<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="3958fddec2f2300979834d9248cbb5ee"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp2-finch-5573"
    timestamp="1220458349"
    engine="1.0">
  <yum:name>sledp2-finch</yum:name>
  <summary lang="en">Security update for pidgin, gaim and finch</summary>
  <summary lang="de">Security update for pidgin, gaim and finch</summary>
  <description lang="en">- specially crafted MSN SLP messages could cause an integer
  overflow in pidgin. Attackers could potentially exploit
  that to execute arbitrary code (CVE-2008-2927).

- overly long file names in MSN file transfers could crash
  pidgin (CVE-2008-2955).

- SSL certifcates were not verfied. Therefore piding didn't
  notice faked certificates (CVE-2008-3532)

Additionally a problem was fixed that prevented gaim
clients from  connecting to the ICQ network after a server
change on July 1st  2008.
</description>
  <description lang="de">- specially crafted MSN SLP messages could cause an integer
  overflow in pidgin. Attackers could potentially exploit
  that to execute arbitrary code (CVE-2008-2927).

- overly long file names in MSN file transfers could crash
  pidgin (CVE-2008-2955).

- SSL certifcates were not verfied. Therefore piding didn't
  notice faked certificates (CVE-2008-3532)

Additionally a problem was fixed that prevented gaim
clients from  connecting to the ICQ network after a server
change on July 1st  2008.
</description>
  <yum:version ver="5573" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="finch" epoch="0" ver="2.3.1" rel="10.9" flags="EQ"/>
    <rpm:entry kind="atom" name="libpurple" epoch="0" ver="2.3.1" rel="10.9" flags="EQ"/>
    <rpm:entry kind="atom" name="pidgin" epoch="0" ver="2.3.1" rel="10.9" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>finch</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.3.1" rel="10.9"/>
      <checksum type="sha" pkgid="YES">b6d6c99c19686989b8e1a8d4743dc319a04c82ca</checksum>
      <time file="1220459560" build="1220458349"/>
      <size package="201053" installed="502662" archive="504512"/>
      <location xml:base="media://#1" href="suse/x86_64/finch-2.3.1-10.19.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="finch" epoch="0" ver="2.3.1" rel="10.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="finch"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>libpurple</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.3.1" rel="10.9"/>
      <checksum type="sha" pkgid="YES">d6ac5a7f757226aa7dbc487a573bea95746cd821</checksum>
      <time file="1220459560" build="1220458349"/>
      <size package="4995779" installed="18248393" archive="18283720"/>
      <location xml:base="media://#1" href="suse/x86_64/libpurple-2.3.1-10.19.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="libpurple" epoch="0" ver="2.3.1" rel="10.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="libpurple"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>pidgin</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.3.1" rel="10.9"/>
      <checksum type="sha" pkgid="YES">23bb80ad4a376a328943a600c1726ead70520536</checksum>
      <time file="1220459560" build="1220458349"/>
      <size package="1608553" installed="2806662" archive="2894412"/>
      <location xml:base="media://#1" href="suse/x86_64/pidgin-2.3.1-10.19.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="pidgin" epoch="0" ver="2.3.1" rel="10.9" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="pidgin"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
