<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="8446b116898e33640c58be9a9340fc91"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="1548">
  <id>dbg111-compat-openssl097g</id>
  <title>openssl: fix for possible man-in-the-middle attack due to renegotiation</title>
  <release>openSUSE 11.1</release>
  <issued date="1258105348"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=553641" id="553641" title="bug number 553641" type="bugzilla"/>
  </references>
  <description>The TLS/SSLv3 protocol as implemented in openssl prior to
this update was not able to associate data to a
renegotiated connection. This allowed man-in-the-middle
attackers to inject HTTP requests in a HTTPS session
without being noticed. For example Apache's mod_ssl was
vulnerable to this kind of attack because it uses openssl.
Please note that renegotiation will be disabled by this
update and may cause problems in some cases.
(CVE-2009-3555: CVSS v2 Base Score: 6.4)
</description>
  <pkglist>
    <collection>
        <package name="compat-openssl097g-debuginfo" arch="i586" version="0.9.7g" release="146.11.1">
          <filename>compat-openssl097g-debuginfo-0.9.7g-146.11.1.i586.rpm</filename>
        </package>
        <package name="compat-openssl097g-debuginfo" arch="ppc" version="0.9.7g" release="146.11.1">
          <filename>compat-openssl097g-debuginfo-0.9.7g-146.11.1.ppc.rpm</filename>
        </package>
        <package name="compat-openssl097g-debuginfo" arch="x86_64" version="0.9.7g" release="146.11.1">
          <filename>compat-openssl097g-debuginfo-0.9.7g-146.11.1.x86_64.rpm</filename>
        </package>
        <package name="compat-openssl097g-debuginfo-32bit" arch="x86_64" version="0.9.7g" release="146.11.1">
          <filename>compat-openssl097g-debuginfo-32bit-0.9.7g-146.11.1.x86_64.rpm</filename>
        </package>
        <package name="compat-openssl097g-debuginfo-64bit" arch="ppc" version="0.9.7g" release="146.11.1">
          <filename>compat-openssl097g-debuginfo-64bit-0.9.7g-146.11.1.ppc.rpm</filename>
        </package>
        <package name="compat-openssl097g-debugsource" arch="i586" version="0.9.7g" release="146.11.1">
          <filename>compat-openssl097g-debugsource-0.9.7g-146.11.1.i586.rpm</filename>
        </package>
        <package name="compat-openssl097g-debugsource" arch="ppc" version="0.9.7g" release="146.11.1">
          <filename>compat-openssl097g-debugsource-0.9.7g-146.11.1.ppc.rpm</filename>
        </package>
        <package name="compat-openssl097g-debugsource" arch="x86_64" version="0.9.7g" release="146.11.1">
          <filename>compat-openssl097g-debugsource-0.9.7g-146.11.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
