<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="92960116ff6e91e1d8bc4b0cc8af4ea7"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp2-tomcat5-5955"
    timestamp="1232636043"
    engine="1.0">
  <yum:name>sdkp2-tomcat5</yum:name>
  <summary lang="en">Security update for Tomcat 5</summary>
  <summary lang="de">Security update for Tomcat 5</summary>
  <description lang="en">Two old but not yet fixed security issues in tomcat5 were
spotted and are fixed by this update:

CVE-2006-3835: Apache Tomcat 5 before 5.5.17 allows remote
attackers to list directories via a semicolon (;) preceding
a filename with a mapped extension, as demonstrated by URLs
ending with /;index.jsp and /;help.do.

Cross-site scripting (XSS) vulnerability in certain
applications using Apache Tomcat allowed remote attackers
to inject arbitrary web script or HTML via crafted
&quot;Accept-Language headers that do not conform to RFC 2616&quot;.

These issues were rated &quot;low&quot; by the Apache Tomcat team.
</description>
  <description lang="de">Two old but not yet fixed security issues in tomcat5 were
spotted and are fixed by this update:

CVE-2006-3835: Apache Tomcat 5 before 5.5.17 allows remote
attackers to list directories via a semicolon (;) preceding
a filename with a mapped extension, as demonstrated by URLs
ending with /;index.jsp and /;help.do.

Cross-site scripting (XSS) vulnerability in certain
applications using Apache Tomcat allowed remote attackers
to inject arbitrary web script or HTML via crafted
&quot;Accept-Language headers that do not conform to RFC 2616&quot;.

These issues were rated &quot;low&quot; by the Apache Tomcat team.
</description>
  <yum:version ver="5955" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="tomcat5" epoch="0" ver="5.0.30" rel="27.35" flags="EQ"/>
    <rpm:entry kind="atom" name="tomcat5-admin-webapps" epoch="0" ver="5.0.30" rel="27.35" flags="EQ"/>
    <rpm:entry kind="atom" name="tomcat5-webapps" epoch="0" ver="5.0.30" rel="27.35" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>tomcat5</name>
      <arch>noarch</arch>
      <version epoch="0" ver="5.0.30" rel="27.35"/>
      <checksum type="sha" pkgid="YES">ef66743b3cf4e68fa90daaf074b915da90b3fab5</checksum>
      <time file="1232638988" build="1232636043"/>
      <size package="2370317" installed="2670769" archive="2687364"/>
      <location xml:base="media://#1" href="suse/noarch/tomcat5-5.0.30-27.40.noarch.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="tomcat5" epoch="0" ver="5.0.30" rel="27.35" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="tomcat5"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>tomcat5-admin-webapps</name>
      <arch>noarch</arch>
      <version epoch="0" ver="5.0.30" rel="27.35"/>
      <checksum type="sha" pkgid="YES">fb9a66a70bb7deb7ec3fdb87c1cd9dc84ca7c0be</checksum>
      <time file="1232638988" build="1232636043"/>
      <size package="1263782" installed="1593248" archive="1611268"/>
      <location xml:base="media://#1" href="suse/noarch/tomcat5-admin-webapps-5.0.30-27.40.noarch.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="tomcat5-admin-webapps" epoch="0" ver="5.0.30" rel="27.35" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="tomcat5-admin-webapps"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>tomcat5-webapps</name>
      <arch>noarch</arch>
      <version epoch="0" ver="5.0.30" rel="27.35"/>
      <checksum type="sha" pkgid="YES">8fe01512368e739720b0aeddce95a93218391f05</checksum>
      <time file="1232638988" build="1232636043"/>
      <size package="1947353" installed="30426515" archive="30793580"/>
      <location xml:base="media://#1" href="suse/noarch/tomcat5-webapps-5.0.30-27.40.noarch.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="tomcat5-webapps" epoch="0" ver="5.0.30" rel="27.35" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="tomcat5-webapps"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
