<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="45b2a4c2c1b2b8002e0b1a73efd03241"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdk-OpenOffice_org-2651"
    timestamp="1172753606"
    engine="1.0">
  <yum:name>sdk-OpenOffice_org</yum:name>
  <summary lang="en">Security update for OpenOffice_org</summary>
  <summary lang="de">Security update for OpenOffice_org</summary>
  <description lang="en">Following security problems were fixed in OpenOffice_org:

This update also brings OpenOffice_org to version 2.0.4.17,
same as SUSE Linux Enterprise Desktop 10 and contains lots
of bugfixes.

It also contains support for the Office XML converter hooks.

CVE-2007-0002: Various problems were fixed in the
Wordperfect converter library libwpd in OpenOffice_org
which could be used by remote attackers to potentially
execute code or crash OpenOffice_org.

CVE-2007-0238: A stack overflow in the StarCalc parser
could be used by remote attackers to potentially execute
code by supplying a crafted document.

CVE-2007-0239: A shell quoting problem when opening URLs
was fixed which could be used by remote attackers to
execute code by supplying a crafted document and making the
user click on an embedded link.
</description>
  <description lang="de">Following security problems were fixed in OpenOffice_org:

This update also brings OpenOffice_org to version 2.0.4.17,
same as SUSE Linux Enterprise Desktop 10 and contains lots
of bugfixes.

It also contains support for the Office XML converter hooks.

CVE-2007-0002: Various problems were fixed in the
Wordperfect converter library libwpd in OpenOffice_org
which could be used by remote attackers to potentially
execute code or crash OpenOffice_org.

CVE-2007-0238: A stack overflow in the StarCalc parser
could be used by remote attackers to potentially execute
code by supplying a crafted document.

CVE-2007-0239: A shell quoting problem when opening URLs
was fixed which could be used by remote attackers to
execute code by supplying a crafted document and making the
user click on an embedded link.
</description>
  <yum:version ver="2651" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="OpenOffice_org-mono" epoch="0" ver="2.0.4" rel="38.2.3" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>OpenOffice_org-mono</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.4" rel="38.2.3"/>
      <checksum type="sha" pkgid="YES">682da3f9402652dd89ccfda43971c4ec784ee643</checksum>
      <time file="1172757663" build="1172753606"/>
      <size package="329926" installed="867364" archive="868976"/>
      <location xml:base="media://#1" href="suse/i586/OpenOffice_org-mono-2.0.4-38.2.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="OpenOffice_org-mono" epoch="0" ver="2.0.4" rel="38.2.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="OpenOffice_org-mono"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
