<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="37e6149ffa4539f63a70576decf83a8b"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp1-apache2-4669"
    timestamp="1194654856"
    engine="1.0">
  <yum:name>sdkp1-apache2</yum:name>
  <summary lang="en">Security update for apache2</summary>
  <summary lang="de">Security update for apache2</summary>
  <description lang="en">Several bugs were fixed in the Apache2 webserver:

These include the following security issues:

- CVE-2006-5752: mod_status: Fix a possible XSS attack
  against a site with a public server-status page and
  ExtendedStatus enabled, for browsers which perform
  charset &quot;detection&quot;.
- CVE-2007-1863: mod_cache: Prevent a segmentation fault if
  attributes are listed in a Cache-Control header without
  any value.
- CVE-2007-3304: prefork, worker, event MPMs: Ensure that
  the parent process cannot be forced to kill processes
  outside its process group.
- CVE-2007-3847: mod_proxy: Prevent reading past the end of
  a buffer when parsing date-related headers. PR 41144.
- CVE-2007-4465: mod_autoindex: Add in ContentType and
  Charset options to IndexOptions directive. This allows
  the admin to explicitly set the content-type and charset
  of the generated page.

and the following non-security issues:

- get_module_list: replace loadmodule.conf atomically
- Use File::Temp to create good tmpdir in logresolve.pl2
  (httpd-2.x.x-logresolve.patchs)
</description>
  <description lang="de">Several bugs were fixed in the Apache2 webserver:

These include the following security issues:

- CVE-2006-5752: mod_status: Fix a possible XSS attack
  against a site with a public server-status page and
  ExtendedStatus enabled, for browsers which perform
  charset &quot;detection&quot;.
- CVE-2007-1863: mod_cache: Prevent a segmentation fault if
  attributes are listed in a Cache-Control header without
  any value.
- CVE-2007-3304: prefork, worker, event MPMs: Ensure that
  the parent process cannot be forced to kill processes
  outside its process group.
- CVE-2007-3847: mod_proxy: Prevent reading past the end of
  a buffer when parsing date-related headers. PR 41144.
- CVE-2007-4465: mod_autoindex: Add in ContentType and
  Charset options to IndexOptions directive. This allows
  the admin to explicitly set the content-type and charset
  of the generated page.

and the following non-security issues:

- get_module_list: replace loadmodule.conf atomically
- Use File::Temp to create good tmpdir in logresolve.pl2
  (httpd-2.x.x-logresolve.patchs)
</description>
  <yum:version ver="4669" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="apache2" epoch="0" ver="2.2.3" rel="16.15" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-devel" epoch="0" ver="2.2.3" rel="16.15" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-doc" epoch="0" ver="2.2.3" rel="16.15" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-example-pages" epoch="0" ver="2.2.3" rel="16.15" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-prefork" epoch="0" ver="2.2.3" rel="16.15" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-worker" epoch="0" ver="2.2.3" rel="16.15" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.15"/>
      <checksum type="sha" pkgid="YES">b9efce2676e2639b8dc82cc799f78790d5806105</checksum>
      <time file="1194795264" build="1194654856"/>
      <size package="1033784" installed="2927672" archive="2997808"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-2.2.3-16.17.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2" epoch="0" ver="2.2.3" rel="16.15" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.15"/>
      <checksum type="sha" pkgid="YES">17b0218597671a9e766f4051a8ec4ea18629a40d</checksum>
      <time file="1194795265" build="1194654856"/>
      <size package="211603" installed="628141" archive="661932"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-devel-2.2.3-16.17.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-devel" epoch="0" ver="2.2.3" rel="16.15" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-doc</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.15"/>
      <checksum type="sha" pkgid="YES">67d52fe1ce8c7913bf5b8a06e3e1c43126b49ce4</checksum>
      <time file="1194795265" build="1194654856"/>
      <size package="1459134" installed="8757342" archive="8877632"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-doc-2.2.3-16.17.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-doc" epoch="0" ver="2.2.3" rel="16.15" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-doc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-example-pages</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.15"/>
      <checksum type="sha" pkgid="YES">734953e6fec698957b47198d1e3e7c1d316f5fac</checksum>
      <time file="1194795265" build="1194654856"/>
      <size package="94518" installed="10200" archive="11484"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-example-pages-2.2.3-16.17.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-example-pages" epoch="0" ver="2.2.3" rel="16.15" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-example-pages"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-prefork</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.15"/>
      <checksum type="sha" pkgid="YES">23a87b656e8928e2b1033dc03cea5088afc6a588</checksum>
      <time file="1194795265" build="1194654856"/>
      <size package="315877" installed="613736" archive="627720"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-prefork-2.2.3-16.17.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-prefork" epoch="0" ver="2.2.3" rel="16.15" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-prefork"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-worker</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.15"/>
      <checksum type="sha" pkgid="YES">f97eccf9cadcaa54da50f74fcd8af3fbca7ae5fd</checksum>
      <time file="1194795265" build="1194654856"/>
      <size package="322896" installed="631016" archive="644912"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-worker-2.2.3-16.17.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-worker" epoch="0" ver="2.2.3" rel="16.15" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-worker"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
