<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="254e16f8849045414f4aad7942b25e58"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp1-ethereal-3888"
    timestamp="1184254737"
    engine="1.0">
  <yum:name>sdkp1-ethereal</yum:name>
  <summary lang="en">Security update for ethereal</summary>
  <summary lang="de">Security update for ethereal</summary>
  <description lang="en">Various security problems were fixed in the wireshark
0.99.6 release, which were backported to ethereal
(predecessor of wireshark):

CVE-2007-3389: Wireshark allowed remote attackers to cause
a denial of service (crash) via a crafted chunked encoding
in an HTTP response, possibly related to a zero-length
payload.

CVE-2007-3390: Wireshark when running on certain systems,
allowed remote attackers to cause a denial of service
(crash) via crafted iSeries capture files that trigger a
SIGTRAP.

CVE-2007-3391: Wireshark allowed remote attackers to cause
a denial of service (memory consumption) via a malformed
DCP ETSI packet that triggers an infinite loop.

CVE-2007-3392: Wireshark allowed remote attackers to cause
a denial of service via malformed (1) SSL or (2) MMS
packets that trigger an infinite loop.

CVE-2007-3393: Off-by-one error in the DHCP/BOOTP dissector
in Wireshark allowed remote attackers to cause a denial of
service (crash) via crafted DHCP-over-DOCSIS packets.
</description>
  <description lang="de">Various security problems were fixed in the wireshark
0.99.6 release, which were backported to ethereal
(predecessor of wireshark):

CVE-2007-3389: Wireshark allowed remote attackers to cause
a denial of service (crash) via a crafted chunked encoding
in an HTTP response, possibly related to a zero-length
payload.

CVE-2007-3390: Wireshark when running on certain systems,
allowed remote attackers to cause a denial of service
(crash) via crafted iSeries capture files that trigger a
SIGTRAP.

CVE-2007-3391: Wireshark allowed remote attackers to cause
a denial of service (memory consumption) via a malformed
DCP ETSI packet that triggers an infinite loop.

CVE-2007-3392: Wireshark allowed remote attackers to cause
a denial of service via malformed (1) SSL or (2) MMS
packets that trigger an infinite loop.

CVE-2007-3393: Off-by-one error in the DHCP/BOOTP dissector
in Wireshark allowed remote attackers to cause a denial of
service (crash) via crafted DHCP-over-DOCSIS packets.
</description>
  <yum:version ver="3888" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="ethereal-devel" epoch="0" ver="0.10.14" rel="16.16" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>ethereal-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.10.14" rel="16.16"/>
      <checksum type="sha" pkgid="YES">652f5dcaa63e37da518b2ba6f6c6f494b4b2aa98</checksum>
      <time file="1184328476" build="1184254737"/>
      <size package="123748" installed="467015" archive="475236"/>
      <location xml:base="media://#1" href="suse/x86_64/ethereal-devel-0.10.14-16.24.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="ethereal-devel" epoch="0" ver="0.10.14" rel="16.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="ethereal-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
