<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="6dc784ab0d16da7d3d1e152e4331e82a"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="100">
  <id>bluez-audio</id>
  <title>bluez security update</title>
  <release>openSUSE 11.0</release>
  <issued date="1216171535"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=404963" id="404963" title="bug number 404963" type="bugzilla"/>
  </references>
  <description>Missing length checks in bluez-libs could cause a buffer
overflow in Bluetooth applications. Malicious bluetooth
devices could potentially exploit that to execute arbitrary
code (CVE-2008-2374).

Note: The source code of each application that uses
vulnerable functions of bluez-libs needs to be adapted to
actually fix the problem.
</description>
  <pkglist>
    <collection>
        <package name="bluez-audio" arch="i586" version="3.32" release="8.2">
          <filename>bluez-audio-3.32-8.2.i586.rpm</filename>
        </package>
        <package name="bluez-cups" arch="i586" version="3.32" release="8.2">
          <filename>bluez-cups-3.32-8.2.i586.rpm</filename>
        </package>
        <package name="bluez-cups" arch="ppc" version="3.32" release="8.2">
          <filename>bluez-cups-3.32-8.2.ppc.rpm</filename>
        </package>
        <package name="bluez-cups" arch="x86_64" version="3.32" release="8.2">
          <filename>bluez-cups-3.32-8.2.x86_64.rpm</filename>
        </package>
        <package name="bluez-libs" arch="i586" version="3.32" release="3.2">
          <filename>bluez-libs-3.32-3.2.i586.rpm</filename>
        </package>
        <package name="bluez-libs" arch="ppc" version="3.32" release="3.2">
          <filename>bluez-libs-3.32-3.2.ppc.rpm</filename>
        </package>
        <package name="bluez-libs" arch="x86_64" version="3.32" release="3.2">
          <filename>bluez-libs-3.32-3.2.x86_64.rpm</filename>
        </package>
        <package name="bluez-test" arch="i586" version="3.32" release="8.2">
          <filename>bluez-test-3.32-8.2.i586.rpm</filename>
        </package>
        <package name="bluez-test" arch="ppc" version="3.32" release="8.2">
          <filename>bluez-test-3.32-8.2.ppc.rpm</filename>
        </package>
        <package name="bluez-test" arch="x86_64" version="3.32" release="8.2">
          <filename>bluez-test-3.32-8.2.x86_64.rpm</filename>
        </package>
        <package name="bluez-utils" arch="i586" version="3.32" release="8.2">
          <filename>bluez-utils-3.32-8.2.i586.rpm</filename>
        </package>
        <package name="bluez-utils" arch="ppc" version="3.32" release="8.2">
          <filename>bluez-utils-3.32-8.2.ppc.rpm</filename>
        </package>
        <package name="bluez-utils" arch="x86_64" version="3.32" release="8.2">
          <filename>bluez-utils-3.32-8.2.x86_64.rpm</filename>
        </package>
        <package name="obex-data-server" arch="i586" version="0.3" release="26.2">
          <filename>obex-data-server-0.3-26.2.i586.rpm</filename>
        </package>
        <package name="obex-data-server" arch="ppc" version="0.3" release="26.2">
          <filename>obex-data-server-0.3-26.2.ppc.rpm</filename>
        </package>
        <package name="obex-data-server" arch="x86_64" version="0.3" release="26.2">
          <filename>obex-data-server-0.3-26.2.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
