<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="dc5f5cc020c3d593a243573dc0f44754"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="1232">
  <id>dbg111-curl</id>
  <title>curl security update</title>
  <release>openSUSE 11.1</release>
  <issued date="1250728016"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=527990" id="527990" title="bug number 527990" type="bugzilla"/>
  </references>
  <description>curl did not detect embedded null characters in certificate
names. By using specially crafted certificates attackers
could exploit that to conduct man in the middle attacks
(CVE-2009-2417).

Note the previous update that was supposed to fix the issue
accidentally lacked the actual fix which was corrected this
time.
</description>
  <pkglist>
    <collection>
        <package name="curl-debuginfo" arch="i586" version="7.19.0" release="11.3.1">
          <filename>curl-debuginfo-7.19.0-11.3.1.i586.rpm</filename>
        </package>
        <package name="curl-debuginfo" arch="ppc" version="7.19.0" release="11.3.1">
          <filename>curl-debuginfo-7.19.0-11.3.1.ppc.rpm</filename>
        </package>
        <package name="curl-debuginfo" arch="x86_64" version="7.19.0" release="11.3.1">
          <filename>curl-debuginfo-7.19.0-11.3.1.x86_64.rpm</filename>
        </package>
        <package name="curl-debugsource" arch="i586" version="7.19.0" release="11.3.1">
          <filename>curl-debugsource-7.19.0-11.3.1.i586.rpm</filename>
        </package>
        <package name="curl-debugsource" arch="ppc" version="7.19.0" release="11.3.1">
          <filename>curl-debugsource-7.19.0-11.3.1.ppc.rpm</filename>
        </package>
        <package name="curl-debugsource" arch="x86_64" version="7.19.0" release="11.3.1">
          <filename>curl-debugsource-7.19.0-11.3.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
