<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="f99093a5bf235f2d2471722a946414f0"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp3-openssl-6655"
    timestamp="1258027952"
    engine="1.0">
  <yum:name>sledp3-openssl</yum:name>
  <summary lang="en">Security update for OpenSSL</summary>
  <summary lang="de">Security update for OpenSSL</summary>
  <description lang="en">The TLS/SSLv3 protocol as implemented in openssl prior to
this update was not able to associate data to a
renegotiated connection. This allowed man-in-the-middle
attackers to inject HTTP requests in a HTTPS session
without being noticed. For example Apache's mod_ssl was
vulnerable to this kind of attack because it uses openssl.
Please note that renegotiation will be disabled by this
update and may cause problems in some cases.
(CVE-2009-3555: CVSS v2 Base Score: 6.4)
</description>
  <description lang="de">The TLS/SSLv3 protocol as implemented in openssl prior to
this update was not able to associate data to a
renegotiated connection. This allowed man-in-the-middle
attackers to inject HTTP requests in a HTTPS session
without being noticed. For example Apache's mod_ssl was
vulnerable to this kind of attack because it uses openssl.
Please note that renegotiation will be disabled by this
update and may cause problems in some cases.
(CVE-2009-3555: CVSS v2 Base Score: 6.4)
</description>
  <yum:version ver="6655" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="openssl" epoch="0" ver="0.9.8a" rel="18.39.1" flags="EQ"/>
    <rpm:entry kind="atom" name="openssl-32bit" epoch="0" ver="0.9.8a" rel="18.39.1" flags="EQ"/>
    <rpm:entry kind="atom" name="openssl-devel" epoch="0" ver="0.9.8a" rel="18.39.1" flags="EQ"/>
    <rpm:entry kind="atom" name="openssl-devel-32bit" epoch="0" ver="0.9.8a" rel="18.39.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssl</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.9.8a" rel="18.39.1"/>
      <checksum type="sha" pkgid="YES">7fe97c77a32be6e9c5bf461d9e4f0e3df27c0b84</checksum>
      <time file="1258027969" build="1258027952"/>
      <size package="1247392" installed="2998930" archive="3018744"/>
      <location xml:base="media://#1" href="suse/x86_64/openssl-0.9.8a-18.39.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssl" epoch="0" ver="0.9.8a" rel="18.39.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssl"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssl-32bit</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.9.8a" rel="18.39.1"/>
      <checksum type="sha" pkgid="YES">d9b450b362fba1e556489b1ddb52447277395ab5</checksum>
      <time file="1258028340" build="1258028333"/>
      <size package="666265" installed="1582736" archive="1584540"/>
      <location xml:base="media://#1" href="suse/x86_64/openssl-32bit-0.9.8a-18.39.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssl-32bit" epoch="0" ver="0.9.8a" rel="18.39.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssl-32bit"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssl-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.9.8a" rel="18.39.1"/>
      <checksum type="sha" pkgid="YES">627c48535286cf18a66dcba5da7b029d0200c571</checksum>
      <time file="1258027969" build="1258027952"/>
      <size package="920931" installed="4761591" archive="4772728"/>
      <location xml:base="media://#1" href="suse/x86_64/openssl-devel-0.9.8a-18.39.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssl-devel" epoch="0" ver="0.9.8a" rel="18.39.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssl-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>openssl-devel-32bit</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.9.8a" rel="18.39.1"/>
      <checksum type="sha" pkgid="YES">2684103a3a37e6ee7b909609f4cc207e1a2d1f91</checksum>
      <time file="1258028340" build="1258028335"/>
      <size package="718197" installed="2682746" archive="2683440"/>
      <location xml:base="media://#1" href="suse/x86_64/openssl-devel-32bit-0.9.8a-18.39.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="openssl-devel-32bit" epoch="0" ver="0.9.8a" rel="18.39.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="openssl-devel-32bit"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
