<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="50f32d80d39a4dd5b12549f50b2c99b4"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp3-finch-6861"
    timestamp="1266590788"
    engine="1.0">
  <yum:name>sdkp3-finch</yum:name>
  <summary lang="en">Security update for pidgin</summary>
  <summary lang="de">Security update for pidgin</summary>
  <description lang="en">
This update of pidgin fixes various security vulnerabilities



 CVE-2010-0013: CVSS v2 Base Score: 4.3: Path Traversal (CWE-22)
  Remote file disclosure vulnerability by using the MSN protocol.
 CVE-2010-0277: CVSS v2 Base Score: 4.9: Resource Management Errors (CWE-399)
   MSN protocol plugin in libpurple allowed remote attackers to cause a denial of service (memory corruption) at least.
 CVE-2010-0420
  Same nick names in XMPP MUC lead to a crash in finch.
 CVE-2010-0423
  A remote denial of service attack (resource consumption) is possible by sending an IM with a lot of smilies in it.


</description>
  <description lang="de">This update of pidgin fixes various security vulnerabilities
- CVE-2010-0013: CVSS v2 Base Score: 4.3: Path Traversal
  (CWE-22) Remote file disclosure vulnerability by using
  the MSN protocol.
- CVE-2010-0277: CVSS v2 Base Score: 4.9: Resource
  Management Errors (CWE-399) MSN protocol plugin in
  libpurple allowed remote attackers to cause a denial of
  service (memory corruption) at least.
- CVE-2010-0420 Same nick names in XMPP MUC lead to a crash
  in finch.
- CVE-2010-0423 A remote denial of service attack (resource
  consumption) is possible by sending an IM with a lot of
  smilies in it.
</description>
  <yum:version ver="6861" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="finch" epoch="0" ver="2.6.6" rel="0.4.1" flags="EQ"/>
    <rpm:entry kind="atom" name="finch-devel" epoch="0" ver="2.6.6" rel="0.4.1" flags="EQ"/>
    <rpm:entry kind="atom" name="libpurple" epoch="0" ver="2.6.6" rel="0.4.1" flags="EQ"/>
    <rpm:entry kind="atom" name="libpurple-devel" epoch="0" ver="2.6.6" rel="0.4.1" flags="EQ"/>
    <rpm:entry kind="atom" name="pidgin" epoch="0" ver="2.6.6" rel="0.4.1" flags="EQ"/>
    <rpm:entry kind="atom" name="pidgin-devel" epoch="0" ver="2.6.6" rel="0.4.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>finch</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.6" rel="0.4.1"/>
      <checksum type="sha" pkgid="YES">cf2c2ab9862d789594fa44a77cea836321b8c944</checksum>
      <time file="1266590912" build="1266590788"/>
      <size package="211310" installed="523838" archive="525964"/>
      <location xml:base="media://#1" href="suse/i586/finch-2.6.6-0.4.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="finch" epoch="0" ver="2.6.6" rel="0.4.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="finch"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>finch-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.6" rel="0.4.1"/>
      <checksum type="sha" pkgid="YES">b6bdfe7a9dfde7b0b19c1dd19f6d7d1f52e1de62</checksum>
      <time file="1266590912" build="1266590788"/>
      <size package="44595" installed="180483" archive="188336"/>
      <location xml:base="media://#1" href="suse/i586/finch-devel-2.6.6-0.4.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="finch-devel" epoch="0" ver="2.6.6" rel="0.4.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="finch-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>libpurple</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.6" rel="0.4.1"/>
      <checksum type="sha" pkgid="YES">36ba751f3441ac2daf85c218808ef05fbbd8ccbf</checksum>
      <time file="1266590912" build="1266590788"/>
      <size package="6524355" installed="26005949" archive="25071580"/>
      <location xml:base="media://#1" href="suse/i586/libpurple-2.6.6-0.4.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="libpurple" epoch="0" ver="2.6.6" rel="0.4.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="libpurple"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>libpurple-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.6" rel="0.4.1"/>
      <checksum type="sha" pkgid="YES">58052af8f3d7c59967d3038912ccaa5f9d8b8c7e</checksum>
      <time file="1266590913" build="1266590788"/>
      <size package="184760" installed="1195269" archive="1207860"/>
      <location xml:base="media://#1" href="suse/i586/libpurple-devel-2.6.6-0.4.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="libpurple-devel" epoch="0" ver="2.6.6" rel="0.4.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="libpurple-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>pidgin</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.6" rel="0.4.1"/>
      <checksum type="sha" pkgid="YES">c1220204fa5c38a044b063b19ed58f59cd7e8104</checksum>
      <time file="1266590913" build="1266590788"/>
      <size package="1870099" installed="3827528" archive="3942064"/>
      <location xml:base="media://#1" href="suse/i586/pidgin-2.6.6-0.4.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="pidgin" epoch="0" ver="2.6.6" rel="0.4.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="pidgin"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>pidgin-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.6" rel="0.4.1"/>
      <checksum type="sha" pkgid="YES">b8319dc3f970cb5dba31316217ee2283f3b2dad0</checksum>
      <time file="1266590913" build="1266590788"/>
      <size package="63007" installed="268878" archive="278284"/>
      <location xml:base="media://#1" href="suse/i586/pidgin-devel-2.6.6-0.4.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="pidgin-devel" epoch="0" ver="2.6.6" rel="0.4.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="pidgin-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
