<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="99ff98254c77739e0c421ee90228d262"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="clamav-2390"
    timestamp="1166008528"
    engine="1.0">
  <yum:name>clamav</yum:name>
  <summary lang="en">Security update for clamav</summary>
  <summary lang="de">Security update for clamav</summary>
  <description lang="en">This update to ClamAV version 0.88.7 fixes various bugs:

CVE-2006-5874: Clam AntiVirus (ClamAV) allows remote
attackers to cause a denial of service (crash) via a
malformed base64-encoded MIME attachment that triggers a
null pointer dereference.

CVE-2006-6481: Clam AntiVirus (ClamAV) 0.88.6 allowed
remote attackers to cause a denial of service (stack
overflow and application crash) by wrapping many layers of
multipart/mixed content around a document, a different
vulnerability than CVE-2006-5874 and CVE-2006-6406.

CVE-2006-6406: Clam AntiVirus (ClamAV) 0.88.6 allowed
remote attackers to bypass virus detection by inserting
invalid characters into base64 encoded content in a
multipart/mixed MIME file, as demonstrated with the EICAR
test file.


</description>
  <description lang="de">This update to ClamAV version 0.88.7 fixes various bugs:

CVE-2006-5874: Clam AntiVirus (ClamAV) allows remote
attackers to cause a denial of service (crash) via a
malformed base64-encoded MIME attachment that triggers a
null pointer dereference.

CVE-2006-6481: Clam AntiVirus (ClamAV) 0.88.6 allowed
remote attackers to cause a denial of service (stack
overflow and application crash) by wrapping many layers of
multipart/mixed content around a document, a different
vulnerability than CVE-2006-5874 and CVE-2006-6406.

CVE-2006-6406: Clam AntiVirus (ClamAV) 0.88.6 allowed
remote attackers to bypass virus detection by inserting
invalid characters into base64 encoded content in a
multipart/mixed MIME file, as demonstrated with the EICAR
test file.


</description>
  <yum:version ver="2390" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="clamav" epoch="0" ver="0.88.7" rel="1.2" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>clamav</name>
      <arch>i586</arch>
      <version epoch="0" ver="0.88.7" rel="1.2"/>
      <checksum type="sha" pkgid="YES">d15774e57e80dca2c7788e0ce7d7199e4a88a7d6</checksum>
      <time file="1166028229" build="1166008528"/>
      <size package="1076640" installed="2218947" archive="2254048"/>
      <location xml:base="media://#1" href="suse/i586/clamav-0.90.2-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="clamav" epoch="0" ver="0.88.7" rel="1.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="clamav"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
