<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="7d7b4291a8a6bf4a9378e00b2c4c8f7f"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdk-mailman-2174"
    timestamp="1160777742"
    engine="1.0">
  <yum:name>sdk-mailman</yum:name>
  <summary lang="en">Security update for mailman</summary>
  <summary lang="de">Security update for mailman</summary>
  <description lang="en">This update of mailman fixes the following security issues:
- A malicious user could visit a specially crafted URI and
  inject an apparent log message into Mailman's error log
  which might induce an unsuspecting administrator to visit
  a phishing site. This has been blocked. Thanks to Moritz
  Naumann for its discovery.
- Fixed denial of service attack which can be caused by
  some standards-breaking RFC 2231 formatted headers.
  CVE-2006-2941.
- Several cross-site scripting issues have been fixed.
  Thanks to Moritz Naumann for their discovery.
  CVE-2006-3636
- Fixed an unexploitable format string vulnerability.
  Discovery and fix by Karl Chen. Analysis of
  non-exploitability by Martin 'Joey' Schulze. Also thanks
  go to Lionel Elie Mamane. CVE-2006-2191.
</description>
  <description lang="de">This update of mailman fixes the following security issues:
- A malicious user could visit a specially crafted URI and
  inject an apparent log message into Mailman's error log
  which might induce an unsuspecting administrator to visit
  a phishing site. This has been blocked. Thanks to Moritz
  Naumann for its discovery.
- Fixed denial of service attack which can be caused by
  some standards-breaking RFC 2231 formatted headers.
  CVE-2006-2941.
- Several cross-site scripting issues have been fixed.
  Thanks to Moritz Naumann for their discovery.
  CVE-2006-3636
- Fixed an unexploitable format string vulnerability.
  Discovery and fix by Karl Chen. Analysis of
  non-exploitability by Martin 'Joey' Schulze. Also thanks
  go to Lionel Elie Mamane. CVE-2006-2191.
</description>
  <yum:version ver="2174" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="mailman" epoch="0" ver="2.1.7" rel="15.5" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mailman</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.1.7" rel="15.5"/>
      <checksum type="sha" pkgid="YES">c7959b425622b903b35e49e63a41b24821509e39</checksum>
      <time file="1161015115" build="1160777742"/>
      <size package="5528504" installed="27236187" archive="27591408"/>
      <location xml:base="media://#1" href="suse/i586/mailman-2.1.7-15.5.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mailman" epoch="0" ver="2.1.7" rel="15.5" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mailman"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
