<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="3fafef103902137d0bea93863e650bdb"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="gpg-2994"
    timestamp="1174672588"
    engine="1.0">
  <yum:name>gpg</yum:name>
  <summary lang="en">Security update for gpg</summary>
  <summary lang="de">Security update for gpg</summary>
  <description lang="en">When printing a text stream with a GPG signature it was
possible for an attacker to create a stream with &quot;unsigned
text, signed text&quot; where both unsigned and signed text
would be shown without distinction which one was signed and
which part wasn't.

This is tracked by the Mitre CVE ID CVE-2007-1263.

The update introduces a new option
--allow-multiple-messages to print out such messages in the
future, by default it only prints and handles the first one.
</description>
  <description lang="de">When printing a text stream with a GPG signature it was
possible for an attacker to create a stream with &quot;unsigned
text, signed text&quot; where both unsigned and signed text
would be shown without distinction which one was signed and
which part wasn't.

This is tracked by the Mitre CVE ID CVE-2007-1263.

The update introduces a new option
--allow-multiple-messages to print out such messages in the
future, by default it only prints and handles the first one.
</description>
  <yum:version ver="2994" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="gpg" epoch="0" ver="1.4.2" rel="23.16" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>gpg</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2" rel="23.16"/>
      <checksum type="sha" pkgid="YES">2234f523662c0aeda2ff5a4f07b8cc6a18202b88</checksum>
      <time file="1174906417" build="1174672588"/>
      <size package="1567918" installed="4769971" archive="4779956"/>
      <location xml:base="media://#1" href="suse/i586/gpg-1.4.2-23.16.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="gpg" epoch="0" ver="1.4.2" rel="23.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="gpg"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
