<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="50f32d80d39a4dd5b12549f50b2c99b4"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp3-finch-6861"
    timestamp="1266590161"
    engine="1.0">
  <yum:name>sledp3-finch</yum:name>
  <summary lang="en">Security update for pidgin</summary>
  <summary lang="de">Security update for pidgin</summary>
  <description lang="en">
This update of pidgin fixes various security vulnerabilities



 CVE-2010-0013: CVSS v2 Base Score: 4.3: Path Traversal (CWE-22)
  Remote file disclosure vulnerability by using the MSN protocol.
 CVE-2010-0277: CVSS v2 Base Score: 4.9: Resource Management Errors (CWE-399)
   MSN protocol plugin in libpurple allowed remote attackers to cause a denial of service (memory corruption) at least.
 CVE-2010-0420
  Same nick names in XMPP MUC lead to a crash in finch.
 CVE-2010-0423
  A remote denial of service attack (resource consumption) is possible by sending an IM with a lot of smilies in it.


</description>
  <description lang="de">This update of pidgin fixes various security vulnerabilities
- CVE-2010-0013: CVSS v2 Base Score: 4.3: Path Traversal
  (CWE-22) Remote file disclosure vulnerability by using
  the MSN protocol.
- CVE-2010-0277: CVSS v2 Base Score: 4.9: Resource
  Management Errors (CWE-399) MSN protocol plugin in
  libpurple allowed remote attackers to cause a denial of
  service (memory corruption) at least.
- CVE-2010-0420 Same nick names in XMPP MUC lead to a crash
  in finch.
- CVE-2010-0423 A remote denial of service attack (resource
  consumption) is possible by sending an IM with a lot of
  smilies in it.
</description>
  <yum:version ver="6861" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="finch" epoch="0" ver="2.6.6" rel="0.4.1" flags="EQ"/>
    <rpm:entry kind="atom" name="libpurple" epoch="0" ver="2.6.6" rel="0.4.1" flags="EQ"/>
    <rpm:entry kind="atom" name="pidgin" epoch="0" ver="2.6.6" rel="0.4.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>finch</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.6.6" rel="0.4.1"/>
      <checksum type="sha" pkgid="YES">b48412849a7fbfd9b2cc5a84fc624fe48d3705cb</checksum>
      <time file="1266590193" build="1266590161"/>
      <size package="232902" installed="590930" archive="593076"/>
      <location xml:base="media://#1" href="suse/x86_64/finch-2.6.6-0.4.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="finch" epoch="0" ver="2.6.6" rel="0.4.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="finch"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>libpurple</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.6.6" rel="0.4.1"/>
      <checksum type="sha" pkgid="YES">9642cf161ed5171e8c21e952b469685d7b704b32</checksum>
      <time file="1266590193" build="1266590161"/>
      <size package="6601037" installed="26362677" archive="25460368"/>
      <location xml:base="media://#1" href="suse/x86_64/libpurple-2.6.6-0.4.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="libpurple" epoch="0" ver="2.6.6" rel="0.4.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="libpurple"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>pidgin</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.6.6" rel="0.4.1"/>
      <checksum type="sha" pkgid="YES">230d4675e47def27ae78434045ab7bfadbd4dd17</checksum>
      <time file="1266590194" build="1266590161"/>
      <size package="1905209" installed="3955692" archive="4070276"/>
      <location xml:base="media://#1" href="suse/x86_64/pidgin-2.6.6-0.4.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="pidgin" epoch="0" ver="2.6.6" rel="0.4.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="pidgin"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
