<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="237f45f6ed85d324a9d45daadd2e66fd"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp3-tar-6922"
    timestamp="1268355738"
    engine="1.0">
  <yum:name>sledp3-tar</yum:name>
  <summary lang="en">Security update for tar</summary>
  <description lang="en">A malicious remote tape server could cause a buffer overflow in tar.
In order to exploit that an attacker would have to trick the victim
to extract a file that causes tar to open a connection to the rmt
server (CVE-2010-0624). It's advisable to always use tar's
--force-local local option to avoid such tricks.
</description>
  <yum:version ver="6922" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="tar" epoch="0" ver="1.15.1" rel="23.16.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>tar</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.15.1" rel="23.16.1"/>
      <checksum type="sha" pkgid="YES">e8d7b1653a705de60492c5ba8e7877dfd8c5492d</checksum>
      <time file="1268355745" build="1268355738"/>
      <size package="654067" installed="1508746" archive="1515668"/>
      <location xml:base="media://#1" href="suse/x86_64/tar-1.15.1-23.16.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="tar" epoch="0" ver="1.15.1" rel="23.16.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="tar"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
