<?xml version="1.0" encoding="UTF-8"?>
<oval xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval#redhat redhat-schema.xsd http://oval.mitre.org/XMLSchema/oval#unix unix-schema.xsd http://oval.mitre.org/XMLSchema/oval#independent independent-schema.xsd http://oval.mitre.org/XMLSchema/oval oval-schema.xsd" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:redhat="http://oval.mitre.org/XMLSchema/oval#redhat">
  <generator>
    <schema_version>4.1</schema_version>
    <timestamp>20051116211159</timestamp>
  </generator>
  <definitions>
    <definition id="OVAL2" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Mutt</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</description>
      <reference source="CVE">CVE-2003-0140</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-201" comment="balsa version is less than 2.0.6-2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-201" comment="/usr/bin/balsa is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>CUPS</product>
      </affected>
      <dates>
        <submitted date="2003-08-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</description>
      <reference source="CVE">CVE-2003-0195</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-202" comment="cups version is less than 1.1.17-13.3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-201" comment="cupsd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL28" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>skk</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.</description>
      <reference source="CVE">CVE-2003-0539</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-216" comment="Vulnerable config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL52" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>EOG</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</description>
      <reference source="CVE">CVE-2003-0165</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-205" comment="eog version is less than 2.2.0-2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-232" comment="eog is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL54" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</description>
      <reference source="CVE">CVE-2003-0081</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL55" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0159</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL69" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</description>
      <reference source="CVE">CVE-2003-0356</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL73" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</description>
      <reference source="CVE">CVE-2003-0357</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL75" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</description>
      <reference source="CVE">CVE-2003-0428</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL84" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</description>
      <reference source="CVE">CVE-2003-0429</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL88" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</description>
      <reference source="CVE">CVE-2003-0430</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL101" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.</description>
      <reference source="CVE">CVE-2003-0431</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL106" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.</description>
      <reference source="CVE">CVE-2003-0432</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL107" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ximian Evolution</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2003-0128</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL108" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ximian Evolution</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</description>
      <reference source="CVE">CVE-2003-0129</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL111" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ximian Evolution</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</description>
      <reference source="CVE">CVE-2003-0130</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL112" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.</description>
      <reference source="CVE">CVE-2003-0547</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL113" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.</description>
      <reference source="CVE">CVE-2003-0548</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL129" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.</description>
      <reference source="CVE">CVE-2003-0549</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL133" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GNU Ghostscript</product>
      </affected>
      <dates>
        <submitted date="2003-08-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.</description>
      <reference source="CVE">CVE-2003-0354</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-211" comment="ghostscript version is less than 7.05-32.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-262" comment="/usr/bin/gs is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL135" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GnuPG</product>
      </affected>
      <dates>
        <submitted date="2003-08-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.</description>
      <reference source="CVE">CVE-2003-0255</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-212" comment="gnupg version is less than 1.2.1-4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-263" comment="/usr/bin/gnupg is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL138" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GtkHTML</product>
      </affected>
      <dates>
        <submitted date="2003-09-02-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</description>
      <reference source="CVE">CVE-2003-0133</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-213" comment="gtkhtml version is less than 1.1.9-0.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL148" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GtkHTML</product>
      </affected>
      <dates>
        <submitted date="2003-09-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.</description>
      <reference source="CVE">CVE-2003-0541</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-214" comment="gtkhtml version is less than 1.1.9-0.9.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-266" comment="/usr/bin/evolution is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL150" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
      <reference source="CVE">CVE-2003-0020</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL151" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</description>
      <reference source="CVE">CVE-2003-0083</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL156" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</description>
      <reference source="CVE">CVE-2003-0132</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL164" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2005-06-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-15-09:48">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.</description>
      <reference source="CVE">CVE-2004-0975</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-22" comment="openssl, openssl-devel, OR openssl-perl older than 0.9.7a-33.15 or openssl096b older than 0.9.6b-16.22.3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-1" comment="/tmp is writable by everyone" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL169" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-09-05-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.</description>
      <reference source="CVE">CVE-2003-0192</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-203" comment="httpd.worker is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL173" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-09-05-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.</description>
      <reference source="CVE">CVE-2003-0253</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL183" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-09-05-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.</description>
      <reference source="CVE">CVE-2003-0254</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL193" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>KDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.</description>
      <reference source="CVE">CVE-2003-0690</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-217" comment="kdebase version is less than 3.1-15" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-278" comment="/usr/bin/kdm is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL215" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>KDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.</description>
      <reference source="CVE">CVE-2003-0692</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-217" comment="kdebase version is less than 3.1-15" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-278" comment="/usr/bin/kdm is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL230" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>krb5</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</description>
      <reference source="CVE">CVE-2003-0028</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-218" comment="krb5-server version is less than 1.2.7-14" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL244" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>krb5</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
      <reference source="CVE">CVE-2003-0082</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-218" comment="krb5-server version is less than 1.2.7-14" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL248" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>krb5</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</description>
      <reference source="CVE">CVE-2003-0138</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-219" comment="krb5-libs version is less than 1.2.7-14" negate="false"/>
          <criterion test_ref="cmp-289" comment="krb5-server or krb5-workstation installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL250" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>krb5</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</description>
      <reference source="CVE">CVE-2003-0139</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-219" comment="krb5-libs version is less than 1.2.7-14" negate="false"/>
          <criterion test_ref="cmp-289" comment="krb5-server or krb5-workstation installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL254" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</description>
      <reference source="CVE">CVE-2003-0127</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rrt-202" comment="kernel version = 2.4.20-6" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uut-2" comment="kernel 2.4.20-6 or earlier is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL260" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Netfilter</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</description>
      <reference source="CVE">CVE-2003-0187</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL261" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Netfilter</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.</description>
      <reference source="CVE">CVE-2003-0244</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL263" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Gaim</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Gaim before 1.3.1 allows remote attackers to cause a denial of service (crash) via a malformed MSN message that leads to a memory allocation of a large size, possibly due to an integer signedness error.</description>
      <reference source="CVE">CVE-2005-1934</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-21" comment="gaim RPM earlier than 1:1.3.1-0.el3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-56" comment="/usr/bin/gaim is executable by any user" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL278" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.</description>
      <reference source="CVE">CVE-2003-0246</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL284" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").</description>
      <reference source="CVE">CVE-2003-0247</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL292" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.</description>
      <reference source="CVE">CVE-2003-0248</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL295" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.</description>
      <reference source="CVE">CVE-2003-0364</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL304" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>/proc/tty/driver/serial</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</description>
      <reference source="CVE">CVE-2003-0461</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL309" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).</description>
      <reference source="CVE">CVE-2003-0462</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL311" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.</description>
      <reference source="CVE">CVE-2003-0464</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL327" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.</description>
      <reference source="CVE">CVE-2003-0476</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL328" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.</description>
      <reference source="CVE">CVE-2003-0501</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL345" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>php</product>
      </affected>
      <dates>
        <submitted date="2005-07-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.</description>
      <reference source="CVE">CVE-2005-1751</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-27" comment="php RPM prior to  0:4.3.2-24.ent" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-1" comment="/tmp is writable by everyone" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL350" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>php</product>
      </affected>
      <dates>
        <submitted date="2005-07-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</description>
      <reference source="CVE">CVE-2005-1921</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-27" comment="php RPM prior to  0:4.3.2-24.ent" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-4" comment="/etc/httpd/conf.d/php.conf exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL358" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>cpio</product>
      </affected>
      <dates>
        <submitted date="2005-08-08-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-09-07:56">DRAFT</status_change>
        <status_change date="2005-08-24-09:56">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.</description>
      <reference source="CVE">CVE-2005-1111</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-28" comment="cpio rpm is older than 0:2.5-4.RHEL3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-61" comment="/bin/cpio is executable by all" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL380" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.</description>
      <reference source="CVE">CVE-2003-0550</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL382" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>gzip</product>
      </affected>
      <dates>
        <submitted date="2005-06-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</description>
      <reference source="CVE">CVE-2005-1228</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-7" comment="gzip RPM earlier than 0:1.3.3-12rhel3" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="upt-529" comment="/usr/bin/gzip is executable" negate="false"/>
          <criterion test_ref="upt-428" comment="/usr/bin/gunzip is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL384" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.</description>
      <reference source="CVE">CVE-2003-0551</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL385" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.</description>
      <reference source="CVE">CVE-2003-0552</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL386" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.</description>
      <reference source="CVE">CVE-2003-0619</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL387" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.</description>
      <reference source="CVE">CVE-2003-0699</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL401" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.</description>
      <reference source="CVE">CVE-2003-0700</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL411" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Konqueror</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.</description>
      <reference source="CVE">CVE-2003-0459</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-224" comment="kdelibs version is less than 3.1-12" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-304" comment="/usr/bin/konqueror is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL417" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
      <reference source="CVE">CVE-2005-2265</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL423" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>LPRng</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</description>
      <reference source="CVE">CVE-2003-0136</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-225" comment="lprng version is less than 3.8.19-3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-83" comment="psbanner is world-executable" negate="false"/>
          <criterion test_ref="rlt-204" comment="lpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL430" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>lv</product>
      </affected>
      <dates>
        <submitted date="2003-08-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</description>
      <reference source="CVE">CVE-2003-0188</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-226" comment="lv version is less than 4.49.4-9.9.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL434" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Mutt</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</description>
      <reference source="CVE">CVE-2003-0140</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-227" comment="mutt version is less than 1.4.1-1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-305" comment="/usr/bin/mutt is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL436" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>MySQL</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</description>
      <reference source="CVE">CVE-2003-0073</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-205" comment="mysqld is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL442" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>MySQL</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</description>
      <reference source="CVE">CVE-2003-0150</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-205" comment="mysqld is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL443" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>nfs-utils</product>
      </affected>
      <dates>
        <submitted date="2003-09-02-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.</description>
      <reference source="CVE">CVE-2003-0252</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-229" comment="nfs-utils version is less than 1.0.1-3.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-206" comment="rpc.mountd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL445" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</description>
      <reference source="CVE">CVE-2003-0190</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-230" comment="openssh-server version is less than 3.5p1-6.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-207" comment="sshd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL446" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.</description>
      <reference source="CVE">CVE-2003-0682</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-207" comment="sshd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL447" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</description>
      <reference source="CVE">CVE-2003-0693</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-207" comment="sshd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL452" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.</description>
      <reference source="CVE">CVE-2003-0695</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-207" comment="sshd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL461" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</description>
      <reference source="CVE">CVE-2003-0131</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-914" comment="affected version of SSL and TLS components for OpenSSL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL466" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</description>
      <reference source="CVE">CVE-2003-0147</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-914" comment="affected version of SSL and TLS components for OpenSSL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL469" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>pam_smb</product>
      </affected>
      <dates>
        <submitted date="2003-09-05-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0686</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-237" comment="pam_smb version is less than 1.1.6-9.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL470" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>CGI.pm</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.</description>
      <reference source="CVE">CVE-2003-0615</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-238" comment="perl-CGI version is less than 2.81-88.3" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL485" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>php</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.</description>
      <reference source="CVE">CVE-2003-0442</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-239" comment="php version is less than 4.2.2-17.2" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL499" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>pine</product>
      </affected>
      <dates>
        <submitted date="2003-09-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.</description>
      <reference source="CVE">CVE-2003-0720</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-240" comment="pine version is less than 4.44-19.90.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-314" comment="/usr/bin/pine is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL503" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>pine</product>
      </affected>
      <dates>
        <submitted date="2003-09-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.</description>
      <reference source="CVE">CVE-2003-0721</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-240" comment="pine version is less than 4.44-19.90.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-314" comment="/usr/bin/pine is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL522" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Postfix</product>
      </affected>
      <dates>
        <submitted date="2003-09-02-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.</description>
      <reference source="CVE">CVE-2003-0468</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-241" comment="postfix version is less than 1.1.12-1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-208" comment="smtpd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL544" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Postfix</product>
      </affected>
      <dates>
        <submitted date="2003-09-02-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.</description>
      <reference source="CVE">CVE-2003-0540</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-241" comment="postfix version is less than 1.1.12-1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-208" comment="smtpd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL550" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
      <reference source="CVE">CVE-2005-2270</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL552" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>smbd</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0085</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-209" comment="smbd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL554" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</description>
      <reference source="CVE">CVE-2003-0086</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL564" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</description>
      <reference source="CVE">CVE-2003-0196</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-210" comment="smbd is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL567" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Samba, Samba-TNG</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0201</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-210" comment="smbd is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL569" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>semi MIME library</product>
      </affected>
   