<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="43be6b4ccd31b0dd00d0838b3b5792f3"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp3-gpg2-7107"
    timestamp="1280335156"
    engine="1.0">
  <yum:name>sledp3-gpg2</yum:name>
  <summary lang="en">Security update for gpg2</summary>
  <description lang="en">
This update fixes a vulnerability of GnuPG2 to arbitrary code execution by 
context-dependent attackers due to reusing a freed pointer when verifying a 
signature or importing a certificate with many &quot;Subject Alternate Names&quot;. (
CVE-2010-2547 &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2547&gt; 
)

</description>
  <yum:version ver="7107" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="gpg2" epoch="0" ver="1.9.18" rel="17.21.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>gpg2</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.9.18" rel="17.21.1"/>
      <checksum type="sha" pkgid="YES">ae3edcccb8c6e11e9016b5c235975d59eec51f1c</checksum>
      <time file="1280335164" build="1280335156"/>
      <size package="772536" installed="1919169" archive="1923652"/>
      <location xml:base="media://#1" href="suse/i586/gpg2-1.9.18-17.21.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="gpg2" epoch="0" ver="1.9.18" rel="17.21.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="gpg2"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
