <checksum type="sha">db65b717dce0ad4c93520cef5448fb86adfac3c9</checksum>
          <time file="1190390482" build="1192684647"/>
          <size package="571498" archive="1596716"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12"/>
          <base-version epoch="0" ver="4.2p1" rel="18.9"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/openssh-4.2p1-18_18.30.x86_64.delta.rpm"/>
          <checksum type="sha">14a27da650aa59d7197020645912b58179b9f4bf</checksum>
          <time file="1193151679" build="1192684647"/>
          <size package="300252" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="aa98efbfb3e68bca46f337058e781948" buildtime="1146557832" sequence_info="openssh-4.2p1-18-1d12de853d1cdb42a8d10a160d21dffb0233829192"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/openssh-4.2p1-18.12_18.30.x86_64.delta.rpm"/>
          <checksum type="sha">929be0d5aaf544d8e4bd18b2633446f648bc1a10</checksum>
          <time file="1193151680" build="1192684647"/>
          <size package="347715" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12" md5sum="ccd7c4cc07534349764273246e78ed49" buildtime="1163200346" sequence_info="openssh-4.2p1-18.12-1ea90c3f7abe60a7f436da11b4103a43023382b11c12"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh-askpass</name>
      <arch>i586</arch>
      <version epoch="0" ver="4.2p1" rel="18.30"/>
      <checksum type="sha" pkgid="YES">be3c5c5b580ae131acf6319bbe5b7de4ef149026</checksum>
      <time file="1193150516" build="1192668011"/>
      <size package="41334" installed="35965" archive="36856"/>
      <location href="rpm/i586/openssh-askpass-4.2p1-18.30.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh-askpass" epoch="0" ver="4.2p1" rel="18.30" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh-askpass"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/openssh-askpass-4.2p1-18.30.i586.patch.rpm"/>
          <checksum type="sha">dd3bfd705c6329fdeeb4e535844bef51af6c709d</checksum>
          <time file="1190390490" build="1192668011"/>
          <size package="35393" archive="28452"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12"/>
          <base-version epoch="0" ver="4.2p1" rel="18.9"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/openssh-askpass-4.2p1-18_18.30.i586.delta.rpm"/>
          <checksum type="sha">61d03294dce5e3bce5935c0010fd40c1618ce123</checksum>
          <time file="1193151685" build="1192668011"/>
          <size package="25203" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="2777fa4c4d4f463c193f81cfe761bd46" buildtime="1146556672" sequence_info="openssh-askpass-4.2p1-18-b6c0707789589ce4a0783b9fa92685320140"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/openssh-askpass-4.2p1-18.12_18.30.i586.delta.rpm"/>
          <checksum type="sha">15112ab69cf12e99522e113e8c8aa03ab05fb46d</checksum>
          <time file="1193151686" build="1192668011"/>
          <size package="28690" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12" md5sum="4634a0754e93674ef9cfbaea199173a4" buildtime="1163193101" sequence_info="openssh-askpass-4.2p1-18.12-29b08ea0bfc1545288a33775f5672774011120"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh-askpass</name>
      <arch>ppc</arch>
      <version epoch="0" ver="4.2p1" rel="18.30"/>
      <checksum type="sha" pkgid="YES">66d732ae3f4afbc0bde1f7782f3023c87d7e0b2b</checksum>
      <time file="1193150563" build="1192688910"/>
      <size package="44662" installed="43577" archive="44468"/>
      <location href="rpm/ppc/openssh-askpass-4.2p1-18.30.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh-askpass" epoch="0" ver="4.2p1" rel="18.30" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh-askpass"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/openssh-askpass-4.2p1-18.30.ppc.patch.rpm"/>
          <checksum type="sha">cc82afe49fdf6f2e8a569641dde16828c763833e</checksum>
          <time file="1190390494" build="1192688910"/>
          <size package="38717" archive="36064"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12"/>
          <base-version epoch="0" ver="4.2p1" rel="18.9"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/openssh-askpass-4.2p1-18_18.30.ppc.delta.rpm"/>
          <checksum type="sha">704237548cbc038f3d167149021debe5755bb0bd</checksum>
          <time file="1193151689" build="1192688910"/>
          <size package="33453" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="0bb769aba68acafc6b668b96e3de4444" buildtime="1146555781" sequence_info="openssh-askpass-4.2p1-18-8f83205233a71a79bddac4d5474ec4b80140"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssh-askpass</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="4.2p1" rel="18.30"/>
      <checksum type="sha" pkgid="YES">9222da6367ccfb7436752c3a5143e0e838818f14</checksum>
      <time file="1193150613" build="1192684647"/>
      <size package="43632" installed="44605" archive="45504"/>
      <location href="rpm/x86_64/openssh-askpass-4.2p1-18.30.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssh-askpass" epoch="0" ver="4.2p1" rel="18.30" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssh-askpass"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/openssh-askpass-4.2p1-18.30.x86_64.patch.rpm"/>
          <checksum type="sha">fe9d3d2142d7e0fc61ec513a93fe6f0aab940605</checksum>
          <time file="1190390498" build="1192684647"/>
          <size package="37716" archive="37092"/>
          <base-version epoch="0" ver="4.2p1" rel="18"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12"/>
          <base-version epoch="0" ver="4.2p1" rel="18.9"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/openssh-askpass-4.2p1-18_18.30.x86_64.delta.rpm"/>
          <checksum type="sha">ebf21ca5ddb931bd87b07bf574f0dedd316ae647</checksum>
          <time file="1193151693" build="1192684647"/>
          <size package="24823" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18" md5sum="2e303949008cc76aa3a862feeb64ae9c" buildtime="1146557832" sequence_info="openssh-askpass-4.2p1-18-62b32fb7d422dea9265f77a59e0d74740140"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/openssh-askpass-4.2p1-18.12_18.30.x86_64.delta.rpm"/>
          <checksum type="sha">cdbcdc6f3fa5af3c5f7e33cabf2d33905cecc9a8</checksum>
          <time file="1193151693" build="1192684647"/>
          <size package="28491" archive="0"/>
          <base-version epoch="0" ver="4.2p1" rel="18.12" md5sum="c3d1f4394a9490e5fa8f540c94c1fdcc" buildtime="1163200346" sequence_info="openssh-askpass-4.2p1-18.12-49475ef1a68e9cea30e56adb356e69b1011120"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
