<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="5a1747eaf95d5d08c71e444e9e421c5e"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp3-rubygem-actionpack-2_0-6874"
    timestamp="1266856978"
    engine="1.0">
  <yum:name>sdkp3-rubygem-actionpack-2_0</yum:name>
  <summary lang="en">Security update for rubygem-actionpack-2_0</summary>
  <summary lang="de">Security update for rubygem-actionpack-2_0</summary>
  <description lang="en">
This update of rubygems fixes two vulnerabilities:



 CVE-2008-7248: CVSS v2 Base Score: 4.3
  Rails CSRF protection can be bypassed by using special content-types
  for a HTTP request.
 CVE-2009-4214: CVSS v2 Base Score: 4.3
  The method strip_tags does not completely protect agains XSS attacks.


</description>
  <description lang="de">This update of rubygems fixes two vulnerabilities:
- CVE-2008-7248: CVSS v2 Base Score: 4.3 Rails CSRF
  protection can be bypassed by using special content-types
  for a HTTP request.
- CVE-2009-4214: CVSS v2 Base Score: 4.3 The method
  strip_tags does not completely protect agains XSS attacks.
</description>
  <yum:version ver="6874" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="rubygem-actionpack-2_0" epoch="0" ver="2.0.2" rel="0.9.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>rubygem-actionpack-2_0</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.0.2" rel="0.9.1"/>
      <checksum type="sha" pkgid="YES">2e21b68e75bac2a550fd58e1ace903f1ffa3f7e7</checksum>
      <time file="1266856991" build="1266856978"/>
      <size package="1878283" installed="6296971" archive="6766288"/>
      <location xml:base="media://#1" href="suse/x86_64/rubygem-actionpack-2_0-2.0.2-0.9.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="rubygem-actionpack-2_0" epoch="0" ver="2.0.2" rel="0.9.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="rubygem-actionpack-2_0"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
