<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="1915c5a071fe3232134ef53a4a42aba0"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="1834">
  <id>dbg111-openssl-CVE-2009-4355.patch</id>
  <title>openssl security update</title>
  <release>openSUSE 11.1</release>
  <issued date="1263989531"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=566238" id="566238" title="bug number 566238" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=467437" id="467437" title="bug number 467437" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4355" id="CVE-2009-4355" title="CVE-2009-4355" type="cve"/>
  </references>
  <description>Incorrect use of an openssl cleanup function can lead to
memory leaks in applications. For example an ssl enabled
web server such as apache that uses php, curl and openssl
leaks memory if a SIGHUP signal was sent to apache. The
openssl cleanup function was made more robust to avoid
memory leaks (CVE-2009-4355).

Additionally a problem with creating pkcs12 files was fixed.
</description>
  <pkglist>
    <collection>
        <package name="openssl-debuginfo" arch="i586" version="0.9.8h" release="28.13.1">
          <filename>openssl-debuginfo-0.9.8h-28.13.1.i586.rpm</filename>
        </package>
        <package name="openssl-debuginfo" arch="ppc" version="0.9.8h" release="28.13.1">
          <filename>openssl-debuginfo-0.9.8h-28.13.1.ppc.rpm</filename>
        </package>
        <package name="openssl-debuginfo" arch="x86_64" version="0.9.8h" release="28.13.1">
          <filename>openssl-debuginfo-0.9.8h-28.13.1.x86_64.rpm</filename>
        </package>
        <package name="openssl-debugsource" arch="i586" version="0.9.8h" release="28.13.1">
          <filename>openssl-debugsource-0.9.8h-28.13.1.i586.rpm</filename>
        </package>
        <package name="openssl-debugsource" arch="ppc" version="0.9.8h" release="28.13.1">
          <filename>openssl-debugsource-0.9.8h-28.13.1.ppc.rpm</filename>
        </package>
        <package name="openssl-debugsource" arch="x86_64" version="0.9.8h" release="28.13.1">
          <filename>openssl-debugsource-0.9.8h-28.13.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
