<?xml version="1.0" encoding="UTF-8"?>
<oval xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns:redhat="http://oval.mitre.org/XMLSchema/oval#redhat" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval oval-schema.xsd http://oval.mitre.org/XMLSchema/oval#redhat redhat-schema.xsd" oval:schemaVersion="3.0" redhat:schemaVersion="3.0" oval:timeStamp="20050323104802">
	<definitions>
		<definition id="OVAL2" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mutt</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0140</cveid>
			<dates>
				<created date="2003-08-18"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-201" comment="balsa version is less than 2.0.6-2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-201" comment="/usr/bin/balsa is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL6" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>CUPS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0195</cveid>
			<dates>
				<created date="2003-08-19"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-202" comment="cups version is less than 1.1.17-13.3" />
				</software>
				<configuration>
					<criterion test_ref="rlt-201" comment="cupsd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL28" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>skk</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0539</cveid>
			<dates>
				<created date="2003-09-04"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-216" comment="Vulnerable config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL52" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>EOG</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0165</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-205" comment="eog version is less than 2.2.0-2" />
				</software>
				<configuration>
					<criterion test_ref="cmp-232" comment="eog is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL54" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2003-0081</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL55" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0159</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL69" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0356</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL73" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0357</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL75" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0428</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL84" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0429</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL88" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0430</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL101" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0431</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL106" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ethereal</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0432</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-238" comment="Vulnerable Config" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL107" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ximian Evolution</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0128</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL108" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ximian Evolution</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0129</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL111" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Ximian Evolution</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0130</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL112" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0547</cveid>
			<dates>
				<created date="2003-09-04"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL113" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0548</cveid>
			<dates>
				<created date="2003-09-04"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CAN-2003-0549</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL129" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0549</cveid>
			<dates>
				<created date="2003-09-04"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL133" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GNU Ghostscript</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0354</cveid>
			<dates>
				<created date="2003-08-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-211" comment="ghostscript version is less than 7.05-32.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-262" comment="/usr/bin/gs is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL135" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GnuPG</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0255</cveid>
			<dates>
				<created date="2003-08-19"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-212" comment="gnupg version is less than 1.2.1-4" />
				</software>
				<configuration>
					<criterion test_ref="cmp-263" comment="/usr/bin/gnupg is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL138" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GtkHTML</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0133</cveid>
			<dates>
				<created date="2003-09-02"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-213" comment="gtkhtml version is less than 1.1.9-0.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL148" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>GtkHTML</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0541</cveid>
			<dates>
				<created date="2003-09-10"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-214" comment="gtkhtml version is less than 1.1.9-0.9.1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-266" comment="/usr/bin/evolution is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL150" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2003-0020</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL151" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0083</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CAN-2003-0020</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL156" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0132</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL169" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0192</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-203" comment="httpd.worker is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL173" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0253</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL183" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0254</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-202" comment="httpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL193" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>KDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0690</cveid>
			<dates>
				<created date="2003-09-21"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-217" comment="kdebase version is less than 3.1-15" />
				</software>
				<configuration>
					<criterion test_ref="cmp-278" comment="/usr/bin/kdm is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL215" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>KDM</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0692</cveid>
			<dates>
				<created date="2003-09-21"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-217" comment="kdebase version is less than 3.1-15" />
				</software>
				<configuration>
					<criterion test_ref="cmp-278" comment="/usr/bin/kdm is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL230" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0028</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CAN-2002-0391</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-218" comment="krb5-server version is less than 1.2.7-14" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL244" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0082</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun")</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-218" comment="krb5-server version is less than 1.2.7-14" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL248" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0138</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-219" comment="krb5-libs version is less than 1.2.7-14" />
					<criterion test_ref="cmp-289" comment="krb5-server or krb5-workstation installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL250" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0139</cveid>
			<dates>
				<created date="2003-08-14"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-219" comment="krb5-libs version is less than 1.2.7-14" />
					<criterion test_ref="cmp-289" comment="krb5-server or krb5-workstation installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL254" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0127</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rrt-202" comment="kernel version = 2.4.20-6" />
				</software>
				<configuration>
					<criterion test_ref="rut-204" comment="kernel 2.4.20-6 or earlier is running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL260" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Netfilter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0187</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL261" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Netfilter</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0244</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL278" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0246</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL284" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0247</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops")</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL292" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0248</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL295" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0364</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL304" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>/proc/tty/driver/serial</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0461</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL309" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0462</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash)</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL311" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0464</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL327" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0476</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL328" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0501</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL380" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0550</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL384" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0551</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL385" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0552</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL386" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0619</cveid>
			<dates>
				<created date="2003-09-25"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL387" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0699</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CAN-2003-0700</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL401" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Linux kernel</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0700</cveid>
			<dates>
				<created date="2003-09-26"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CAN-2003-0699</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL411" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Konqueror</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0459</cveid>
			<dates>
				<created date="2003-09-04"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-224" comment="kdelibs version is less than 3.1-12" />
				</software>
				<configuration>
					<criterion test_ref="cmp-304" comment="/usr/bin/konqueror is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL423" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>LPRng</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0136</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-225" comment="lprng version is less than 3.8.19-3.1" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ret-255" comment="psbanner is world-executable" />
					<criterion test_ref="rlt-204" comment="lpd listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL430" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>lv</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0188</cveid>
			<dates>
				<created date="2003-08-19"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-226" comment="lv version is less than 4.49.4-9.9.1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL434" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mutt</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0140</cveid>
			<dates>
				<created date="2003-08-18"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-227" comment="mutt version is less than 1.4.1-1" />
				</software>
				<configuration>
					<criterion test_ref="cmp-305" comment="/usr/bin/mutt is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL436" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>MySQL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CVE">2003-0073</cveid>
			<dates>
				<created date="2003-08-18"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-205" comment="mysqld is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL442" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>MySQL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0150</cveid>
			<dates>
				<created date="2003-08-18"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-205" comment="mysqld is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL443" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>nfs-utils</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0252</cveid>
			<dates>
				<created date="2003-09-02"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-229" comment="nfs-utils version is less than 1.0.1-3.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-206" comment="rpc.mountd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL445" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0190</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-230" comment="openssh-server version is less than 3.5p1-6.9" />
				</software>
				<configuration>
					<criterion test_ref="rlt-207" comment="sshd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL446" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0682</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CAN-2003-0693 and CAN-2003-0695</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" />
				</software>
				<configuration>
					<criterion test_ref="rlt-207" comment="sshd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL447" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0693</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CAN-2003-0695</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" />
				</software>
				<configuration>
					<criterion test_ref="rlt-207" comment="sshd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL452" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0695</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CAN-2003-0693</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" />
				</software>
				<configuration>
					<criterion test_ref="rlt-207" comment="sshd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL461" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0131</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-914" comment="affected version of SSL and TLS components for OpenSSL" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL466" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>OpenSSL</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0147</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-11">Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal)</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-914" comment="affected version of SSL and TLS components for OpenSSL" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL469" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>pam_smb</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0686</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-237" comment="pam_smb version is less than 1.1.6-9.9" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL470" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>CGI.pm</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0615</cveid>
			<dates>
				<created date="2003-09-25"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-238" comment="perl-CGI version is less than 2.81-88.3" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL485" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>php</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0442</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-239" comment="php version is less than 4.2.2-17.2" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL499" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>pine</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0720</cveid>
			<dates>
				<created date="2003-09-12"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-240" comment="pine version is less than 4.44-19.90.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-314" comment="/usr/bin/pine is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL503" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>pine</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0721</cveid>
			<dates>
				<created date="2003-09-12"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-240" comment="pine version is less than 4.44-19.90.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-314" comment="/usr/bin/pine is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL522" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Postfix</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0468</cveid>
			<dates>
				<created date="2003-09-02"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-241" comment="postfix version is less than 1.1.12-1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-208" comment="smtpd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL544" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Postfix</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0540</cveid>
			<dates>
				<created date="2003-09-02"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-241" comment="postfix version is less than 1.1.12-1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-208" comment="smtpd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL552" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>smbd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0085</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" />
				</software>
				<configuration>
					<criterion test_ref="rlt-209" comment="smbd listens on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL554" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Samba</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0086</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL564" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Samba</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0196</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CAN-2003-0201</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" />
				</software>
				<configuration>
					<criterion test_ref="rlt-210" comment="smbd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL567" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Samba, Samba-TNG</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0201</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" />
				</software>
				<configuration>
					<criterion test_ref="rlt-210" comment="smbd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL569" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>semi MIME library</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0440</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-319" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-320" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL572" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0694</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-246" comment="sendmail version is less than 8.12.8-5.90" />
				</software>
				<configuration>
					<criterion test_ref="cmp-323" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL595" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0681</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-247" comment="sendmail version is less than 8.12.8-9.90" />
				</software>
				<configuration>
					<criterion test_ref="cmp-323" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL597" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0688</cveid>
			<dates>
				<created date="2003-09-05"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-248" comment="sendmail version is less than 8.12.8-6.90" />
				</software>
				<configuration>
					<criterion test_ref="rlt-212" comment="sendmail is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL603" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0694</cveid>
			<dates>
				<created date="2003-09-21"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-247" comment="sendmail version is less than 8.12.8-9.90" />
				</software>
				<configuration>
					<criterion test_ref="cmp-323" comment="Vulnerable Config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL614" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>SquirrelMail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0160</cveid>
			<dates>
				<created date="2003-08-17"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-249" comment="squirrelmail version is less than 1.2.11-1" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL619" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>unzip</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0282</cveid>
			<dates>
				<created date="2003-09-04"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-250" comment="unzip version is less than 5.50-33" />
				</software>
				<configuration>
					<criterion test_ref="cmp-335" comment="/usr/bin/unzip is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL631" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>up2date</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0546</cveid>
			<dates>
				<created date="2003-09-03"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-251" comment="up2date version is less than 3.1.23.1-5" />
				</software>
				<configuration>
					<criterion test_ref="rct-206" comment="rhnsd is running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL634" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>vsftpd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0135</cveid>
			<dates>
				<created date="2003-08-11"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-252" comment="vsftpd version is less than 1.1.3-8" />
				</software>
				<configuration>
					<criterion test_ref="rlt-213" comment="vsftpd is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL657" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>xinetd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
			</contributors>
			<cveid status="CAN">2003-0211</cveid>
			<dates>
				<created date="2003-08-18"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<modified date="2004-05-17">Changed tested epoch in xinetd test rvt-253 to 2, based on testing.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-253" comment="xinetd version is less than 2:2.3.11-1.9.0" />
				</software>
				<configuration>
					<criterion test_ref="rlt-214" comment="xinetd is listening to the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL664" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>xpdf</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0434</cveid>
			<dates>
				<created date="2003-08-29"/>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Various PDF viewers including Adobe Acrobat 5.06 and Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-254" comment="xpdf version is less than 2.0.1-11" />
				</software>
				<configuration>
					<criterion test_ref="cmp-338" comment="xpdf is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL667" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>ypserv</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0251</cveid>
			<dates>
				<created date="2003-08-29"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-03-25">INTERIM</status_change>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-255" comment="ypserv version is less than 2.8-0.9E" />
				</software>
				<configuration>
					<criterion test_ref="rlt-215" comment="ypserv is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL803" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>PWLib</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0097</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Added a program_name element to rlt-217</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-257" comment="pwlib version is less than 1.4.7-4.1" />
				</software>
				<configuration>
					<criterion test_ref="rlt-217" comment="a program is listening on TCP or UDP port 1720" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL804" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>netpbm</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2003-0924</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-341" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-342" comment="Vulnerable configuration" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL806" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>XFree86</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0083</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CAN-2004-0084 and CAN-2004-0106</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" />
				</software>
				<configuration>
					<criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL807" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>XFree86</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0084</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CAN-2004-0083 and CAN-2004-0106</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" />
				</software>
				<configuration>
					<criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL809" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>XFree86</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CAN">2004-0106</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CAN-2004-0083 and CAN-2004-0084</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" />
				</software>
				<configuration>
					<criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL810" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
				<product>netpbm</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
				<contributor organization="The MITRE Corporation">Matt Busby</contributor>
			</contributors>
			<cveid status="CVE">2003-0924</cveid>
			<dates>
				<created date="2004-03-20"/>
				<modified date="2004-05-05">Corrected syntax errors in sql verion of the definition.</modified>
				<status_change date="2004-05-25">ACCEPTED</status_change>
			</dates>
			<description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="cmp-574" comment="Vulnerable Config" />
				</software>
				<configuration>
					<criterion test_ref="cmp-342" comment="Vulnerable configuration" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL811" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mutt</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CVE">2004-0078</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-265" comment="mutt version is less than 1.4.1-3.3" />
				</software>
				<configuration>
					<criterion test_ref="cmp-305" comment="/usr/bin/mutt is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL813" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mailman</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0965</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-266" comment="mailman version is less than 2.1.1-5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-218" comment="httpd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL815" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Mailman</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2003-0992</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-266" comment="mailman version is less than 2.1.1-5" />
				</software>
				<configuration>
					<criterion test_ref="rlt-218" comment="httpd is listening on the network" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL818" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Gaim</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0006</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-267" comment="gaim version is less than 0.75-0.9.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-802" comment="/usr/bin/gaim is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL819" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Gaim</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0007</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="rrt-201" comment="Red Hat 9 is installed" />
					<criterion test_ref="rut-201" comment="ix86 architecture" />
					<criterion test_ref="rvt-267" comment="gaim version is less than 0.75-0.9.0" />
				</software>
				<configuration>
					<criterion test_ref="cmp-802" comment="/usr/bin/gaim is executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL820" class="vulnerability">
			<affected family="redhat">
				<redhat:platform>Red Hat Linux 9</redhat:platform>
				<product>Gaim</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Jay Beale</submitter>
				<contributor organization="The MITRE Corporation">Jay Beale</contributor>
			</contributors>
			<cveid status="CAN">2004-0008</cveid>
			<dates>
				<created date="2004-03-20"/>
				<status_change date="2004-05-05">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that trig