<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="8de2d508793de8ff7df41d3b20495e54"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp3-apache2-6572"
    timestamp="1256057378"
    engine="1.0">
  <yum:name>sdkp3-apache2</yum:name>
  <summary lang="en">Security update for Apache 2</summary>
  <summary lang="de">Security update for Apache 2</summary>
  <description lang="en">This update of the Apache webserver fixes various security
issues:
- the option IncludesNOEXEC could be bypassed via .htaccess
  (CVE-2009-1195) 
- mod_proxy could run into an infinite loop when used as
  reverse  proxy (CVE-2009-1890) 
- mod_deflate continued to compress large files even after
  a network connection was closed, causing mod_deflate to
  consume large amounts of CPU (CVE-2009-1891)
- The ap_proxy_ftp_handler function in
  modules/proxy/proxy_ftp.c in the mod_proxy_ftp module
  allows remote FTP servers to cause a denial of service
  (NULL pointer dereference and child process crash) via a
  malformed reply to an EPSV command. (CVE-2009-3094)
- access restriction bypass in mod_proxy_ftp module
  (CVE-2009-3095)

Also a incompatibility between mod_cache and mod_rewrite
was fixed.
</description>
  <description lang="de">This update of the Apache webserver fixes various security
issues:
- the option IncludesNOEXEC could be bypassed via .htaccess
  (CVE-2009-1195) 
- mod_proxy could run into an infinite loop when used as
  reverse  proxy (CVE-2009-1890) 
- mod_deflate continued to compress large files even after
  a network connection was closed, causing mod_deflate to
  consume large amounts of CPU (CVE-2009-1891)
- The ap_proxy_ftp_handler function in
  modules/proxy/proxy_ftp.c in the mod_proxy_ftp module
  allows remote FTP servers to cause a denial of service
  (NULL pointer dereference and child process crash) via a
  malformed reply to an EPSV command. (CVE-2009-3094)
- access restriction bypass in mod_proxy_ftp module
  (CVE-2009-3095)

Also a incompatibility between mod_cache and mod_rewrite
was fixed.
</description>
  <yum:version ver="6572" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="apache2" epoch="0" ver="2.2.3" rel="16.28.1" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-devel" epoch="0" ver="2.2.3" rel="16.28.1" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-doc" epoch="0" ver="2.2.3" rel="16.28.1" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-example-pages" epoch="0" ver="2.2.3" rel="16.28.1" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-prefork" epoch="0" ver="2.2.3" rel="16.28.1" flags="EQ"/>
    <rpm:entry kind="atom" name="apache2-worker" epoch="0" ver="2.2.3" rel="16.28.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.28.1"/>
      <checksum type="sha" pkgid="YES">2f84d9076f0e9e3179162dc7e7ddc7e5fac8b0ec</checksum>
      <time file="1256057406" build="1256057378"/>
      <size package="1036401" installed="2921377" archive="2991372"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-2.2.3-16.28.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2" epoch="0" ver="2.2.3" rel="16.28.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.28.1"/>
      <checksum type="sha" pkgid="YES">50872465f42493ddd68b83f50254d8dc4e872062</checksum>
      <time file="1256057407" build="1256057378"/>
      <size package="214589" installed="628594" archive="662384"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-devel-2.2.3-16.28.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-devel" epoch="0" ver="2.2.3" rel="16.28.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-doc</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.28.1"/>
      <checksum type="sha" pkgid="YES">8a927cd8d56f602976c82a731c2276008a88d497</checksum>
      <time file="1256057407" build="1256057378"/>
      <size package="1462310" installed="8757342" archive="8877632"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-doc-2.2.3-16.28.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-doc" epoch="0" ver="2.2.3" rel="16.28.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-doc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-example-pages</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.28.1"/>
      <checksum type="sha" pkgid="YES">9bf244d55854d99fe80096f0d31ff343bbe56774</checksum>
      <time file="1256057408" build="1256057378"/>
      <size package="97430" installed="10200" archive="11484"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-example-pages-2.2.3-16.28.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-example-pages" epoch="0" ver="2.2.3" rel="16.28.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-example-pages"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-prefork</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.28.1"/>
      <checksum type="sha" pkgid="YES">a47f62ecd2c332949d857a76e2ba8d27cfe8c14c</checksum>
      <time file="1256057408" build="1256057378"/>
      <size package="318753" installed="612720" archive="626704"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-prefork-2.2.3-16.28.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-prefork" epoch="0" ver="2.2.3" rel="16.28.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-prefork"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>apache2-worker</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.2.3" rel="16.28.1"/>
      <checksum type="sha" pkgid="YES">ba3a5c05ff28232e99ea8a62ac4e0478a8f61084</checksum>
      <time file="1256057408" build="1256057378"/>
      <size package="325961" installed="630104" archive="644000"/>
      <location xml:base="media://#1" href="suse/x86_64/apache2-worker-2.2.3-16.28.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="apache2-worker" epoch="0" ver="2.2.3" rel="16.28.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="apache2-worker"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
