<?xml version="1.0" encoding="UTF-8"?>
<oval xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns:solaris="http://oval.mitre.org/XMLSchema/oval#solaris" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval oval-schema.xsd http://oval.mitre.org/XMLSchema/oval#solaris solaris-schema.xsd" oval:schemaVersion="3.0" solaris:schemaVersion="3.0" oval:timeStamp="20050323104945">
	<definitions>
		<definition id="OVAL7" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>kcms_configure</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0594</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-201" comment="File kcms_configure exists" />
				</software>
				<configuration>
					<criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL9" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>libnsl</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0391</cveid>
			<dates>
				<created date="2003-01-28"/>
			</dates>
			<description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" />
					<criterion test_ref="cmp-205" negate="true" comment="Patches 108827-30 and 108901-06" />
				</software>
				<configuration>
					<criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL10" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>xlock</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0652</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-204" comment="File xlock exists" />
					<criterion test_ref="spt-203" negate="true" comment="Patch 108652-38 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-209" comment="File xlock SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL11" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>snmpdx</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0796</cveid>
			<dates>
				<created date="2002-09-25"/>
			</dates>
			<description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-205" comment="File snmpdx exists" />
					<criterion test_ref="spt-204" negate="true" comment="Patch 108869-16 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-203" comment="snmpdx running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL14" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Xsun</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0158</cveid>
			<dates>
				<created date="2002-08-23"/>
			</dates>
			<description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-206" comment="File Xsun exists" />
					<criterion test_ref="spt-205" negate="true" comment="Patch 108652-52 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-210" comment="File Xsun SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL15" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0677</cveid>
			<dates>
				<created date="2003-01-31"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-206" negate="true" comment="Patch 110286-09 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL31" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CVE">2002-0033</cveid>
			<dates>
				<created date="2003-01-31"/>
				<modified date="2005-01-28">Updated to include Solaris 9 and Solaris 9 patch info</modified>
				<status_change date="2005-02-01">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name</description>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
					<criterion test_ref="spt-207" negate="true" comment="Patch 110896-02 or later installed" />
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-111" negate="true" comment="Patch 114008-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL33" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Xsun</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0158</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-206" comment="File Xsun exists" />
					<criterion test_ref="spt-208" negate="true" comment="Patch 108376-38 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-210" comment="File Xsun SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL34" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>whodo</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2001-1076</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-209" comment="File whodo exists" />
					<criterion test_ref="spt-209" negate="true" comment="Patch 111600-01 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-219" comment="File whodo SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL41" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>rpc.rwalld</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0573</cveid>
			<dates>
				<created date="2003-01-30"/>
			</dates>
			<description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-210" comment="File rpc.rwalld exists" />
					<criterion test_ref="spt-210" negate="true" comment="Patch 112899-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-221" comment="File rpc.rwalld executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL42" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>libnsl</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0391</cveid>
			<dates>
				<created date="2003-01-02"/>
			</dates>
			<description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" />
					<criterion test_ref="cmp-223" negate="true" comment="Patches 106942-22 and 108451-06" />
				</software>
				<configuration>
					<criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL43" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CAN">2002-0084</cveid>
			<dates>
				<created date="2002-10-17"/>
				<modified date="2005-01-28">Updated to add patch test</modified>
				<status_change date="2005-02-01">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
					<criterion test_ref="spt-109" negate="true" comment="Patch 108800-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL47" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>whodo</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2001-1076</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-209" comment="File whodo exists" />
					<criterion test_ref="spt-213" negate="true" comment="Patch 111826-01 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-219" comment="File whodo SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL48" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0088</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL56" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>rpc.yppasswdd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0779</cveid>
			<dates>
				<created date="2002-08-30"/>
			</dates>
			<description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-212" comment="File rpc.yppasswdd exists" />
					<criterion test_ref="spt-214" negate="true" comment="Patch 111596-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-204" comment="rpc.yppasswdd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL60" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0088</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL62" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>mibiisa</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0797</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-213" comment="File mibiisa exists" />
					<criterion test_ref="spt-215" negate="true" comment="Patch 107709-19 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-205" comment="mibiisa running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL65" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>kcms_configure</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0594</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-201" comment="File kcms_configure exists" />
					<criterion test_ref="spt-216" negate="true" comment="Patch 107337-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL67" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0089</cveid>
			<dates>
				<created date="2002-09-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
					<criterion test_ref="spt-217" negate="true" comment="Patch 110453-01 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL68" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>admintool</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0089</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-211" comment="File admintool exists" />
					<criterion test_ref="spt-218" negate="true" comment="Patch 108721-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-229" comment="File admintool SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL70" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>dtspcd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0803</cveid>
			<dates>
				<created date="2002-08-23"/>
			</dates>
			<description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary command</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-214" comment="File dtspcd exists" />
					<criterion test_ref="spt-219" negate="true" comment="Patch 108949-07 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-239" comment="File dtspcd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL74" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>dtspcd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0803</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary command</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-214" comment="File dtspcd exists" />
					<criterion test_ref="spt-220" negate="true" comment="Patch 106934-04 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-239" comment="File dtspcd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL79" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>rpc.rwalld</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0573</cveid>
			<dates>
				<created date="2003-01-30"/>
			</dates>
			<description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-210" comment="File rpc.rwalld exists" />
					<criterion test_ref="spt-221" negate="true" comment="Patch 112846-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-221" comment="File rpc.rwalld executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL80" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0678</cveid>
			<dates>
				<created date="2003-01-29"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-222" negate="true" comment="Patch 107893-19 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL86" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>lbxproxy</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0090</cveid>
			<dates>
				<created date="2002-08-30"/>
			</dates>
			<description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-215" comment="File lbxproxy exists" />
					<criterion test_ref="spt-223" negate="true" comment="Patch 108652-51 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL91" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0677</cveid>
			<dates>
				<created date="2003-01-31"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-222" negate="true" comment="Patch 107893-19 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL94" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mibiisa</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0797</cveid>
			<dates>
				<created date="2002-09-25"/>
			</dates>
			<description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-213" comment="File mibiisa exists" />
					<criterion test_ref="spt-204" negate="true" comment="Patch 108869-16 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-205" comment="mibiisa running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL97" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CAN">2002-0084</cveid>
			<dates>
				<created date="2002-09-17"/>
				<modified date="2005-01-27">Updated to add patch test</modified>
				<modified date="2005-01-28">Added Solaris 9 and Solaris 9 patch test to the definition</modified>
				<status_change date="2005-02-01">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-110" negate="true" comment="Patch 110896-02 or later installed" />
					<criterion test_ref="spt-111" negate="true" comment="Patch 114008-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL102" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>rpc.yppasswdd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0779</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-212" comment="File rpc.yppasswdd exists" />
					<criterion test_ref="spt-224" negate="true" comment="Patch 111590-02 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-204" comment="rpc.yppasswdd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL114" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>snmpdx</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CAN">2002-0796</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-205" comment="File snmpdx exists" />
					<criterion test_ref="spt-215" negate="true" comment="Patch 107709-19 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-203" comment="snmpdx running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL120" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>kcms_server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2003-0027</cveid>
			<dates>
				<created date="2003-01-30"/>
			</dates>
			<description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-216" comment="File kcms_server exists" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL124" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CVE">2002-0033</cveid>
			<dates>
				<created date="2002-10-17"/>
				<modified date="2005-01-28">Added patch test</modified>
				<status_change date="2005-02-01">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-208" comment="File cachefsd exists" />
					<criterion test_ref="spt-109" negate="true" comment="Patch 108800-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-217" comment="File cachefsd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL131" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>xlock</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2001-0652</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-204" comment="File xlock exists" />
					<criterion test_ref="spt-225" negate="true" comment="Patch 108376-30 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-209" comment="File xlock SUID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL149" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>fs.auto, xfs</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-1317</cveid>
			<dates>
				<created date="2003-09-08"/>
			</dates>
			<description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-217" comment="File fs.auto exists" />
					<criterion test_ref="sft-218" comment="File xfs exists" />
					<criterion test_ref="spt-226" negate="true" comment="Patch 109862-03 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-267" comment="File xfs executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL152" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>fs.auto, xfs</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
				<contributor organization="The MITRE Corporation">David Proulx</contributor>
			</contributors>
			<cveid status="CVE">2002-1317</cveid>
			<dates>
				<created date="2003-09-08"/>
			</dates>
			<description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-217" comment="File fs.auto exists" />
					<criterion test_ref="sft-218" comment="File xfs exists" />
					<criterion test_ref="spt-227" negate="true" comment="Patch 108117-06 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-267" comment="File xfs executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL175" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0678</cveid>
			<dates>
				<created date="2003-01-29"/>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-206" negate="true" comment="Patch 110286-09 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL177" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0679</cveid>
			<dates>
				<created date="2003-01-29"/>
			</dates>
			<description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-228" negate="true" comment="Patch 107893-20 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL179" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>lbxproxy</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0090</cveid>
			<dates>
				<created date="2002-10-17"/>
			</dates>
			<description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sft-215" comment="File lbxproxy exists" />
					<criterion test_ref="spt-229" negate="true" comment="Patch 107654-10 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL192" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2002-0679</cveid>
			<dates>
				<created date="2003-01-29"/>
			</dates>
			<description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-207" comment="File rpc.ttdbserverd exists" />
					<criterion test_ref="spt-230" negate="true" comment="Patch 110286-10 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL195" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>kcms_server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">David Proulx</submitter>
			</contributors>
			<cveid status="CVE">2003-0027</cveid>
			<dates>
				<created date="2003-01-24"/>
			</dates>
			<description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-202" comment="Solaris 8 Installed" />
					<criterion test_ref="sft-216" comment="File kcms_server exists" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" />
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL449" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Bind</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-1220</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" />
					<criterion test_ref="spt-26" negate="true" comment="Patch 112970-03 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-211" comment="in.named running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL555" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Xsun</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CVE">2001-0422</cveid>
			<dates>
				<created date="2004-12-28"/>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" />
					<criterion test_ref="spt-4" negate="true" comment="Patch 108376-25 or later installed" />
					<criterion test_ref="spt-5" negate="true" comment="Patch 108652-30 or later installed" />
					<criterion test_ref="sat-12" comment="X Window System platform software (SUNWxwplt) installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1048" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>snmpdx</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2002-0012</cveid>
			<dates>
				<created date="2005-02-01"/>
				<status_change date="2005-02-01">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" />
					<criterion test_ref="sat-48" comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" />
					<criterion test_ref="spt-104" negate="true" comment="Patch 107709-18 or later installed" />
					<criterion test_ref="spt-105" negate="true" comment="Patch 108869-15 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-203" comment="snmpdx running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1099" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2002-0677</cveid>
			<dates>
				<created date="2004-10-15"/>
				<modified date="2005-01-11">modified sat-6 - Changed test to pattern match and added check for 64bit version</modified>
				<modified date="2005-01-14">modified sat-6 - Changed regular expression test to properly check for 64bit package</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<status_change date="2005-01-24">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" />
					<criterion test_ref="spt-255" negate="true" comment="Patch 112808-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
					<criterion test_ref="sct-201" comment="inetd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1110" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2003-0058</cveid>
			<dates>
				<created date="2005-02-01"/>
				<status_change date="2005-02-01">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-157" comment="Solaris 7 and Solaris Enterprise Authentication Mechanism OR Solaris 8 or 9 installed" />
					<criterion test_ref="spt-96" negate="true" comment="Patch 112536-02 or later installed" />
					<criterion test_ref="spt-99" negate="true" comment="Patch 112908-04 or later installed" />
					<criterion test_ref="spt-97" negate="true" comment="Patch 112237-07 or later installed" />
					<criterion test_ref="spt-98" negate="true" comment="Patch 112390-07 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-1000" comment="test not supported in version 3 schema" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1227" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0760</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" />
					<criterion test_ref="spt-46" negate="true" comment="Patch 117765-02 or later installed" />
					<criterion test_ref="spt-47" negate="true" comment="Patch 117767-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1273" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Sadmin</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0722</cveid>
			<dates>
				<created date="2004-10-15"/>
				<modified date="2004-10-15">Added check for sadmind called with strong authentication</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-7" comment="System and Network Administration Framework Installed" />
					<criterion test_ref="spt-259" negate="true" comment="Patch 116457-02 or later installed" />
					<criterion test_ref="spt-260" negate="true" comment="Patch 116442-01 or later installed" />
					<criterion test_ref="spt-261" negate="true" comment="Patch 116454-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="sit-209" comment="inetd.conf contains sadmind" />
					<criterion test_ref="sit-210" negate="true" comment="Sadmin called using strong authentication" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1436" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0368</cveid>
			<dates>
				<created date="2004-10-12"/>
				<modified date="2004-10-12">Added patch 107180-31 test for Solaris 7.  Changed vulnerable software test logic a little</modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sft-219" comment="File /usr/dt/bin/dtlogin exists" />
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-231" comment="Patch 108919-21 or later installed" />
					<criterion test_ref="spt-232" comment="Patch 112807-09 or later installed" />
					<criterion test_ref="spt-249" comment="Patch 107180-31 or later installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-206" comment="dtlogin running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1467" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Samba</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-1318</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-28" comment="Samba - Usr (SUNWsmbau) installed" />
					<criterion test_ref="spt-48" negate="true" comment="Patch 114684-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-3" comment="smbd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1479" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>libpng</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0599</cveid>
			<dates>
				<created date="2004-12-12"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-11" comment="Netscape installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1707" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Sun Enterprise Storage Manager (ESM)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description></description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="sat-1" comment="Sun Enterprise Storage Manager installed" />
					<criterion test_ref="spt-242" negate="true" comment="Patch 117367-01 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1844" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>NIS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CVE">2001-1328</cveid>
			<dates>
				<created date="2004-12-29"/>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" />
					<criterion test_ref="sat-13" comment="NIS/NIS+ Utilities installed (SUNWnisu)" />
					<criterion test_ref="spt-8" negate="true" comment="Patch 108750-02 or later installed" />
					<criterion test_ref="spt-9" negate="true" comment="Patch 110322-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-2" comment="ypbind running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL1880" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>dtspcd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">1999-0689</cveid>
			<dates>
				<created date="2005-02-01"/>
				<status_change date="2005-02-01">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sat-49" comment="CDE Daemons (SUNWdtdmn) installed" />
					<criterion test_ref="spt-107" negate="true" comment="Patch 108221-01 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1905" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0092</cveid>
			<dates>
				<created date="2005-02-01"/>
				<status_change date="2005-02-01">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" />
					<criterion test_ref="spt-100" negate="true" comment="Patch 107702-12 or later installed" />
					<criterion test_ref="spt-101" negate="true" comment="Patch 109354-19 or later installed" />
					<criterion test_ref="spt-102" negate="true" comment="Patch 114497-01 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL1982" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0174</cveid>
			<dates>
				<created date="2004-10-14"/>
				<modified date="2004-10-18">Changed apache test to file test</modified>
				<modified date="2004-10-19">Changed apache test to package test</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Apache before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket.</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="spt-254" negate="true" comment="Patch 113146-05 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2002" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0523</cveid>
			<dates>
				<created date="2004-10-11"/>
				<modified date="2005-01-14">Changed two unknown tests for kerberos configuration to Solaris text file contents tests </modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-246" negate="true" comment="Patch 112908-16 or later installed" />
					<criterion test_ref="spt-247" negate="true" comment="Patch 112536-05 or later installed" />
					<criterion test_ref="cmp-1104" negate="true" comment="Patches 112237-11 and 112390-09 or greater installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-1000" comment="test not supported in version 3 schema" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2011" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Bind</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0914</cveid>
			<dates>
				<created date="2004-10-19"/>
				<modified date="2005-01-11">modified sat-10 - Changed test to pattern match to check for 64bit version of Core Solaris</modified>
				<modified date="2005-01-14">modified sat-10 - Changed regular expression to properly check for 64bit package</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<status_change date="2005-01-24">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-270" negate="true" comment="Patch 106938-08 or later installed" />
					<criterion test_ref="spt-271" negate="true" comment="Patch 109326-13 or later installed" />
					<criterion test_ref="spt-272" negate="true" comment="Patch 112970-06 or later installed" />
					<criterion test_ref="sat-10" comment="Core Solaris (SUNWcsu/SUNWcsxu) installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-211" comment="in.named running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2025" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>login</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CVE">2001-0797</cveid>
			<dates>
				<created date="2004-12-29"/>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" />
					<criterion test_ref="spt-6" negate="true" comment="Patch 112300-01 or later installed" />
					<criterion test_ref="spt-7" negate="true" comment="Patch 111085-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2065" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>pam_krb5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0653</cveid>
			<dates>
				<created date="2004-10-12"/>
				<modified date="2005-01-14">Changed all unknown tests to solaris file contents tests</modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="spt-248" negate="true" comment="Patch 112908-13 or later installed" />
					<criterion test_ref="spt-236" comment="Patch 112908-12 installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-1000" comment="test not supported in version 3 schema" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2094" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Bind</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-1221</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" />
					<criterion test_ref="spt-24" negate="true" comment="Patch 106938-07 or later installed" />
					<criterion test_ref="spt-25" negate="true" comment="Patch 109326-10 or later installed" />
					<criterion test_ref="spt-26" negate="true" comment="Patch 112970-03 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-211" comment="in.named running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2139" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Kerberos5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0644</cveid>
			<dates>
				<created date="2004-10-12"/>
				<modified date="2005-01-14">Changed kerberos unknown test to solaris file contents test</modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="spt-250" negate="true" comment="Patch 112908-15 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-1000" comment="test not supported in version 3 schema" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2163" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Samba</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0201</cveid>
			<dates>
				<created date="2004-12-30"/>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-15" comment="Samba (SUNWsmbar) installed" />
					<criterion test_ref="spt-15" negate="true" comment="Patch 114684-02 or later installed" />
				</software>
				<configuration operation="OR">
					<criterion test_ref="cmp-56" comment="Inetd running and inetd.conf contains smbd" />
					<criterion test_ref="sct-3" comment="smbd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2183" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-0906</cveid>
			<dates>
				<created date="2004-12-22"/>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-3" comment="Sendmail - root (SUNWsndmr) installed" />
					<criterion test_ref="spt-2" negate="true" comment="Patch 113575-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-208" comment="Sendmail running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2378" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>libpng</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0597</cveid>
			<dates>
				<created date="2004-12-12"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-11" comment="Netscape installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2418" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0764</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" />
					<criterion test_ref="spt-46" negate="true" comment="Patch 117765-02 or later installed" />
					<criterion test_ref="spt-47" negate="true" comment="Patch 117767-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2423" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>NIS</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-1199</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-20" comment="NIS Server - User (SUNWypu) installed" />
					<criterion test_ref="spt-33" negate="true" comment="Patch 106541-24 or later installed" />
					<criterion test_ref="spt-34" negate="true" comment="Patch 109328-03 or later installed" />
					<criterion test_ref="spt-35" negate="true" comment="Patch 113579-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-5" comment="ypxfrd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2536" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Kerberos5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0082</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun")</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="cmp-74" comment="Kerberos v5 (any SUNWkrbr/SUNWkrbu/SUNWkrbux) installed" />
					<criterion test_ref="cmp-79" negate="true" comment="Patches 112237-09 and 112390-08 or later installed" />
					<criterion test_ref="cmp-81" negate="true" comment="Patches 112925-03,112923-03,112921-02, and 112908-10 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-1000" comment="test not supported in version 3 schema" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2539" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Bind</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-1219</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR)</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" />
					<criterion test_ref="spt-24" negate="true" comment="Patch 106938-07 or later installed" />
					<criterion test_ref="spt-25" negate="true" comment="Patch 109326-10 or later installed" />
					<criterion test_ref="spt-26" negate="true" comment="Patch 112970-03 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-211" comment="in.named running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2572" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>libpng</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0598</cveid>
			<dates>
				<created date="2004-12-12"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-11" comment="Netscape installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL2590" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Sun Cluster</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0545</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-266" negate="true" comment="Patch 113505-02 or later installed" />
					<criterion test_ref="spt-267" negate="true" comment="Patch 113508-02 or later installed" />
					<criterion test_ref="spt-268" negate="true" comment="Patch 115054-01 or later installed" />
					<criterion test_ref="spt-269" negate="true" comment="Patch 115055-01 or later installed" />
					<criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-210" comment="Apache running with SunPlex Manager config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2592" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>kcms_server</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2003-0027</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-18" comment="Kodak Color Managment Server (KCMS) Runtime Environment (SUNWkcsrt/SUNWkcsrx) installed" />
					<criterion test_ref="spt-20" negate="true" comment="Patch 114636-01 or later installed" />
					<criterion test_ref="spt-21" negate="true" comment="Patch 107337-03 or later installed" />
					<criterion test_ref="spt-22" negate="true" comment="Patch 111400-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" />
					<criterion test_ref="sct-201" comment="inetd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2621" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>Sun Crypto Accelerator 4000</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0079</cveid>
			<dates>
				<created date="2004-10-12"/>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2004-10-27">INTERIM</status_change>
				<status_change date="2004-11-17">ACCEPTED</status_change>
			</dates>
			<description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-243" negate="true" comment="Patch 114796-04 or later installed" />
					<criterion test_ref="sat-2" comment="Sun Crypto Accelerator 4000 software installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2719" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>OpenSSH</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0693</cveid>
			<dates>
				<created date="2004-12-30"/>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CAN-2003-0695</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="spt-19" negate="true" comment="Patch 113273-04 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-4" comment="sshd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2770" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-0678</cveid>
			<dates>
				<created date="2004-10-15"/>
				<modified date="2005-01-11">modified sat-6 - Changed test to pattern match and added check for 64bit version</modified>
				<modified date="2005-01-14">modified sat-6 - Changed regular expression test to properly check for 64bit package</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
				<status_change date="2005-01-24">INTERIM</status_change>
				<status_change date="2005-02-16">ACCEPTED</status_change>
			</dates>
			<description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure</description>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" />
					<criterion test_ref="spt-255" negate="true" comment="Patch 112808-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-201" comment="inetd running" />
					<criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2816" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>fs.auto, xfs</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-1317</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sat-21" comment="X Window System Font Server (SUNWxwfs) installed" />
					<criterion test_ref="spt-42" negate="true" comment="Patch 113923-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" />
					<criterion test_ref="sct-201" comment="inetd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL2975" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Sendmail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CAN">2003-0694</cveid>
			<dates>
				<created date="2004-12-29"/>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="sat-14" comment="Sendmail - user (SUNWsndmu) installed" />
					<criterion test_ref="spt-13" negate="true" comment="Patch 107684-10 or later installed" />
					<criterion test_ref="spt-14" negate="true" comment="Patch 110615-10 or later installed" />
					<criterion test_ref="spt-240" negate="true" comment="Patch 113575-05 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3078" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">1999-0691</cveid>
			<dates>
				<created date="2005-02-01"/>
				<status_change date="2005-02-01">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sat-32" comment="CDE application basic runtime environment (SUNWdtbas/SUNWdtbax) installed" />
					<criterion test_ref="spt-106" negate="true" comment="Patch 108219-01 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3134" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0758</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" />
					<criterion test_ref="spt-46" negate="true" comment="Patch 117765-02 or later installed" />
					<criterion test_ref="spt-47" negate="true" comment="Patch 117767-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3250" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0757</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" />
					<criterion test_ref="spt-46" negate="true" comment="Patch 117765-02 or later installed" />
					<criterion test_ref="spt-47" negate="true" comment="Patch 117767-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3322" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Kerberos5</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0643</cveid>
			<dates>
				<created date="2004-10-12"/>
				<modified date="2005-01-14">Changed kerberos unknown test to solaris file contents test</modified>
				<status_change date="2004-10-13">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Double-free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="sft-222" comment="Kerberos 5 installed" />
					<criterion test_ref="spt-250" negate="true" comment="Patch 112908-15 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-1000" comment="test not supported in version 3 schema" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3465" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Solaris Volume Manager (SVM)</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description></description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-204" comment="Solaris 9 Installed" />
					<criterion test_ref="spt-241" negate="true" comment="Patch 113073-13 or later installed" />
					<criterion test_ref="sat-4" comment="Solaris Volume Manager package installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sft-220" comment="svm.init init script exists" />
					<criterion test_ref="ukn-1000" comment="test not supported in version 3 schema" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3601" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Solaris Runtime Linker</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
				<contributor organization="The MITRE Corporation">Brian Soby</contributor>
			</contributors>
			<cveid status="CAN">2003-0609</cveid>
			<dates>
				<created date="2004-12-29"/>
				<status_change date="2005-01-12">DRAFT</status_change>
				<status_change date="2005-02-02">INTERIM</status_change>
				<status_change date="2005-02-23">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="cmp-54" comment="Solaris 9 OR Patch 106950-14+ OR Patch 109147-07+ installed" />
					<criterion test_ref="spt-10" negate="true" comment="Patch 106950-14 or later installed" />
					<criterion test_ref="spt-11" negate="true" comment="Patch 109147-07 or later installed" />
					<criterion test_ref="spt-12" negate="true" comment="Patch 112963-09 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3603" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0761</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" />
					<criterion test_ref="spt-46" negate="true" comment="Patch 117765-02 or later installed" />
					<criterion test_ref="spt-47" negate="true" comment="Patch 117767-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3637" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>priocntl()</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-1296</cveid>
			<dates>
				<created date="2005-02-01"/>
				<status_change date="2005-02-01">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-33" negate="true" comment="Patch 106541-24 or later installed" />
					<criterion test_ref="spt-113" negate="true" comment="Patch 108528-18 or later installed" />
					<criterion test_ref="spt-114" negate="true" comment="Patch 112233-04 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL3799" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0542</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-263" negate="true" comment="Patch 113146-03 or later installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL3989" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0763</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" />
					<criterion test_ref="spt-46" negate="true" comment="Patch 117765-02 or later installed" />
					<criterion test_ref="spt-47" negate="true" comment="Patch 117767-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4030" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>DtMail</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0800</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-264" negate="true" comment="Patch 109613-07 or later installed" />
					<criterion test_ref="spt-265" negate="true" comment="Patch 112810-06 or later installed" />
					<criterion test_ref="sat-9" comment="CDE Desktop Applications (SUNWdtdst) installed                                                                                               " />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4047" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>bash, tcsh, cash, sh, ksh</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2000-1134</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>tcsh, csh, sh, and bash on various Unix systems follow symlinks when processing &lt;&lt; redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" />
					<criterion test_ref="cmp-69" negate="true" comment="Patches 108574-03, 108162-04, and 108416-02 or later installed" />
					<criterion test_ref="cmp-70" negate="true" comment="Patches 110943-01, 110898-02, and 109324-03 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4098" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>lpstat, libprint</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0999</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="cmp-71" comment="Solaris Printing Services installed (any SUNWpcr/SUNWpcu/SUNWpsr/SUNWpsu)" />
					<criterion test_ref="spt-43" negate="true" comment="Patch 107115-13 or later installed" />
					<criterion test_ref="spt-44" negate="true" comment="Patch 109320-07 or later installed" />
					<criterion test_ref="spt-45" negate="true" comment="Patch 113329-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4114" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2003-0020</cveid>
			<dates>
				<created date="2004-10-14"/>
				<modified date="2004-10-18">Change apache test to file test</modified>
				<modified date="2004-10-19">Changed apache test to package test</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="spt-254" negate="true" comment="Patch 113146-05 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration>
					<criterion test_ref="sct-207" comment="Apache running (httpd)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4190" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>Bind</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">2002-0651</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-30" negate="true" comment="Patch 106938-06 or later installed" />
					<criterion test_ref="spt-31" negate="true" comment="Patch 109326-09 or later installed" />
					<criterion test_ref="spt-32" negate="true" comment="Patch 112970-02 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="ukn-1000" comment="test not supported in version 3 schema" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4254" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Sun Cluster</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0543</cveid>
			<dates>
				<created date="2004-10-19"/>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-266" negate="true" comment="Patch 113505-02 or later installed" />
					<criterion test_ref="spt-267" negate="true" comment="Patch 113508-02 or later installed" />
					<criterion test_ref="spt-268" negate="true" comment="Patch 115054-01 or later installed" />
					<criterion test_ref="spt-269" negate="true" comment="Patch 115055-01 or later installed" />
					<criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sct-210" comment="Apache running with SunPlex Manager config" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4329" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>cachefsd</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2002-0085</cveid>
			<dates>
				<created date="2005-02-01"/>
				<status_change date="2005-02-01">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" />
					<criterion test_ref="spt-109" negate="true" comment="Patch 108800-02 or later installed" />
					<criterion test_ref="spt-110" negate="true" comment="Patch 110896-02 or later installed" />
					<criterion test_ref="spt-111" negate="true" comment="Patch 114008-01 or later installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" />
					<criterion test_ref="sct-201" comment="inetd running" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL4374" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>CDE</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CVE">1999-0693</cveid>
			<dates>
				<created date="2005-02-01"/>
				<status_change date="2005-02-01">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" />
					<criterion test_ref="spt-108" negate="true" comment="Patch 107893-05 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4383" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 7</solaris:platform>
				<product>lpstat</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0091</cveid>
			<dates>
				<created date="2005-02-01"/>
				<status_change date="2005-02-01">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="sut-203" comment="Solaris 7 Installed" />
					<criterion test_ref="sat-43" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" />
					<criterion test_ref="spt-112" negate="true" comment="Patch 107115-12 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4403" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<product>mozilla</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2004-0762</cveid>
			<dates>
				<created date="2005-01-19"/>
				<status_change date="2005-01-24">DRAFT</status_change>
				<status_change date="2005-02-16">INTERIM</status_change>
				<status_change date="2005-03-09">ACCEPTED</status_change>
			</dates>
			<description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" />
					<criterion test_ref="spt-46" negate="true" comment="Patch 117765-02 or later installed" />
					<criterion test_ref="spt-47" negate="true" comment="Patch 117767-02 or later installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL4416" class="vulnerability">
			<affected family="solaris">
				<solaris:platform>Sun Solaris 8</solaris:platform>
				<solaris:platform>Sun Solaris 9</solaris:platform>
				<product>Apache</product>
			</affected>
			<contributors>
				<submitter organization="The MITRE Corporation">Brian Soby</submitter>
			</contributors>
			<cveid status="CAN">2003-0987</cveid>
			<dates>
				<created date="2004-10-14"/>
				<modified date="2004-10-18">Change apache test to file test</modified>
				<modified date="2004-10-19">Changed apache test to package test</modified>
				<status_change date="2004-10-20">DRAFT</status_change>
				<status_change date="2004-11-03">INTERIM</status_change>
				<status_change date="2004-12-09">ACCEPTED</status_change>
			</dates>
			<description>mod_digest for Apache does not properly verify the nonce of a client response by using a AuthNonce secret</description>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" />
					<criterion test_ref="spt-253" negate="true" comment="Patch 116973-01 or later installed" />
					<criterion test_ref="spt-254" negate="true" comment="Patch 113146-05 or later installed" />
					<criterion test_ref="sat-5" comment="Apache (SUNWapch