<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="460569ff05f9f1dd9cb03924fffb9bda"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="fetchmail-2608"
    timestamp="1170809208"
    engine="1.0">
  <yum:name>fetchmail</yum:name>
  <summary lang="en">Security update for fetchmail</summary>
  <summary lang="de">Security update for fetchmail</summary>
  <description lang="en">Three security issues have been fixed in fetchmail:

CVE-2005-4348: fetchmail when configured for multidrop
mode, allows remote attackers to cause a denial of service
(application crash) by sending messages without headers
from upstream mail servers.

CVE-2006-5867: fetchmail did not properly enforce TLS and
may transmit cleartext passwords over unsecured links if
certain circumstances occur, which allows remote attackers
to obtain sensitive information via man-in-the-middle
(MITM) attacks.

CVE-2006-5974: fetchmail when refusing a message delivered
via the mda option, allowed remote attackers to cause a
denial of service (crash) via unknown vectors that trigger
a NULL pointer dereference when calling the ferror or
fflush functions.
</description>
  <description lang="de">Three security issues have been fixed in fetchmail:

CVE-2005-4348: fetchmail when configured for multidrop
mode, allows remote attackers to cause a denial of service
(application crash) by sending messages without headers
from upstream mail servers.

CVE-2006-5867: fetchmail did not properly enforce TLS and
may transmit cleartext passwords over unsecured links if
certain circumstances occur, which allows remote attackers
to obtain sensitive information via man-in-the-middle
(MITM) attacks.

CVE-2006-5974: fetchmail when refusing a message delivered
via the mda option, allowed remote attackers to cause a
denial of service (crash) via unknown vectors that trigger
a NULL pointer dereference when calling the ferror or
fflush functions.
</description>
  <yum:version ver="2608" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="fetchmail" epoch="0" ver="6.3.2" rel="15.8" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>fetchmail</name>
      <arch>i586</arch>
      <version epoch="0" ver="6.3.2" rel="15.8"/>
      <checksum type="sha" pkgid="YES">155606e112ad98e3d79ad33ade9ca5ea0452ac09</checksum>
      <time file="1171533739" build="1170809208"/>
      <size package="725029" installed="1971878" archive="1983928"/>
      <location xml:base="media://#1" href="suse/i586/fetchmail-6.3.2-15.8.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="fetchmail" epoch="0" ver="6.3.2" rel="15.8" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="fetchmail"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
