<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="60a7eebd98be5aca456464d144eb5065"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="399">
  <id>dbg111-jhead</id>
  <title>jhead: various security problems were fixed</title>
  <release>openSUSE 11.1</release>
  <issued date="1231376516"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=435979" id="435979" title="bug number 435979" type="bugzilla"/>
  </references>
  <description>This update of jhead fixes several security problems:
- CVE-2008-4575: buffer overflow in DoCommand()
- CVE-2008-4639: local symlink attack
- CVE-2008-4640: DoCommand() allowed deletion of arbitrary
  files
- CVE-2008-4641: execution of arbitrary shell commands in
  DoCommand()
</description>
  <pkglist>
    <collection>
        <package name="jhead" arch="i586" version="2.84" release="1.24.1">
          <filename>jhead-2.84-1.24.1.i586.rpm</filename>
        </package>
        <package name="jhead-debuginfo" arch="ppc" version="2.84" release="1.24.1">
          <filename>jhead-debuginfo-2.84-1.24.1.ppc.rpm</filename>
        </package>
        <package name="jhead-debuginfo" arch="x86_64" version="2.84" release="1.24.1">
          <filename>jhead-debuginfo-2.84-1.24.1.x86_64.rpm</filename>
        </package>
        <package name="jhead-debugsource" arch="ppc" version="2.84" release="1.24.1">
          <filename>jhead-debugsource-2.84-1.24.1.ppc.rpm</filename>
        </package>
        <package name="jhead-debugsource" arch="x86_64" version="2.84" release="1.24.1">
          <filename>jhead-debugsource-2.84-1.24.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
