<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="9fc2c5a4de44f225a0a6359cd98eb972"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="java-1_4_2-sun-3843"
    timestamp="1183635016"
    engine="1.0">
  <yum:name>java-1_4_2-sun</yum:name>
  <summary lang="en">java-1_4_2-sun: Security update to 1.4.2 patchlevel 15</summary>
  <summary lang="de">java-1_4_2-sun: Security update auf 1.4.2 Patchlevel 15</summary>
  <description lang="en">The Sun JAVA JDK 1.4.2 was upgraded to release 15 to fix
various bugs, including the following security bugs:

CVE-2007-2788 / CVE-2007-3004: Integer overflow in the
embedded ICC profile image parser in Sun Java Development
Kit (JDK), allows remote attackers to execute arbitrary
code or cause a denial of service (JVM crash) via a crafted
JPEG or BMP file.

CVE-2007-2789 / CVE-2007-3005: The BMP image parser in Sun
Java Development Kit (JDK), on Unix/Linux systems, allows
remote attackers to trigger the opening of arbitrary local
files via a crafted BMP file, which causes a denial of
service (system hang) in certain cases such as /dev/tty,
and has other unspecified impact.

CVE-2007-0243: Buffer overflow in Sun JDK and Java Runtime
Environment (JRE) allows applets to gain privileges via a
GIF image with a block with a 0 width field, which triggers
memory corruption.
</description>
  <description lang="de">Das Sun JAVA JDK 1.4.2 wurde auf Release 15 gebracht, die
unter anderem folgende Sicherheitsprobleme behebt:

CVE-2007-2788 / CVE-2007-3004: Integerüberlauf im embedded
ICC Profil Parser erlaubt entfernten Angreifern potentiell
beliebigen Code auszuführen oder einen Absturz
hervorzurufen, in dem bestimmte JPEG oder BMP Dateien
bearbeitet werden.

CVE-2007-2789 / CVE-2007-3005: Der BMP Bildparser im Sun
JDK auf UNIX/Linux Systemen erlaubt entfernten Angreifern
das Öffnen einer lokalen Datei durch ein spezielles BMP
Bild, die zum Hängen der JVM oder ähnlichen Effekten führen
kann.

CVE-2007-0243: Pufferüberlauf im Sun JRE erlaubt entfernten
Angreifern durch ein präpariertes GIF Bild mit einem Block
mit Breite 0 Memory Corruption auszulösen, die evt zu einer
Privilege Escalation führen kann.
</description>
  <yum:version ver="3843" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="java-1_4_2-sun" epoch="0" ver="1.4.2_update15" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-alsa" epoch="0" ver="1.4.2_update15" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-demo" epoch="0" ver="1.4.2_update15" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-devel" epoch="0" ver="1.4.2_update15" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-jdbc" epoch="0" ver="1.4.2_update15" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-plugin" epoch="0" ver="1.4.2_update15" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-src" epoch="0" ver="1.4.2_update15" rel="0.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2_update15" rel="0.1"/>
      <checksum type="sha" pkgid="YES">0196e9bf2e150743652794703438285d37e78ac8</checksum>
      <time file="1183717494" build="1183635016"/>
      <size package="18787408" installed="59988543" archive="60118272"/>
      <location href="rpm/i586/java-1_4_2-sun-1.4.2_update15-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun" epoch="0" ver="1.4.2_update15" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-1.4.2_update15-0.1.i586.patch.rpm"/>
          <checksum type="sha">93c3fcea0347a395d671600c565d973a734c2d13</checksum>
          <time file="1183720353" build="1183635016"/>
          <size package="18732079" archive="60057236"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-1.4.2_update12_1.4.2_update15-17_0.1.i586.delta.rpm"/>
          <checksum type="sha">35ec2b57f23d059383ea5e48dcdc94d7f5d2522d</checksum>
          <time file="1183720396" build="1183635016"/>
          <size package="1281280" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17" md5sum="d9c2ce9d86d93fe2f5622c9a037e29d4" buildtime="1164480922" sequence_info="java-1_4_2-sun-1.4.2_update12-17-d7413a5ce7a6bef04aaba7815902693cbb21aa15ee66c1"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-1.4.2_update13_1.4.2_update15-3.1_0.1.i586.delta.rpm"/>
          <checksum type="sha">6ca829a1753f91c75c765e6b518062930d8a099f</checksum>
          <time file="1183720434" build="1183635016"/>
          <size package="1002774" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1" md5sum="81c565319263d8c7c58e9e01d13f704a" buildtime="1166716905" sequence_info="java-1_4_2-sun-1.4.2_update13-3.1-df929de884c966a2a0855b8ca7c91918e32bf11aa15fe6"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-alsa</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2_update15" rel="0.1"/>
      <checksum type="sha" pkgid="YES">cd43a59881ac9dcb81bbadbc405022c22cc4a12c</checksum>
      <time file="1183717494" build="1183635016"/>
      <size package="22079" installed="26584" archive="26892"/>
      <location href="rpm/i586/java-1_4_2-sun-alsa-1.4.2_update15-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-alsa" epoch="0" ver="1.4.2_update15" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-alsa"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-alsa-1.4.2_update15-0.1.i586.patch.rpm"/>
          <checksum type="sha">dcd131270526d84baf142e0f38b5f84cd33e7205</checksum>
          <time file="1183720443" build="1183635016"/>
          <size package="22245" archive="26892"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-alsa-1.4.2_update12_1.4.2_update15-17_0.1.i586.delta.rpm"/>
          <checksum type="sha">d5ada0ca1266e320d495087680985ce6aba2c63e</checksum>
          <time file="1183720443" build="1183635016"/>
          <size package="11359" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17" md5sum="8745b1ae55f13a8fbc6799c225f27db3" buildtime="1164480922" sequence_info="java-1_4_2-sun-alsa-1.4.2_update12-17-3c1fae20ee368ac3fe4bca3fc119398410"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-alsa-1.4.2_update13_1.4.2_update15-3.1_0.1.i586.delta.rpm"/>
          <checksum type="sha">a167a8fba0e6c156107c927e7c01f13c4e92f9e7</checksum>
          <time file="1183720443" build="1183635016"/>
          <size package="11360" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1" md5sum="3d80e29e86da461750d4f81aebf468ff" buildtime="1166716905" sequence_info="java-1_4_2-sun-alsa-1.4.2_update13-3.1-ecf1c49b0ba70b7f77b3c5b20a4075b710"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-demo</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2_update15" rel="0.1"/>
      <checksum type="sha" pkgid="YES">4fc255ed704067eb5edbfd7280d1319c8357cceb</checksum>
      <time file="1183717495" build="1183635016"/>
      <size package="6318971" installed="9468096" archive="9650812"/>
      <location href="rpm/i586/java-1_4_2-sun-demo-1.4.2_update15-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-demo" epoch="0" ver="1.4.2_update15" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-demo"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-demo-1.4.2_update15-0.1.i586.patch.rpm"/>
          <checksum type="sha">76508683f4f503e035aed92f2626723ee54874eb</checksum>
          <time file="1183720452" build="1183635016"/>
          <size package="4501986" archive="4662808"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-demo-1.4.2_update13_1.4.2_update15-3.1_0.1.i586.delta.rpm"/>
          <checksum type="sha">bd8fb7f492660c56822647dfc5dcc739e283051e</checksum>
          <time file="1183720458" build="1183635016"/>
          <size package="131863" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1" md5sum="f3b3678952a3633c93e6f314c16695c1" buildtime="1166716905" sequence_info="java-1_4_2-sun-demo-1.4.2_update13-3.1-233b82c9148ccb70ba9fbfd34c4baf9cecf1"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2_update15" rel="0.1"/>
      <checksum type="sha" pkgid="YES">7917ed47ef1cbc5f401bc27ea14ced8f836478ac</checksum>
      <time file="1183717495" build="1183635016"/>
      <size package="2906843" installed="8021647" archive="8032316"/>
      <location href="rpm/i586/java-1_4_2-sun-devel-1.4.2_update15-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-devel" epoch="0" ver="1.4.2_update15" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-devel-1.4.2_update15-0.1.i586.patch.rpm"/>
          <checksum type="sha">148146315c2558992bf0dc3b0d6c678834b7accf</checksum>
          <time file="1183720467" build="1183635016"/>
          <size package="2812438" archive="7939408"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-devel-1.4.2_update12_1.4.2_update15-17_0.1.i586.delta.rpm"/>
          <checksum type="sha">7dee17ef793fb830ceffbed1c4eeea5e946d349b</checksum>
          <time file="1183720471" build="1183635016"/>
          <size package="209417" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17" md5sum="cb56af07b21e6b8d8660f2376b6b566c" buildtime="1164480922" sequence_info="java-1_4_2-sun-devel-1.4.2_update12-17-8c6255f7f833beb78dc8a3daf67c062ad55d10"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-devel-1.4.2_update13_1.4.2_update15-3.1_0.1.i586.delta.rpm"/>
          <checksum type="sha">6bf0cda7669eef2aa7891e8c3300ca5a5b1e4673</checksum>
          <time file="1183720474" build="1183635016"/>
          <size package="284678" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1" md5sum="9167d98e8dc65249a9d07060f6a74765" buildtime="1166716905" sequence_info="java-1_4_2-sun-devel-1.4.2_update13-3.1-3c9cf72f751e9014c24a513370efb983d5"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-jdbc</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2_update15" rel="0.1"/>
      <checksum type="sha" pkgid="YES">1298d9c09bbc8f1f252e551748bae125c0c8c148</checksum>
      <time file="1183717495" build="1183635016"/>
      <size package="24317" installed="50016" archive="50324"/>
      <location href="rpm/i586/java-1_4_2-sun-jdbc-1.4.2_update15-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-jdbc" epoch="0" ver="1.4.2_update15" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-jdbc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-jdbc-1.4.2_update15-0.1.i586.patch.rpm"/>
          <checksum type="sha">0adabd60b12195c57b7fabd224c42f3838e3b919</checksum>
          <time file="1183720476" build="1183635016"/>
          <size package="24485" archive="50324"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-jdbc-1.4.2_update12_1.4.2_update15-17_0.1.i586.delta.rpm"/>
          <checksum type="sha">627b17f93a5b9bd9c499a8582f017e55ab023c7d</checksum>
          <time file="1183720476" build="1183635016"/>
          <size package="11313" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17" md5sum="723910672f3f75aa5197ef3cad95f408" buildtime="1164480922" sequence_info="java-1_4_2-sun-jdbc-1.4.2_update12-17-401dfdd0080741ff2220a2bc7f7507d410"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-jdbc-1.4.2_update13_1.4.2_update15-3.1_0.1.i586.delta.rpm"/>
          <checksum type="sha">3f5dbda492786b2deb98c00819eb39368c993bd4</checksum>
          <time file="1183720476" build="1183635016"/>
          <size package="11308" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1" md5sum="0abe0b6df38b505babea046b29ec984f" buildtime="1166716905" sequence_info="java-1_4_2-sun-jdbc-1.4.2_update13-3.1-c069b934ff34e39959d947e57db8088f10"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-plugin</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2_update15" rel="0.1"/>
      <checksum type="sha" pkgid="YES">e46298b9a688bc3e061ab9922bd69efaf277ff76</checksum>
      <time file="1183717495" build="1183635016"/>
      <size package="796161" installed="2637914" archive="2643928"/>
      <location href="rpm/i586/java-1_4_2-sun-plugin-1.4.2_update15-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-plugin" epoch="0" ver="1.4.2_update15" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-plugin"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-plugin-1.4.2_update15-0.1.i586.patch.rpm"/>
          <checksum type="sha">25116a2f6e4d829d9fbc8110b6376e9e8501d261</checksum>
          <time file="1183720480" build="1183635016"/>
          <size package="796147" archive="2643628"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-plugin-1.4.2_update12_1.4.2_update15-17_0.1.i586.delta.rpm"/>
          <checksum type="sha">395a0aca572f2971a2ac012cf5eb27783a19b710</checksum>
          <time file="1183720481" build="1183635016"/>
          <size package="20079" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update12" rel="17" md5sum="752a6dce7b45f4ac8b34d9fe6eae89b7" buildtime="1164480922" sequence_info="java-1_4_2-sun-plugin-1.4.2_update12-17-b5c2d31fb7bbb7a7725be9202c5991d2c312"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-plugin-1.4.2_update13_1.4.2_update15-3.1_0.1.i586.delta.rpm"/>
          <checksum type="sha">55490981e2d7b4cd3a08b1b8f5aa76fa9756daf2</checksum>
          <time file="1183720482" build="1183635016"/>
          <size package="19972" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1" md5sum="d0adc2abc1aaa827c50f3d537bf81278" buildtime="1166716905" sequence_info="java-1_4_2-sun-plugin-1.4.2_update13-3.1-51cb507343096050e077723a536a19aec312"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-src</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2_update15" rel="0.1"/>
      <checksum type="sha" pkgid="YES">954822cfb1de66442d0df64da62647304229c805</checksum>
      <time file="1183717496" build="1183635016"/>
      <size package="10945978" installed="11521827" archive="11522116"/>
      <location href="rpm/i586/java-1_4_2-sun-src-1.4.2_update15-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-src" epoch="0" ver="1.4.2_update15" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-src"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/java-1_4_2-sun-src-1.4.2_update15-0.1.i586.patch.rpm"/>
          <checksum type="sha">d34052ad796a9312b535b5939e1a93bdfd623627</checksum>
          <time file="1183720501" build="1183635016"/>
          <size package="10946100" archive="11522116"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/java-1_4_2-sun-src-1.4.2_update13_1.4.2_update15-3.1_0.1.i586.delta.rpm"/>
          <checksum type="sha">fde9672f33ff0204a7be9fe913b37d265888e8b4</checksum>
          <time file="1183720510" build="1183635016"/>
          <size package="521057" archive="0"/>
          <base-version epoch="0" ver="1.4.2_update13" rel="3.1" md5sum="8386c144d54f9a37f73ebcec9b7a81d9" buildtime="1166716905" sequence_info="java-1_4_2-sun-src-1.4.2_update13-3.1-6647dbfc3db64d46d4acc8e25fabaea610"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
