<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="3958fddec2f2300979834d9248cbb5ee"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp2-finch-5573"
    timestamp="1220458241"
    engine="1.0">
  <yum:name>sdkp2-finch</yum:name>
  <summary lang="en">Security update for pidgin, gaim and finch</summary>
  <summary lang="de">Security update for pidgin, gaim and finch</summary>
  <description lang="en">- specially crafted MSN SLP messages could cause an integer
  overflow in pidgin. Attackers could potentially exploit
  that to execute arbitrary code (CVE-2008-2927).

- overly long file names in MSN file transfers could crash
  pidgin (CVE-2008-2955).

- SSL certifcates were not verfied. Therefore piding didn't
  notice faked certificates (CVE-2008-3532)

Additionally a problem was fixed that prevented gaim
clients from  connecting to the ICQ network after a server
change on July 1st  2008.
</description>
  <description lang="de">- specially crafted MSN SLP messages could cause an integer
  overflow in pidgin. Attackers could potentially exploit
  that to execute arbitrary code (CVE-2008-2927).

- overly long file names in MSN file transfers could crash
  pidgin (CVE-2008-2955).

- SSL certifcates were not verfied. Therefore piding didn't
  notice faked certificates (CVE-2008-3532)

Additionally a problem was fixed that prevented gaim
clients from  connecting to the ICQ network after a server
change on July 1st  2008.
</description>
  <yum:version ver="5573" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="finch" epoch="0" ver="2.3.1" rel="10.9" flags="EQ"/>
    <rpm:entry kind="atom" name="finch-devel" epoch="0" ver="2.3.1" rel="10.9" flags="EQ"/>
    <rpm:entry kind="atom" name="libpurple" epoch="0" ver="2.3.1" rel="10.9" flags="EQ"/>
    <rpm:entry kind="atom" name="libpurple-devel" epoch="0" ver="2.3.1" rel="10.9" flags="EQ"/>
    <rpm:entry kind="atom" name="pidgin" epoch="0" ver="2.3.1" rel="10.9" flags="EQ"/>
    <rpm:entry kind="atom" name="pidgin-devel" epoch="0" ver="2.3.1" rel="10.9" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>finch</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.3.1" rel="10.9"/>
      <checksum type="sha" pkgid="YES">eae7b5243adf3568ca22261a80aa2bd60c962155</checksum>
      <time file="1220459457" build="1220458241"/>
      <size package="183650" installed="444346" archive="446180"/>
      <location xml:base="media://#1" href="suse/i586/finch-2.3.1-10.19.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="finch" epoch="0" ver="2.3.1" rel="10.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="finch"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>finch-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.3.1" rel="10.9"/>
      <checksum type="sha" pkgid="YES">2e1f28cd88580ed18266d4638f785b359da34ea3</checksum>
      <time file="1220459457" build="1220458241"/>
      <size package="40323" installed="167758" archive="175152"/>
      <location xml:base="media://#1" href="suse/i586/finch-devel-2.3.1-10.19.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="finch-devel" epoch="0" ver="2.3.1" rel="10.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="finch-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>libpurple</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.3.1" rel="10.9"/>
      <checksum type="sha" pkgid="YES">3661ab37d6839ae721465665f672ceb7b22eb84c</checksum>
      <time file="1220459457" build="1220458241"/>
      <size package="4905519" installed="17926329" archive="17961604"/>
      <location xml:base="media://#1" href="suse/i586/libpurple-2.3.1-10.19.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="libpurple" epoch="0" ver="2.3.1" rel="10.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="libpurple"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>libpurple-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.3.1" rel="10.9"/>
      <checksum type="sha" pkgid="YES">0a2cb36ce088bf417e1ef52fe2ad32f049f44633</checksum>
      <time file="1220459458" build="1220458241"/>
      <size package="137602" installed="806779" archive="817672"/>
      <location xml:base="media://#1" href="suse/i586/libpurple-devel-2.3.1-10.19.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="libpurple-devel" epoch="0" ver="2.3.1" rel="10.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="libpurple-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>pidgin</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.3.1" rel="10.9"/>
      <checksum type="sha" pkgid="YES">8b9615b1a8640176e7ca8d3115e6c85ac94cba75</checksum>
      <time file="1220459458" build="1220458241"/>
      <size package="1575746" installed="2727130" archive="2814844"/>
      <location xml:base="media://#1" href="suse/i586/pidgin-2.3.1-10.19.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="pidgin" epoch="0" ver="2.3.1" rel="10.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="pidgin"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>pidgin-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.3.1" rel="10.9"/>
      <checksum type="sha" pkgid="YES">fb52ba28ca3b3b68ca4225c1935bfad182934a28</checksum>
      <time file="1220459458" build="1220458241"/>
      <size package="50981" installed="219887" archive="227876"/>
      <location xml:base="media://#1" href="suse/i586/pidgin-devel-2.3.1-10.19.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="pidgin-devel" epoch="0" ver="2.3.1" rel="10.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="pidgin-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
