<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="71fe824ad8d14f886e3c15a6be27fc14"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdk-xine-lib-2307"
    timestamp="1164484620"
    engine="1.0">
  <yum:name>sdk-xine-lib</yum:name>
  <summary lang="en">Security update for xine-lib</summary>
  <summary lang="de">Security update for xine-lib</summary>
  <description lang="en">Multiple buffer overflows were fixed in the XINE decoder
libraries, which could be used by attackers to crash
players or potentially execute code.


CVE-2006-4799: Buffer overflow in ffmpeg for xine-lib
before 1.1.2 might allow context-dependent attackers to
execute arbitrary code via a crafted AVI file and &quot;bad
indexes&quot;.

CVE-2006-4800: Multiple buffer overflows in libavcodec in
ffmpeg before 0.4.9_p20060530 allow remote attackers to
cause a denial of service or possibly execute arbitrary
code via multiple unspecified vectors in (1) dtsdec.c, (2)
vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6)
tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c,
(11) smacker.c, (12) snow.c, and (13) tta.c.
</description>
  <description lang="de">Multiple buffer overflows were fixed in the XINE decoder
libraries, which could be used by attackers to crash
players or potentially execute code.


CVE-2006-4799: Buffer overflow in ffmpeg for xine-lib
before 1.1.2 might allow context-dependent attackers to
execute arbitrary code via a crafted AVI file and &quot;bad
indexes&quot;.

CVE-2006-4800: Multiple buffer overflows in libavcodec in
ffmpeg before 0.4.9_p20060530 allow remote attackers to
cause a denial of service or possibly execute arbitrary
code via multiple unspecified vectors in (1) dtsdec.c, (2)
vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6)
tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c,
(11) smacker.c, (12) snow.c, and (13) tta.c.
</description>
  <yum:version ver="2307" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="xine-lib" epoch="0" ver="1.1.1" rel="24.10" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>xine-lib</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.1.1" rel="24.10"/>
      <checksum type="sha" pkgid="YES">29a2a40dd08b234714c140a731651dd4753102db</checksum>
      <time file="1164589945" build="1164484620"/>
      <size package="2698366" installed="5627393" archive="5657540"/>
      <location xml:base="media://#1" href="suse/i586/xine-lib-1.1.1-24.20.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="xine-lib" epoch="0" ver="1.1.1" rel="24.10" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="xine-lib"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
