<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="a9b0730b9578c91a3685d9913a531d37"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="mozilla-nss-2067"
    timestamp="1158188808"
    engine="1.0">
  <yum:name>mozilla-nss</yum:name>
  <summary lang="en">Security update for mozilla-nss,mozilla-nss-devel</summary>
  <summary lang="de">Security update for mozilla-nss,mozilla-nss-devel</summary>
  <description lang="en">A security problem in the SSL handling of the NSS libraries
was found:

If an RSA key with exponent 3 is used it may be possible to
forge a PKCS verify the certificate if they are not
checking for excess data in the RSA exponentiation result
of the signature.

This bug is tracked by the Mitre CVE ID CVE-2006-4340 and
CVE-2006-4341.
</description>
  <description lang="de">A security problem in the SSL handling of the NSS libraries
was found:

If an RSA key with exponent 3 is used it may be possible to
forge a PKCS verify the certificate if they are not
checking for excess data in the RSA exponentiation result
of the signature.

This bug is tracked by the Mitre CVE ID CVE-2006-4340 and
CVE-2006-4341.
</description>
  <yum:version ver="2067" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="mozilla-nss" epoch="0" ver="3.11" rel="21.7" flags="EQ"/>
    <rpm:entry kind="atom" name="mozilla-nss-devel" epoch="0" ver="3.11" rel="21.7" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mozilla-nss</name>
      <arch>i586</arch>
      <version epoch="0" ver="3.11" rel="21.7"/>
      <checksum type="sha" pkgid="YES">09ee1e301fbff833a27daba6bc42b5127bd0de3b</checksum>
      <time file="1158245650" build="1158188808"/>
      <size package="658063" installed="1514316" archive="1515520"/>
      <location xml:base="media://#1" href="suse/i586/mozilla-nss-3.11-21.7.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mozilla-nss" epoch="0" ver="3.11" rel="21.7" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mozilla-nss"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>mozilla-nss-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="3.11" rel="21.7"/>
      <checksum type="sha" pkgid="YES">173148253ec3fe7b59afc398bd78864fe4137b64</checksum>
      <time file="1158245652" build="1158188808"/>
      <size package="210010" installed="1165453" archive="1178936"/>
      <location xml:base="media://#1" href="suse/i586/mozilla-nss-devel-3.11-21.7.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="mozilla-nss-devel" epoch="0" ver="3.11" rel="21.7" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="mozilla-nss-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
