<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="6aff74781b473ea7af3f5de69049a030"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="xine-lib-2308"
    timestamp="1164497695"
    engine="1.0">
  <yum:name>xine-lib</yum:name>
  <summary lang="en">xine-lib: Fixed various buffer overflow security problems</summary>
  <summary lang="de">xine-lib: Mehrere Pufferüberläufe wurden behoben.</summary>
  <description lang="en">Multiple buffer overflows were fixed in the XINE decoder
libraries, which could be used by attackers to crash
players or potentially execute code.

CVE-2006-4799: Buffer overflow in ffmpeg for xine-lib
before 1.1.2 might allow context-dependent attackers to
execute arbitrary code via a crafted AVI file and &quot;bad
indexes&quot;.

CVE-2006-4800: Multiple buffer overflows in libavcodec in
ffmpeg before 0.4.9_p20060530 allow remote attackers to
cause a denial of service or possibly execute arbitrary
code via multiple unspecified vectors in (1) dtsdec.c, (2)
vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6)
tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c,
(11) smacker.c, (12) snow.c, and (13) tta.c.
</description>
  <description lang="de">Mehrere Pufferüberläufe in den Xine Dekodern wurden
behoben, die von Angreifern dazu ausgenutzt werden konnten,
Player zu Absturz zu bringen oder potentiell Schadcode
auszuführen.

CVE-2006-4799: Ausnutzen eines Pufferüberlaufs mittels
einer präparierter AVI Datei und &quot;bad indexes&quot; im ffmpeg
für xine-lib vor 1.1.2 konnten Angreifern potentiell
erlauben Schadcode auszuführen.

CVE-2006-4800: Mehrere Pufferüberläufe in libavcodec in
ffmpeg erlaubt entfernten Angreifern einen Absturz oder das
Ausführen von Schadcode zu verursachen, durch Ausnutzen von
Problem in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4)
sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8)
alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12)
snow.c und (13) tta.c.
</description>
  <yum:version ver="2308" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="xine-lib" epoch="0" ver="1.1.1" rel="24.10" flags="EQ"/>
    <rpm:entry kind="atom" name="xine-lib-32bit" epoch="0" ver="1.1.1" rel="24.10" flags="EQ"/>
    <rpm:entry kind="atom" name="xine-lib-64bit" epoch="0" ver="1.1.1" rel="24.10" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>xine-lib</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.1.1" rel="24.10"/>
      <checksum type="sha" pkgid="YES">2d3dd9ec896f8882e3451ad7af33f28a00301447</checksum>
      <time file="1164580797" build="1164497695"/>
      <size package="2699049" installed="5627393" archive="5657540"/>
      <location href="rpm/i586/xine-lib-1.1.1-24.10.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="xine-lib" epoch="0" ver="1.1.1" rel="24.10" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="xine-lib"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/xine-lib-1.1.1-24.10.i586.patch.rpm"/>
          <checksum type="sha">256305bce1a9f9c67672c531779bd0810cd2aa97</checksum>
          <time file="1164634253" build="1164497695"/>
          <size package="1117167" archive="2902308"/>
          <base-version epoch="0" ver="1.1.1" rel="24"/>
          <base-version epoch="0" ver="1.1.1" rel="24.6"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/xine-lib-1.1.1-24_24.10.i586.delta.rpm"/>
          <checksum type="sha">7259091afabea5b495797a067d6aae40af9a6983</checksum>
          <time file="1164634256" build="1164497695"/>
          <size package="63679" archive="0"/>
          <base-version epoch="0" ver="1.1.1" rel="24" md5sum="da5e0f646e643ef3bcf48ab76cf10073" buildtime="1146573178" sequence_info="xine-lib-1.1.1-24-86a349d0eaacb0961dc8e6a8839ff27ccf20"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/xine-lib-1.1.1-24.6_24.10.i586.delta.rpm"/>
          <checksum type="sha">9ad1ca8c566d4f63294c9b1579142f5729f014a9</checksum>
          <time file="1164634259" build="1164497695"/>
          <size package="1053705" archive="0"/>
          <base-version epoch="0" ver="1.1.1" rel="24.6" md5sum="90c03d34c9e00dfc9068b34c848f52bc" buildtime="1150137108" sequence_info="xine-lib-1.1.1-24.6-cd0bfe489f1a115efd0c864dbdf6079f8b20"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>xine-lib</name>
      <arch>ppc</arch>
      <version epoch="0" ver="1.1.1" rel="24.10"/>
      <checksum type="sha" pkgid="YES">0b158f7c98029e5620a79eeec38300b05b7165c8</checksum>
      <time file="1164581204" build="1164576836"/>
      <size package="2621425" installed="5732997" archive="5760768"/>
      <location href="rpm/ppc/xine-lib-1.1.1-24.10.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="xine-lib" epoch="0" ver="1.1.1" rel="24.10" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="xine-lib"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/xine-lib-1.1.1-24.10.ppc.patch.rpm"/>
          <checksum type="sha">7da57e2dd31bef8238403facfabb0ef404aa4466</checksum>
          <time file="1164634268" build="1164576836"/>
          <size package="1044283" archive="3005664"/>
          <base-version epoch="0" ver="1.1.1" rel="24"/>
          <base-version epoch="0" ver="1.1.1" rel="24.6"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/xine-lib-1.1.1-24_24.10.ppc.delta.rpm"/>
          <checksum type="sha">7db9ca0749b0ca222817ae05f10d18f495278f73</checksum>
          <time file="1164634272" build="1164576836"/>
          <size package="72346" archive="0"/>
          <base-version epoch="0" ver="1.1.1" rel="24" md5sum="0a06d85b3376d92b09db3a360d8b1347" buildtime="1146581479" sequence_info="xine-lib-1.1.1-24-2346204ce7759b750a1840516eb504c5dd20"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>xine-lib</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.1.1" rel="24.10"/>
      <checksum type="sha" pkgid="YES">64cfae2a5e2d9cc4334ed32976411795dd5e7a53</checksum>
      <time file="1164581974" build="1164478779"/>
      <size package="2582005" installed="5309465" archive="5337408"/>
      <location href="rpm/x86_64/xine-lib-1.1.1-24.10.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="xine-lib" epoch="0" ver="1.1.1" rel="24.10" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="xine-lib"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/xine-lib-1.1.1-24.10.x86_64.patch.rpm"/>
          <checksum type="sha">290d0aa52bced59405033d996585e408ec8bbdc5</checksum>
          <time file="1164634279" build="1164478779"/>
          <size package="975011" archive="2582296"/>
          <base-version epoch="0" ver="1.1.1" rel="24"/>
          <base-version epoch="0" ver="1.1.1" rel="24.6"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/xine-lib-1.1.1-24_24.10.x86_64.delta.rpm"/>
          <checksum type="sha">56360df29b02c5078628becd9518e5eb9b9c18ef</checksum>
          <time file="1164634282" build="1164478779"/>
          <size package="67711" archive="0"/>
          <base-version epoch="0" ver="1.1.1" rel="24" md5sum="8d7a95ad938986bc9b98c009a39786a5" buildtime="1146571486" sequence_info="xine-lib-1.1.1-24-5ab29425e24f63cbf34b05e0919dd78bdd20"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>xine-lib-32bit</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.1.1" rel="24.10"/>
      <checksum type="sha" pkgid="YES">68376a5fd5fece46d8b63e56aeb8e1216c7e665d</checksum>
      <time file="1164580798" build="1164497866"/>
      <size package="1107012" installed="2889312" archive="2903160"/>
      <location href="rpm/x86_64/xine-lib-32bit-1.1.1-24.10.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="xine-lib-32bit" epoch="0" ver="1.1.1" rel="24.10" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="xine-lib-32bit"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/xine-lib-32bit-1.1.1-24.10.x86_64.patch.rpm"/>
          <checksum type="sha">01aa232b9bab0a5e92eaad6fe454b3b27ad90614</checksum>
          <time file="1164634289" build="1164497866"/>
          <size package="1107169" archive="2902308"/>
          <base-version epoch="0" ver="1.1.1" rel="24"/>
          <base-version epoch="0" ver="1.1.1" rel="24.6"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/xine-lib-32bit-1.1.1-24_24.10.x86_64.delta.rpm"/>
          <checksum type="sha">d29af9e069910c202d0424ccb6bb351ea2ce7568</checksum>
          <time file="1164634290" build="1164497866"/>
          <size package="52621" archive="0"/>
          <base-version epoch="0" ver="1.1.1" rel="24" md5sum="1f5834906b168ec2c2d5ee14094661e4" buildtime="1146573242" sequence_info="xine-lib-32bit-1.1.1-24-6a4857f1cd44adea2552c151edf597a3da10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/xine-lib-32bit-1.1.1-24.6_24.10.x86_64.delta.rpm"/>
          <checksum type="sha">0683cc729016ca040728fd6f23fb265b918f5f61</checksum>
          <time file="1164634291" build="1164497866"/>
          <size package="27611" archive="0"/>
          <base-version epoch="0" ver="1.1.1" rel="24.6" md5sum="94a6074d37fd3c8a1b5b7777755beaed" buildtime="1150137165" sequence_info="xine-lib-32bit-1.1.1-24.6-d2aae739b5c530b38e7afd140c7ec1d1da10"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>xine-lib-64bit</name>
      <arch>ppc</arch>
      <version epoch="0" ver="1.1.1" rel="24.10"/>
      <checksum type="sha" pkgid="YES">550c49775416e484f2259ce7a2f7fae3edea6c2d</checksum>
      <time file="1164633950" build="1164633667"/>
      <size package="964397" installed="3110464" archive="3121752"/>
      <location href="rpm/ppc/xine-lib-64bit-1.1.1-24.10.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="xine-lib-64bit" epoch="0" ver="1.1.1" rel="24.10" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="xine-lib-64bit"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/xine-lib-64bit-1.1.1-24.10.ppc.patch.rpm"/>
          <checksum type="sha">cc746c5ca8af9e16c1b115f1bc314fdd2b4f17e2</checksum>
          <time file="1164634294" build="1164633667"/>
          <size package="964632" archive="3121040"/>
          <base-version epoch="0" ver="1.1.1" rel="23"/>
          <base-version epoch="0" ver="1.1.1" rel="24.6"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/xine-lib-64bit-1.1.1-23_24.10.ppc.delta.rpm"/>
          <checksum type="sha">83b74f85fd7ace218f08e9da08d2ce414d3e6e2c</checksum>
          <time file="1164634296" build="1164633667"/>
          <size package="57791" archive="0"/>
          <base-version epoch="0" ver="1.1.1" rel="23" md5sum="49a8503a0b7749cc67e0d856ccc6ae52" buildtime="1146284215" sequence_info="xine-lib-64bit-1.1.1-23-7423aa00a948c5ba02502fe8f9929833c810"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
