<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="9d2407b0352245ff49a54784986b83a9"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="968">
  <id>dbg111-libapr-util1</id>
  <title>libapr-util1: fixed three denial of service bugs</title>
  <release>openSUSE 11.1</release>
  <issued date="1244455551"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=509825" id="509825" title="bug number 509825" type="bugzilla"/>
  </references>
  <description>This update of libapr-util1 fixes a memory consumption bug
in the XML parser that can cause a remote denial-of-service
vulnerability in applications using APR (WebDAV for
example) (CVE-2009-1955). Additionally a one byte buffer
overflow in function apr_brigade_vprintf() (CVE-2009-1956)
and buffer underflow in function apr_strmatch_precompile()
(CVE-2009-0023) was fixed too. Depending on the application
using this function it can lead to remote denial of service
or information leakage.
</description>
  <pkglist>
    <collection>
        <package name="libapr-util1-debuginfo" arch="i586" version="1.3.4" release="13.2.1">
          <filename>libapr-util1-debuginfo-1.3.4-13.2.1.i586.rpm</filename>
        </package>
        <package name="libapr-util1-debuginfo" arch="ppc" version="1.3.4" release="13.2.1">
          <filename>libapr-util1-debuginfo-1.3.4-13.2.1.ppc.rpm</filename>
        </package>
        <package name="libapr-util1-debuginfo" arch="x86_64" version="1.3.4" release="13.2.1">
          <filename>libapr-util1-debuginfo-1.3.4-13.2.1.x86_64.rpm</filename>
        </package>
        <package name="libapr-util1-debugsource" arch="i586" version="1.3.4" release="13.2.1">
          <filename>libapr-util1-debugsource-1.3.4-13.2.1.i586.rpm</filename>
        </package>
        <package name="libapr-util1-debugsource" arch="ppc" version="1.3.4" release="13.2.1">
          <filename>libapr-util1-debugsource-1.3.4-13.2.1.ppc.rpm</filename>
        </package>
        <package name="libapr-util1-debugsource" arch="x86_64" version="1.3.4" release="13.2.1">
          <filename>libapr-util1-debugsource-1.3.4-13.2.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
