<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="9c400659d0ad61b54865449b76c3d803"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="slesp3-neon-6549"
    timestamp="1255348752"
    engine="1.0">
  <yum:name>slesp3-neon</yum:name>
  <summary lang="en">Security update for neon</summary>
  <summary lang="de">Security update for neon</summary>
  <description lang="en">neon did not properly handle embedded NUL characters in
X.509 certificates when comparing host names. Attackers
could exploit that to spoof SSL servers (CVE-2009-2408).

Specially crafted XML documents that contain a large number
of nested entity references could cause neon to consume
large amounts of CPU and memory (CVE-2009-2473).
</description>
  <description lang="de">neon did not properly handle embedded NUL characters in
X.509 certificates when comparing host names. Attackers
could exploit that to spoof SSL servers (CVE-2009-2408).

Specially crafted XML documents that contain a large number
of nested entity references could cause neon to consume
large amounts of CPU and memory (CVE-2009-2473).
</description>
  <yum:version ver="6549" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="neon" epoch="0" ver="0.24.7" rel="20.8.1" flags="EQ"/>
    <rpm:entry kind="atom" name="neon-32bit" epoch="0" ver="0.24.7" rel="20.8.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>neon</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.24.7" rel="20.8.1"/>
      <checksum type="sha" pkgid="YES">ead0e7d2ab9071c8616369a27578c760d8265c34</checksum>
      <time file="1255348757" build="1255348752"/>
      <size package="85407" installed="201887" archive="203500"/>
      <location xml:base="media://#1" href="suse/x86_64/neon-0.24.7-20.8.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="neon" epoch="0" ver="0.24.7" rel="20.8.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="neon"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>neon-32bit</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="0.24.7" rel="20.8.1"/>
      <checksum type="sha" pkgid="YES">77f16e3d9a2ffcdda0c71fbf2a7ae94d8f0f4711</checksum>
      <time file="1255349147" build="1255349146"/>
      <size package="55759" installed="108592" archive="109012"/>
      <location xml:base="media://#1" href="suse/x86_64/neon-32bit-0.24.7-20.8.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="neon-32bit" epoch="0" ver="0.24.7" rel="20.8.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="neon-32bit"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
