<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="b34d7a9ca735ddbfa9cdb9385b65c744"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="clamav-2391"
    timestamp="1165972267"
    engine="1.0">
  <yum:name>clamav</yum:name>
  <summary lang="en">clamav security update</summary>
  <summary lang="de">clamav Sicherheitsupdate</summary>
  <description lang="en">This update to ClamAV version 0.88.7 fixes various bugs:

CVE-2006-5874: Clam AntiVirus (ClamAV) allows remote
attackers to cause a denial of service (crash) via a
malformed base64-encoded MIME attachment that triggers a
null pointer dereference.

CVE-2006-6481: Clam AntiVirus (ClamAV) 0.88.6 allowed
remote attackers to cause a denial of service (stack
overflow and application crash) by wrapping many layers of
multipart/mixed content around a document, a different
vulnerability than CVE-2006-5874 and CVE-2006-6406.

CVE-2006-6406: Clam AntiVirus (ClamAV) 0.88.6 allowed
remote attackers to bypass virus detection by inserting
invalid characters into base64 encoded content in a
multipart/mixed MIME file, as demonstrated with the EICAR
test file.
</description>
  <description lang="de">Dieses Update von ClamAV auf Version 0.88.7 behebt mehrere
Probleme:

CVE-2006-5874: ClamAV erlaubte entfernten Angreifern einen
Absturz zu verursachen indem eine falsch formatiertes
base64 Attachment angefügt wurde, das dann einen NULL
Pointer Referenz auslöste.

CVE-2006-6481: ClamAV erlaubte entfernten Angreifern einen
Absturz (durch Stacküberlauf) auszulösen, indem viele
verschachtelte multipart/mixed Inhalte übergeben worden.
Dieses ist ein von CVE-2006-5874 und CVE-2006-6406
unterschiedliches Problem.

CVE-2006-6406: ClamAV erlaubte entfernten Angreifern die
Virenerkennung zu umgehen indem ungültige Zeichen in einen
Base64 verschlüsselten Inhalt in einem multipart/mixed
Anhang übergeben worden, wie zb mit der EICAR
Testvirusdatei demonstriert.

</description>
  <yum:version ver="2391" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="clamav" epoch="0" ver="0.88.7" rel="1.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>clamav</name>
      <arch>i586</arch>
      <version epoch="0" ver="0.88.7" rel="1.1"/>
      <checksum type="sha" pkgid="YES">b4615ed86936c6d924b6d1bf4057b7d285224536</checksum>
      <time file="1166028047" build="1165972267"/>
      <size package="1074209" installed="2234054" archive="2269152"/>
      <location href="rpm/i586/clamav-0.88.7-1.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="clamav" epoch="0" ver="0.88.7" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="clamav"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/clamav-0.88.7-1.1.i586.patch.rpm"/>
          <checksum type="sha">a3440c094337d969f66d6e9419efc86f30aee520</checksum>
          <time file="1166031114" build="1165972267"/>
          <size package="781700" archive="1893368"/>
          <base-version epoch="0" ver="0.88.6" rel="9"/>
        </patchrpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>clamav</name>
      <arch>ppc</arch>
      <version epoch="0" ver="0.88.7" rel="1.1"/>
      <checksum type="sha" pkgid="YES">443e5e19203c8a68fd093d2c8d1bbd9ee0e81b94</checksum>
      <time file="1166028254" build="1165972528"/>
      <size package="1093842" installed="2328754" archive="2363852"/>
      <location href="rpm/ppc/clamav-0.88.7-1.1.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="clamav" epoch="0" ver="0.88.7" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="clamav"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/clamav-0.88.7-1.1.ppc.patch.rpm"/>
          <checksum type="sha">a575ec9ce419868b63ed926b7d9759842acb8bb7</checksum>
          <time file="1166031125" build="1165972528"/>
          <size package="787969" archive="1988068"/>
          <base-version epoch="0" ver="0.88.6" rel="9"/>
        </patchrpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>clamav</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.88.7" rel="1.1"/>
      <checksum type="sha" pkgid="YES">680ec6dcece0a828e6c1eb0a77ff02069b759fc1</checksum>
      <time file="1166027823" build="1165973088"/>
      <size package="1077599" installed="2285818" archive="2320932"/>
      <location href="rpm/x86_64/clamav-0.88.7-1.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="clamav" epoch="0" ver="0.88.7" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="clamav"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/clamav-0.88.7-1.1.x86_64.patch.rpm"/>
          <checksum type="sha">1de08e56d05bc9f337a37766d5c9dc857b94d8f7</checksum>
          <time file="1166031136" build="1165973088"/>
          <size package="789559" archive="1945148"/>
          <base-version epoch="0" ver="0.88.6" rel="9"/>
        </patchrpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
