<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="80929169daa1efe3e09dfd990377bfc6"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp3-tomcat5-6839"
    timestamp="1265821550"
    engine="1.0">
  <yum:name>sdkp3-tomcat5</yum:name>
  <summary lang="en">Security update for Tomcat 5</summary>
  <description lang="en">
This update of tomcat5/6 fixes:



 CVE-2009-2693: CVSS v2 Base Score: 5.8
  CVE-2009-2902: CVSS v2 Base Score: 4.3
  Directory traversal vulnerability allowed remote attackers
  to create or overwrite arbitrary files/dirs with a specially crafted
  WAR file.
 CVE-2009-2901: CVSS v2 Base Score: 4.3
  When autoDeploy is enabled the autodeployment process deployed
  appBase files that remain from a failed undeploy, which might allow
  remote attackers to bypass intended authentication requirements
  via HTTP requests.


</description>
  <yum:version ver="6839" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="tomcat5" epoch="0" ver="5.5.27" rel="0.9.1" flags="EQ"/>
    <rpm:entry kind="atom" name="tomcat5-admin-webapps" epoch="0" ver="5.5.27" rel="0.9.1" flags="EQ"/>
    <rpm:entry kind="atom" name="tomcat5-webapps" epoch="0" ver="5.5.27" rel="0.9.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>tomcat5</name>
      <arch>noarch</arch>
      <version epoch="0" ver="5.5.27" rel="0.9.1"/>
      <checksum type="sha" pkgid="YES">0bf7a81013506afef6eed245f4970d6c7e65d087</checksum>
      <time file="1265821571" build="1265821550"/>
      <size package="2836800" installed="3160334" archive="3178504"/>
      <location xml:base="media://#1" href="suse/noarch/tomcat5-5.5.27-0.9.1.noarch.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="tomcat5" epoch="0" ver="5.5.27" rel="0.9.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="tomcat5"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>tomcat5-admin-webapps</name>
      <arch>noarch</arch>
      <version epoch="0" ver="5.5.27" rel="0.9.1"/>
      <checksum type="sha" pkgid="YES">2f4220eb4d6d835d01d832907a19032027767f2e</checksum>
      <time file="1265821572" build="1265821550"/>
      <size package="1328282" installed="1731288" archive="1750004"/>
      <location xml:base="media://#1" href="suse/noarch/tomcat5-admin-webapps-5.5.27-0.9.1.noarch.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="tomcat5-admin-webapps" epoch="0" ver="5.5.27" rel="0.9.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="tomcat5-admin-webapps"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>tomcat5-webapps</name>
      <arch>noarch</arch>
      <version epoch="0" ver="5.5.27" rel="0.9.1"/>
      <checksum type="sha" pkgid="YES">12b2b75f5f0b74ea3856ec2d149c62ee30c19d79</checksum>
      <time file="1265821572" build="1265821550"/>
      <size package="969826" installed="7993245" archive="8159872"/>
      <location xml:base="media://#1" href="suse/noarch/tomcat5-webapps-5.5.27-0.9.1.noarch.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="tomcat5-webapps" epoch="0" ver="5.5.27" rel="0.9.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="tomcat5-webapps"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
