<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="470d54b3be4e369bbde36bf7ae7fa6ca"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="2232">
  <id>dbg111-libopenssl-devel</id>
  <title>openssl: Security update fixing CVE-2009-3555 and CVE-2009-3245.</title>
  <release>openSUSE 11.1 DEBUGINFO</release>
  <issued date="1270048542"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=584292" id="584292" title="bug number 584292" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=566238" id="566238" title="bug number 566238" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" id="CVE-2009-3555" title="CVE-2009-3555" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3245" id="CVE-2009-3245" title="CVE-2009-3245" type="cve"/>
  </references>
  <description>This openssl update adds support for RFC5746 TLS
renegotiations to address vulnerabilities tracked as
(CVE-2009-3555).

It also fixes a mishandling of OOM conditions in bn_wexpand
(CVE-2009-3245).
</description>
  <pkglist>
    <collection>
        <package name="openssl-debuginfo" arch="i586" version="0.9.8h" release="28.15.1">
          <filename>openssl-debuginfo-0.9.8h-28.15.1.i586.rpm</filename>
        </package>
        <package name="openssl-debuginfo" arch="ppc" version="0.9.8h" release="28.15.1">
          <filename>openssl-debuginfo-0.9.8h-28.15.1.ppc.rpm</filename>
        </package>
        <package name="openssl-debuginfo" arch="x86_64" version="0.9.8h" release="28.15.1">
          <filename>openssl-debuginfo-0.9.8h-28.15.1.x86_64.rpm</filename>
        </package>
        <package name="openssl-debugsource" arch="i586" version="0.9.8h" release="28.15.1">
          <filename>openssl-debugsource-0.9.8h-28.15.1.i586.rpm</filename>
        </package>
        <package name="openssl-debugsource" arch="ppc" version="0.9.8h" release="28.15.1">
          <filename>openssl-debugsource-0.9.8h-28.15.1.ppc.rpm</filename>
        </package>
        <package name="openssl-debugsource" arch="x86_64" version="0.9.8h" release="28.15.1">
          <filename>openssl-debugsource-0.9.8h-28.15.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
