<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="6e86bacfc257d2963aaba9406ac8d6cd"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp2-libapr-util1-6289"
    timestamp="1244455899"
    engine="1.0">
  <yum:name>sledp2-libapr-util1</yum:name>
  <summary lang="en">Security update for libapr-util1</summary>
  <summary lang="de">Security update for libapr-util1</summary>
  <description lang="en">This update of libapr-util1 fixes a memory consumption bug
in the XML parser that can cause a remote denial-of-service
vulnerability in applications using APR (WebDAV for
example) (CVE-2009-1955). Additionally a one byte buffer
overflow in function apr_brigade_vprintf() (CVE-2009-1956)
and buffer underflow in function apr_strmatch_precompile()
(CVE-2009-0023) was fixed too. Depending on the application
using this function it can lead to remote denial of service
or information leakage.
</description>
  <description lang="de">This update of libapr-util1 fixes a memory consumption bug
in the XML parser that can cause a remote denial-of-service
vulnerability in applications using APR (WebDAV for
example) (CVE-2009-1955). Additionally a one byte buffer
overflow in function apr_brigade_vprintf() (CVE-2009-1956)
and buffer underflow in function apr_strmatch_precompile()
(CVE-2009-0023) was fixed too. Depending on the application
using this function it can lead to remote denial of service
or information leakage.
</description>
  <yum:version ver="6289" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="libapr-util1" epoch="0" ver="1.2.2" rel="13.7" flags="EQ"/>
    <rpm:entry kind="atom" name="libapr-util1-devel" epoch="0" ver="1.2.2" rel="13.7" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>libapr-util1</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.2.2" rel="13.7"/>
      <checksum type="sha" pkgid="YES">7b5ebbdd71aa39f737618b6fc27bbcabdeb3d202</checksum>
      <time file="1244505703" build="1244455899"/>
      <size package="64773" installed="152930" archive="153984"/>
      <location xml:base="media://#1" href="suse/x86_64/libapr-util1-1.2.2-13.7.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="libapr-util1" epoch="0" ver="1.2.2" rel="13.7" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="libapr-util1"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>libapr-util1-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.2.2" rel="13.7"/>
      <checksum type="sha" pkgid="YES">f18252e7ddc7c087ba6d111c65e19c79131de45d</checksum>
      <time file="1244505704" build="1244455899"/>
      <size package="251179" installed="2261902" archive="2295676"/>
      <location xml:base="media://#1" href="suse/x86_64/libapr-util1-devel-1.2.2-13.7.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="libapr-util1-devel" epoch="0" ver="1.2.2" rel="13.7" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="libapr-util1-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
