<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="05c24508b48c6d37bc55ef2ebd8caf3b"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="541">
  <id>dbg111-eID-belgium</id>
  <title>eID-belgium uses EVP_VerifyFinal() incorrectly (CVE-2009-0049)</title>
  <release>openSUSE 11.1</release>
  <issued date="1234979729"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=468866" id="468866" title="bug number 468866" type="bugzilla"/>
  </references>
  <description>eID-belgium uses EVP_VerifyFinal() incorrectly
(CVE-2009-0049) which allowed bypassing the validation of
the certificate chain.
</description>
  <pkglist>
    <collection>
        <package name="eID-belgium-debuginfo" arch="i586" version="2.6.0" release="121.29.2">
          <filename>eID-belgium-debuginfo-2.6.0-121.29.2.i586.rpm</filename>
        </package>
        <package name="eID-belgium-debuginfo" arch="ppc" version="2.6.0" release="121.29.2">
          <filename>eID-belgium-debuginfo-2.6.0-121.29.2.ppc.rpm</filename>
        </package>
        <package name="eID-belgium-debuginfo" arch="x86_64" version="2.6.0" release="121.29.2">
          <filename>eID-belgium-debuginfo-2.6.0-121.29.2.x86_64.rpm</filename>
        </package>
        <package name="eID-belgium-debugsource" arch="i586" version="2.6.0" release="121.29.2">
          <filename>eID-belgium-debugsource-2.6.0-121.29.2.i586.rpm</filename>
        </package>
        <package name="eID-belgium-debugsource" arch="ppc" version="2.6.0" release="121.29.2">
          <filename>eID-belgium-debugsource-2.6.0-121.29.2.ppc.rpm</filename>
        </package>
        <package name="eID-belgium-debugsource" arch="x86_64" version="2.6.0" release="121.29.2">
          <filename>eID-belgium-debugsource-2.6.0-121.29.2.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
