<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="69e817347fcd79b1b527ae7bf60dd28c"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="rsync-4793"
    timestamp="1197056387"
    engine="1.0">
  <yum:name>rsync</yum:name>
  <summary lang="en">rsync: fix to deny bypassing of module hierarchy</summary>
  <summary lang="de">rsync: Fix zur Verbesserung der Zugriffsbeschränkungen.</summary>
  <description lang="en">This update fixes a bug in rsync that allowed remote
attackers to access restricted files outside a module's
hierarchy if no chroot setup was used. (CVE-2007-6199)
Please read http://rsync.samba.org/security.html entry from
November 28th, 2007 to get more information about a secure
configuration of rsync that also covers the bug tracked
with CVE-2007-6200.  This update also fixes some crashes
that only affect rsync-2.6.8 on SLES10.
</description>
  <description lang="de">Dieses Update von rsync erlaubt es Angreifern nicht mehr
Dateien ausserhalb einer Modul-Hierarchie zu referenzieren.
Dies ist über symbolische Links möglich, wenn rsync nicht
in einer Chroot-Umgebung läuft. (CVE-2007-6199) Bitte lesen
Sie auch den Abschnitt vom 28. Nov 2007 unter
http://rsync.samba.org/security.html. Hier werden Tipps zur
sicheren Konfiguration und weitere Details zu CVE-2007-6200
gegeben. Zusätzlich behebt dieses Update noch einige
Abstürze beim Betrieb des rsync-Servers (rsync-2.6.8) unter
SLES10.
</description>
  <yum:version ver="4793" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="rsync" epoch="0" ver="2.6.8" rel="36.22" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>rsync</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.8" rel="36.22"/>
      <checksum type="sha" pkgid="YES">e75a2158c45084a02ed97d26a80f7d6efaeb71cd</checksum>
      <time file="1197370293" build="1197056387"/>
      <size package="327965" installed="597255" archive="599652"/>
      <location href="rpm/i586/rsync-2.6.8-36.22.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="rsync" epoch="0" ver="2.6.8" rel="36.22" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="rsync"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/rsync-2.6.8-36.22.i586.patch.rpm"/>
          <checksum type="sha">56d4e0114df672274a40a47d3775e3976a8d7d38</checksum>
          <time file="1197373080" build="1197056387"/>
          <size package="314989" archive="561616"/>
          <base-version epoch="0" ver="2.6.6" rel="18"/>
          <base-version epoch="0" ver="2.6.8" rel="36.13"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/rsync-2.6.6_2.6.8-18_36.22.i586.delta.rpm"/>
          <checksum type="sha">4fdb3f3f950c9fa3b06ccd2df01d8d56663da356</checksum>
          <time file="1197373081" build="1197056387"/>
          <size package="267213" archive="0"/>
          <base-version epoch="0" ver="2.6.6" rel="18" md5sum="00a6b9881257b9e5c403b4eb4e22b59e" buildtime="1146557925" sequence_info="rsync-2.6.6-18-3e2ae4e6e4a1543380b0f69927867309062114208110"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/rsync-2.6.8-36.13_36.22.i586.delta.rpm"/>
          <checksum type="sha">bb3806cc0dfa6215261244fa888e4f0bfc9b0723</checksum>
          <time file="1197373081" build="1197056387"/>
          <size package="156146" archive="0"/>
          <base-version epoch="0" ver="2.6.8" rel="36.13" md5sum="4b27cdad2334199a2eb786309f0d2a9d" buildtime="1186073683" sequence_info="rsync-2.6.8-36.13-0ea1c4793312d044026035f58b93d08d062114208110"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>rsync</name>
      <arch>ppc</arch>
      <version epoch="0" ver="2.6.8" rel="36.22"/>
      <checksum type="sha" pkgid="YES">ceb6d20e8c3a054fedd24b683de0184c07d7048f</checksum>
      <time file="1197370769" build="1197132107"/>
      <size package="343875" installed="646611" archive="649008"/>
      <location href="rpm/ppc/rsync-2.6.8-36.22.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="rsync" epoch="0" ver="2.6.8" rel="36.22" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="rsync"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/rsync-2.6.8-36.22.ppc.patch.rpm"/>
          <checksum type="sha">335e8c393fd70f5402a0edc33f4aaf509f2c872d</checksum>
          <time file="1197373083" build="1197132107"/>
          <size package="331130" archive="610972"/>
          <base-version epoch="0" ver="2.6.6" rel="18"/>
          <base-version epoch="0" ver="2.6.8" rel="36.13"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/rsync-2.6.6_2.6.8-18_36.22.ppc.delta.rpm"/>
          <checksum type="sha">c7682a1eb77a363d8e8561cc7d4336965c51b3fb</checksum>
          <time file="1197373084" build="1197132107"/>
          <size package="307191" archive="0"/>
          <base-version epoch="0" ver="2.6.6" rel="18" md5sum="b15047d3ba2e118fd0f58cbed346edfd" buildtime="1146561097" sequence_info="rsync-2.6.6-18-fcb020ce34534a54fccd09ed6f2336ac062114208110"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/rsync-2.6.8-36.13_36.22.ppc.delta.rpm"/>
          <checksum type="sha">fd596ca4e2d6c9da8d3c9676457a5a62fc16778b</checksum>
          <time file="1197373085" build="1197132107"/>
          <size package="227935" archive="0"/>
          <base-version epoch="0" ver="2.6.8" rel="36.13" md5sum="541069f5e398cbae28a276691d161c20" buildtime="1186074118" sequence_info="rsync-2.6.8-36.13-c809e422644470c313fc742732113fd7062114208110"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>rsync</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.6.8" rel="36.22"/>
      <checksum type="sha" pkgid="YES">a667d6f8fd1de378ea3cd7cd2f35304b85770bc8</checksum>
      <time file="1197370249" build="1197070896"/>
      <size package="347575" installed="631015" archive="633412"/>
      <location href="rpm/x86_64/rsync-2.6.8-36.22.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="rsync" epoch="0" ver="2.6.8" rel="36.22" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="rsync"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/rsync-2.6.8-36.22.x86_64.patch.rpm"/>
          <checksum type="sha">d39f2e76aa9c85fd6588f71bca34a6d1b41e8299</checksum>
          <time file="1197373086" build="1197070896"/>
          <size package="335150" archive="595376"/>
          <base-version epoch="0" ver="2.6.6" rel="18"/>
          <base-version epoch="0" ver="2.6.8" rel="36.13"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/rsync-2.6.6_2.6.8-18_36.22.x86_64.delta.rpm"/>
          <checksum type="sha">bf8aac2e94e988a7974d60ea231eb4d5d8a7a35f</checksum>
          <time file="1197373088" build="1197070896"/>
          <size package="278662" archive="0"/>
          <base-version epoch="0" ver="2.6.6" rel="18" md5sum="e7f61686f2e0493795d9c5f18ddf370e" buildtime="1146558763" sequence_info="rsync-2.6.6-18-cbf92ee8c8a1715b34b1a8e4aef2e1f7062114208110"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/rsync-2.6.8-36.13_36.22.x86_64.delta.rpm"/>
          <checksum type="sha">96dfc1ccf42260a2e2303027b1203d830032cc6f</checksum>
          <time file="1197373088" build="1197070896"/>
          <size package="156121" archive="0"/>
          <base-version epoch="0" ver="2.6.8" rel="36.13" md5sum="ecc8eee1d8a6142ed3121ff36addebf6" buildtime="1186074296" sequence_info="rsync-2.6.8-36.13-0f7cf67e4741690ad6f30417541b2ae9062114208110"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
