<?xml version="1.0" encoding="UTF-8"?>
<oval xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval#unix unix-schema.xsd http://oval.mitre.org/XMLSchema/oval#independent independent-schema.xsd http://oval.mitre.org/XMLSchema/oval#solaris solaris-schema.xsd http://oval.mitre.org/XMLSchema/oval oval-schema.xsd" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:solaris="http://oval.mitre.org/XMLSchema/oval#solaris">
  <generator>
    <schema_version>4.1</schema_version>
    <timestamp>20051116211256</timestamp>
  </generator>
  <definitions>
    <definition id="OVAL7" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL9" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-28-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-205" comment="Patches 108827-30 and 108901-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL10" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>xlock</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
      <reference source="CVE">CVE-2001-0652</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-8" comment="File xlock exists" negate="false"/>
          <criterion test_ref="spt-203" comment="Patch 108652-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-209" comment="File xlock SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL11" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2002-09-25-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0796</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-9" comment="File snmpdx exists" negate="false"/>
          <criterion test_ref="spt-204" comment="Patch 108869-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL14" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-205" comment="Patch 108652-52 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL15" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-206" comment="Patch 110286-09 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL31" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to include Solaris 9 and Solaris 9 patch info">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:24">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
      <reference source="CVE">CVE-2002-0033</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-207" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL33" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-208" comment="Patch 108376-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL34" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-209" comment="Patch 111600-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL41" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-210" comment="Patch 112899-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL42" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-02-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-223" comment="Patches 106942-22 and 108451-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL43" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to add patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:25">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
      <reference source="CVE">CVE-2002-0084</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL47" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-213" comment="Patch 111826-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL48" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL56" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.yppasswdd</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
      <reference source="CVE">CVE-2001-0779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-16" comment="File rpc.yppasswdd exists" negate="false"/>
          <criterion test_ref="spt-214" comment="Patch 111596-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-7" comment="rpc.yppasswdd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL60" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL62" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>mibiisa</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-17" comment="File mibiisa exists" negate="false"/>
          <criterion test_ref="spt-215" comment="Patch 107709-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-8" comment="mibiisa running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL65" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
          <criterion test_ref="spt-216" comment="Patch 107337-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL67" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-217" comment="Patch 110453-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL68" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-218" comment="Patch 108721-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL70" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-219" comment="Patch 108949-07 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL74" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-220" comment="Patch 106934-04 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL79" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-221" comment="Patch 112846-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL80" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-222" comment="Patch 107893-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL86" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>lbxproxy</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
      <reference source="CVE">CVE-2002-0090</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-19" comment="File lbxproxy exists" negate="false"/>
          <criterion test_ref="spt-223" comment="Patch 108652-51 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL91" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-222" comment="Patch 107893-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL94" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mibiisa</product>
      </affected>
      <dates>
        <submitted date="2002-09-25-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-17" comment="File mibiisa exists" negate="false"/>
          <criterion test_ref="spt-204" comment="Patch 108869-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-8" comment="mibiisa running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL97" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-27-12:00" comment="Updated to add patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-28-12:00" comment="Added Solaris 9 and Solaris 9 patch test to the definition">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:28">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
      <reference source="CVE">CVE-2002-0084</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-110" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL102" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>rpc.yppasswdd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
      <reference source="CVE">CVE-2001-0779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-16" comment="File rpc.yppasswdd exists" negate="false"/>
          <criterion test_ref="spt-224" comment="Patch 111590-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-7" comment="rpc.yppasswdd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL114" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0796</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-9" comment="File snmpdx exists" negate="false"/>
          <criterion test_ref="spt-215" comment="Patch 107709-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL120" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-20" comment="File kcms_server exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL124" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Added patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:29">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
      <reference source="CVE">CVE-2002-0033</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL131" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>xlock</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
      <reference source="CVE">CVE-2001-0652</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-8" comment="File xlock exists" negate="false"/>
          <criterion test_ref="spt-225" comment="Patch 108376-30 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-209" comment="File xlock SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL149" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2003-09-08-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-21" comment="File fs.auto exists" negate="false"/>
          <criterion test_ref="uft-22" comment="File xfs exists" negate="false"/>
          <criterion test_ref="spt-226" comment="Patch 109862-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-267" comment="File xfs executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL152" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2003-09-08-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-21" comment="File fs.auto exists" negate="false"/>
          <criterion test_ref="uft-22" comment="File xfs exists" negate="false"/>
          <criterion test_ref="spt-227" comment="Patch 108117-06 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-267" comment="File xfs executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL175" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-206" comment="Patch 110286-09 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL177" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
      <reference source="CVE">CVE-2002-0679</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-228" comment="Patch 107893-20 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL179" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>lbxproxy</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
      <reference source="CVE">CVE-2002-0090</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-19" comment="File lbxproxy exists" negate="false"/>
          <criterion test_ref="spt-229" comment="Patch 107654-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL192" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
      <reference source="CVE">CVE-2002-0679</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-230" comment="Patch 110286-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL195" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2003-01-24-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-20" comment="File kcms_server exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL449" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.</description>
      <reference source="CVE">CVE-2002-1220</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL555" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2004-12-28-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</description>
      <reference source="CVE">CVE-2001-0422</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="spt-4" comment="Patch 108376-25 or later installed" negate="true"/>
          <criterion test_ref="spt-5" comment="Patch 108652-30 or later installed" negate="true"/>
          <criterion test_ref="sat-12" comment="X Window System platform software (SUNWxwplt) installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL592" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-1351</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-87" comment="Solaris 7 or 8 OR Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed" negate="false"/>
          <criterion test_ref="spt-68" comment="Patch 118239-01 or later installed" negate="true"/>
          <criterion test_ref="spt-69" comment="Patch 116984-01 or later installed" negate="true"/>
          <criterion test_ref="spt-70" comment="Patch 117455-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-19" comment="in.rwhod is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1048" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0012</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-48" comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" negate="false"/>
          <criterion test_ref="spt-104" comment="Patch 107709-18 or later installed" negate="true"/>
          <criterion test_ref="spt-105" comment="Patch 108869-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1099" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-14-12:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-01-24-02:33">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false"/>
          <criterion test_ref="spt-255" comment="Patch 112808-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1110" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</description>
      <reference source="CVE">CVE-2003-0058</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-157" comment="Solaris 7 and Solaris Enterprise Authentication Mechanism OR Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-96" comment="Patch 112536-02 or later installed" negate="true"/>
          <criterion test_ref="spt-99" comment="Patch 112908-04 or later installed" negate="true"/>
          <criterion test_ref="spt-97" comment="Patch 112237-07 or later installed" negate="true"/>
          <criterion test_ref="spt-98" comment="Patch 112390-07 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1127" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>uucp</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Product set to uucp; was mistakenly .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.</description>
      <reference source="CVE">CVE-2004-1359</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-42" comment="Networking UUCP Utilities - Usr (SUNWbnuu) installed" negate="false"/>
          <criterion test_ref="spt-86" comment="Patch 106952-04 or later installed" negate="true"/>
          <criterion test_ref="spt-87" comment="Patch 111570-03 or later installed" negate="true"/>
          <criterion test_ref="spt-88" comment="Patch 113322-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1227" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.</description>
      <reference source="CVE">CVE-2004-0760</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1273" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sadmin</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-02:06">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-15-02:21" comment="Added check for sadmind called with strong authentication">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.</description>
      <reference source="CVE">CVE-2003-0722</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-7" comment="System and Network Administration Framework Installed" negate="false"/>
          <criterion test_ref="spt-259" comment="Patch 116457-02 or later installed" negate="true"/>
          <criterion test_ref="spt-260" comment="Patch 116442-01 or later installed" negate="true"/>
          <criterion test_ref="spt-261" comment="Patch 116454-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="sit-209" comment="inetd.conf contains sadmind" negate="false"/>
          <criterion test_ref="sit-210" comment="Sadmin called using strong authentication" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1436" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:37">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-12-12:47" comment="Added patch 107180-31 test for Solaris 7.  Changed vulnerable software test logic a little">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.</description>
      <reference source="CVE">CVE-2004-0368</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-23" comment="File /usr/dt/bin/dtlogin exists" negate="false"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-231" comment="Patch 108919-21 or later installed" negate="false"/>
          <criterion test_ref="spt-232" comment="Patch 112807-09 or later installed" negate="false"/>
          <criterion test_ref="spt-249" comment="Patch 107180-31 or later installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-9" comment="dtlogin running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1467" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.</description>
      <reference source="CVE">CVE-2002-1318</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-28" comment="Samba - Usr (SUNWsmbau) installed" negate="false"/>
          <criterion test_ref="spt-48" comment="Patch 114684-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-15" comment="smbd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1479" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.</description>
      <reference source="CVE">CVE-2004-0599</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1482" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console (SMC)</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Affected product changed to Sun Management Console (SMC); mistakenly was .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inacessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.</description>
      <reference source="CVE">CVE-2004-1354</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="sat-40" comment="Solaris Management Console Web Components (SUNWwbmc) installed" negate="false"/>
          <criterion test_ref="spt-76" comment="Patch 111313-02 or later installed" negate="true"/>
          <criterion test_ref="spt-77" comment="Patch 116807-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-20" comment="smcboot running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1528" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>tcsh</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Affected product changed to tcsh; mistakenly was .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.</description>
      <reference source="CVE">CVE-2003-1024</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="spt-95" comment="Patch 110943-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1654" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.</description>
      <reference source="CVE">CVE-2004-1349</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="sat-36" comment="GNU Zip (gzip, SUNWgzip) installed" negate="false"/>
          <criterion test_ref="spt-67" comment="Patch 112668-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1684" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>sendfilev()</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</description>
      <reference source="CVE">CVE-2004-1356</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-81" comment="Patch 108528-27 or later installed" negate="true"/>
          <criterion test_ref="spt-80" comment="Patch 112233-12 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1707" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Sun Enterprise Storage Manager (ESM)</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description/>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="sat-1" comment="Sun Enterprise Storage Manager installed" negate="false"/>
          <criterion test_ref="spt-242" comment="Patch 117367-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1732" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>/usr/lib/print/conv_fix</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.</description>
      <reference source="CVE">CVE-2004-1360</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-43" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" negate="false"/>
          <criterion test_ref="spt-89" comment="Patch 107115-14 or later installed" negate="true"/>
          <criterion test_ref="spt-90" comment="Patch 109320-09 or later installed" negate="true"/>
          <criterion test_ref="spt-91" comment="Patch 113329-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1844" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>NIS</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2001-1328</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-13" comment="NIS/NIS+ Utilities installed (SUNWnisu)" negate="false"/>
          <criterion test_ref="spt-8" comment="Patch 108750-02 or later installed" negate="true"/>
          <criterion test_ref="spt-9" comment="Patch 110322-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-3" comment="ypbind running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1880" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</description>
      <reference source="CVE">CVE-1999-0689</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-49" comment="CDE Daemons (SUNWdtdmn) installed" negate="false"/>
          <criterion test_ref="spt-107" comment="Patch 108221-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1905" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</description>
      <reference source="CVE">CVE-2003-0092</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false"/>
          <criterion test_ref="spt-100" comment="Patch 107702-12 or later installed" negate="true"/>
          <criterion test_ref="spt-101" comment="Patch 109354-19 or later installed" negate="true"/>
          <criterion test_ref="spt-102" comment="Patch 114497-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1970" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console (SMC)</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</description>
      <reference source="CVE">CVE-2003-0466</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-34" comment="FTP Server - Usr (SUNWftpu) installed" negate="false"/>
          <criterion test_ref="spt-60" comment="Patch 114564-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-3" comment="inetd.conf contains in.ftpd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1982" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:13">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:12" comment="Changed apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:17" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</description>
      <reference source="CVE">CVE-2004-0174</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2002" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
      </affected>
      <dates>
        <submitted date="2004-10-11-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed two unknown tests for kerberos configuration to Solaris text file contents tests ">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
      <reference source="CVE">CVE-2004-0523</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-246" comment="Patch 112908-16 or later installed" negate="true"/>
          <criterion test_ref="spt-247" comment="Patch 112536-05 or later installed" negate="true"/>
          <criterion test_ref="cmp-1104" comment="Patches 112237-11 and 112390-09 or greater installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
          <criterion test_ref="tft-6" comment="/etc/krb5/krb5.conf is configured with explicit or rules-based mapping" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2011" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified sat-10 - Changed test to pattern match to check for 64bit version of Core Solaris">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-14-12:00" comment="modified sat-10 - Changed regular expression to properly check for 64bit package">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-01-24-02:36">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.</description>
      <reference source="CVE">CVE-2003-0914</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-270" comment="Patch 106938-08 or later installed" negate="true"/>
          <criterion test_ref="spt-271" comment="Patch 109326-13 or later installed" negate="true"/>
          <criterion test_ref="spt-272" comment="Patch 112970-06 or later installed" negate="true"/>
          <criterion test_ref="sat-10" comment="Core Solaris (SUNWcsu/SUNWcsxu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2025" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>login</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.</description>
      <reference source="CVE">CVE-2001-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="spt-6" comment="Patch 112300-01 or later installed" negate="true"/>
          <criterion test_ref="spt-7" comment="Patch 111085-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2065" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>pam_krb5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed all unknown tests to solaris file contents tests">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.</description>
      <reference source="CVE">CVE-2004-0653</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-248" comment="Patch 112908-13 or later installed" negate="true"/>
          <criterion test_ref="spt-236" comment="Patch 112908-12 installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-7" comment="/etc/pam.conf is configured to use pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled" negate="false"/>
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
          <criterion test_ref="tft-8" comment="/etc/syslog.conf is configured to log &quot;debug&quot; level messages for at least daemon" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2094" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.</description>
      <reference source="CVE">CVE-2002-1221</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-24" comment="Patch 106938-07 or later installed" negate="true"/>
          <criterion test_ref="spt-25" comment="Patch 109326-10 or later installed" negate="true"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2139" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed kerberos unknown test to solaris file contents test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.</description>
      <reference source="CVE">CVE-2004-0644</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-250" comment="Patch 112908-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2163" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2004-12-30-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0201</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-15" comment="Samba (SUNWsmbar) installed" negate="false"/>
          <criterion test_ref="spt-15" comment="Patch 114684-02 or later installed" negate="true"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="cmp-56" comment="Inetd running and inetd.conf contains smbd" negate="false"/>
          <criterion test_ref="uct-15" comment="smbd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2183" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2004-12-22-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <modified date="2005-01-27-12:00" comment="Removed &quot;Sendmail running&quot; configuration test.  Sendmail installs as SUID root">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-04-20-12:13">INTERIM</status_change>
        <status_change date="2005-05-11-05:41">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.</description>
      <reference source="CVE">CVE-2002-0906</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-3" comment="Sendmail - root (SUNWsndmr) installed" negate="false"/>
          <criterion test_ref="spt-2" comment="Patch 113575-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2222" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.</description>
      <reference source="CVE">CVE-2002-1337</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-14" comment="Sendmail - user (SUNWsndmu) installed" negate="false"/>
          <criterion test_ref="spt-63" comment="Patch 107684-08 or later installed" negate="true"/>
          <criterion test_ref="spt-64" comment="Patch 110615-08 or later installed" negate="true"/>
          <criterion test_ref="spt-65" comment="Patch 113575-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-11" comment="Sendmail running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2248" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libc</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).</description>
      <reference source="CVE">CVE-2002-1265</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-287" comment="All RPC w/TCP patches installed - CVE-2002-1265" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-21" comment="rpcbind running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2378" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
      <reference source="CVE">CVE-2004-0597</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2418" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.</description>
      <reference source="CVE">CVE-2004-0764</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2423" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>NIS</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.</description>
      <reference source="CVE">CVE-2002-1199</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-20" comment="NIS Server - User (SUNWypu) installed" negate="false"/>
          <criterion test_ref="spt-33" comment="Patch 106541-24 or later installed" negate="true"/>
          <criterion test_ref="spt-34" comment="Patch 109328-03 or later installed" negate="true"/>
          <criterion test_ref="spt-35" comment="Patch 113579-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-17" comment="ypxfrd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2426" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Basic Security Module</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-09:40">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
      </dates>
      <description>Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).</description>
      <reference source="CVE">CVE-2004-0654</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="spt-233" comment="Patch 106541-33 or later installed" negate="true"/>
          <criterion test_ref="spt-234" comment="Patch 109007-18 or later installed" negate="true"/>
          <criterion test_ref="spt-235" comment="Patch 114332-12 or later installed" negate="true"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="ukn-26" comment="Basic Security Module enabled" negate="false"/>
          <criterion test_ref="ukn-27" comment="Auditing Administrative or System-Wide Administrative audit classes" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2536" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
      <reference source="CVE">CVE-2003-0082</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Vulnerability exists in standard Solaris kerberos and SEAM.  This definition only covers Solaris kerberos</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-74" comment="Kerberos v5 (any SUNWkrbr/SUNWkrbu/SUNWkrbux) installed" negate="false"/>
          <criterion test_ref="cmp-79" comment="Patches 112237-09 and 112390-08 or later installed" negate="true"/>
          <criterion test_ref="cmp-81" comment="Patches 112925-03,112923-03,112921-02, and 112908-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2539" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).</description>
      <reference source="CVE">CVE-2002-1219</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-24" comment="Patch 106938-07 or later installed" negate="true"/>
          <criterion test_ref="spt-25" comment="Patch 109326-10 or later installed" negate="true"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2572" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0598</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2590" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sun Cluster</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:11">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.</description>
      <reference source="CVE">CVE-2003-0545</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-266" comment="Patch 113505-02 or later installed" negate="true"/>
          <criterion test_ref="spt-267" comment="Patch 113508-02 or later installed" negate="true"/>
          <criterion test_ref="spt-268" comment="Patch 115054-01 or later installed" negate="true"/>
          <criterion test_ref="spt-269" comment="Patch 115055-01 or later installed" negate="true"/>
          <criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" negate="false"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-13" comment="Apache running with SunPlex Manager config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2592" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-18" comment="Kodak Color Managment Server (KCMS) Runtime Environment (SUNWkcsrt/SUNWkcsrx) installed" negate="false"/>
          <criterion test_ref="spt-20" comment="Patch 114636-01 or later installed" negate="true"/>
          <criterion test_ref="spt-21" comment="Patch 107337-03 or later installed" negate="true"/>
          <criterion test_ref="spt-22" comment="Patch 111400-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2621" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Sun Crypto Accelerator 4000</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-09:44">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0079</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-243" comment="Patch 114796-04 or later installed" negate="true"/>
          <criterion test_ref="sat-2" comment="Sun Crypto Accelerator 4000 software installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2665" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Sun Am7990 Ethernet Driver</product>
      </affected>
      <dates>
        <submitted date="2004-12-30-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
      </dates>
      <description>Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</description>
      <reference source="CVE">CVE-2003-0001</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-16" comment="Patch 112604-02 or later installed" negate="true"/>
          <criterion test_ref="spt-17" comment="Patch 112609-02 or later installed" negate="true"/>
          <criterion test_ref="spt-18" comment="Patch 115172-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-30" comment="Lance Ethernet (le) interface configured to start" negate="false"/>
          <criterion test_ref="ukn-2" comment="Lance Ethernet interface in use" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2719" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2004-12-30-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</description>
      <reference source="CVE">CVE-2003-0693</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="spt-19" comment="Patch 113273-04 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-16" comment="sshd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2770" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-14-12:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-01-24-02:39">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false"/>
          <criterion test_ref="spt-255" comment="Patch 112808-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2816" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-21" comment="X Window System Font Server (SUNWxwfs) installed" negate="false"/>
          <criterion test_ref="spt-42" comment="Patch 113923-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2972" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>TCP/IP</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</description>
      <reference source="CVE">CVE-2004-1355</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-78" comment="Patch 116895-01 or later installed" negate="true"/>
          <criterion test_ref="spt-79" comment="Patch 117000-03 or later installed" negate="true"/>
          <criterion test_ref="spt-80" comment="Patch 112233-12 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2975" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
      <reference source="CVE">CVE-2003-0694</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-14" comment="Sendmail - user (SUNWsndmu) installed" negate="false"/>
          <criterion test_ref="spt-13" comment="Patch 107684-10 or later installed" negate="true"/>
          <criterion test_ref="spt-14" comment="Patch 110615-10 or later installed" negate="true"/>
          <criterion test_ref="spt-240" comment="Patch 113575-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3078" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</description>
      <reference source="CVE">CVE-1999-0691</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-32" comment="CDE application basic runtime environment (SUNWdtbas/SUNWdtbax) installed" negate="false"/>
          <criterion test_ref="spt-106" comment="Patch 108219-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3134" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.</description>
      <reference source="CVE">CVE-2004-0758</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3250" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0757</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3322" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed kerberos unknown test to solaris file contents test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0643</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-250" comment="Patch 112908-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3400" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-1352</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-96" comment="Solaris 7 or 8 OR Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed" negate="false"/>
          <criterion test_ref="spt-71" comment="Patch 118313-01 or later installed" negate="true"/>
          <criterion test_ref="spt-72" comment="Patch 116986-02 or later installed" negate="true"/>
          <criterion test_ref="spt-73" comment="Patch 116774-03 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3465" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Volume Manager (SVM)</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-05:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-05:00">DRAFT</status_change>
        <status_change date="2005-02-16-05:00">INTERIM</status_change>
        <status_change date="2005-03-09-05:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.</description>
      <reference source="CVE">CVE-2004-1346</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="spt-241" comment="Patch 113073-13 or later installed" negate="true"/>
          <criterion test_ref="sat-4" comment="Solaris Volume Manager package installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-24" comment="svm.init init script exists" negate="false"/>
          <criterion test_ref="tft-9" comment="/etc/vfstab is configured with SVM devices" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3505" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>sshd</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.</description>
      <reference source="CVE">CVE-2004-1357</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-41" comment="Secure Shell Server - Usr (SUNWsshdu) installed" negate="false"/>
          <criterion test_ref="spt-83" comment="Patch 113273-05 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-2" comment="/etc/ssh/sshd_config has 0.0.0.0 as ListenAddress" negate="false"/>
          <criterion test_ref="uct-16" comment="sshd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3567" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Basic Security Module</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.</description>
      <reference source="CVE">CVE-2004-1358</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="spt-84" comment="Patch 114332-08 installed" negate="false"/>
          <criterion test_ref="spt-85" comment="Patch 114332-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-3" comment="/etc/system has BSM enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3601" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Solaris Runtime Linker</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.</description>
      <reference source="CVE">CVE-2003-0609</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="cmp-54" comment="Solaris 9 OR Patch 106950-14+ OR Patch 109147-07+ installed" negate="false"/>
          <criterion test_ref="spt-10" comment="Patch 106950-14 or later installed" negate="true"/>
          <criterion test_ref="spt-11" comment="Patch 109147-07 or later installed" negate="true"/>
          <criterion test_ref="spt-12" comment="Patch 112963-09 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3603" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.</description>
      <reference source="CVE">CVE-2004-0761</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3606" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:26">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
      </dates>
      <description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</description>
      <reference source="CVE">CVE-2003-0681</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="sat-3" comment="Sendmail - root (SUNWsndmr) installed" negate="false"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-238" comment="Patch 107684-11 or later installed" negate="true"/>
          <criterion test_ref="spt-239" comment="Patch 110615-11 or later installed" negate="true"/>
          <criterion test_ref="spt-240" comment="Patch 113575-05 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-11" comment="Sendmail running" negate="false"/>
          <criterion test_ref="ukn-36" comment="Sendmail has recipient or final rulesets" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3637" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>priocntl()</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.</description>
      <reference source="CVE">CVE-2002-1296</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-33" comment="Patch 106541-24 or later installed" negate="true"/>
          <criterion test_ref="spt-113" comment="Patch 108528-18 or later installed" negate="true"/>
          <criterion test_ref="spt-114" comment="Patch 112233-04 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3799" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:08">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
      <reference source="CVE">CVE-2003-0542</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-263" comment="Patch 113146-03 or later installed" negate="true"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3831" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>sendfilev()</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.</description>
      <reference source="CVE">CVE-2001-0414</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-35" comment="NTP daemon - Usr (SUNWntpu) installed" negate="false"/>
          <criterion test_ref="spt-61" comment="Patch 109409-04 or later installed" negate="true"/>
          <criterion test_ref="spt-62" comment="Patch 109667-04 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-18" comment="xntpd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3960" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).</description>
      <reference source="CVE">CVE-2004-1348</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-66" comment="Patch 109326-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-31" comment="File /etc/named.conf exists " negate="false"/>
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3989" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.</description>
      <reference source="CVE">CVE-2004-0763</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4030" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>DtMail</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:09">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.</description>
      <reference source="CVE">CVE-2004-0800</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-264" comment="Patch 109613-07 or later installed" negate="true"/>
          <criterion test_ref="spt-265" comment="Patch 112810-06 or later installed" negate="true"/>
          <criterion test_ref="sat-9" comment="CDE Desktop Applications (SUNWdtdst) installed                                                                                               " negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4047" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>bash, tcsh, cash, sh, ksh</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing &lt;&lt; redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.</description>
      <reference source="CVE">CVE-2000-1134</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="cmp-69" comment="Patches 108574-03, 108162-04, and 108416-02 or later installed" negate="true"/>
          <criterion test_ref="cmp-70" comment="Patches 110943-01, 110898-02, and 109324-03 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4098" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>lpstat, libprint</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.</description>
      <reference source="CVE">CVE-2003-0999</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="cmp-71" comment="Solaris Printing Services installed (any SUNWpcr/SUNWpcu/SUNWpsr/SUNWpsu)" negate="false"/>
          <criterion test_ref="spt-43" comment="Patch 107115-13 or later installed" negate="true"/>
          <criterion test_ref="spt-44" comment="Patch 109320-07 or later installed" negate="true"/>
          <criterion test_ref="spt-45" comment="Patch 113329-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4114" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:14">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:14" comment="Change apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:18" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
      <reference source="CVE">CVE-2003-0020</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4190" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.</description>
      <reference source="CVE">CVE-2002-0651</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-30" comment="Patch 106938-06 or later installed" negate="true"/>
          <criterion test_ref="spt-31" comment="Patch 109326-09 or later installed" negate="true"/>
          <criterion test_ref="spt-32" comment="Patch 112970-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-4" comment="/etc/nsswitch.conf configured to resolve hosts through DNS" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4254" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sun Cluster</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:10">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.</description>
      <reference source="CVE">CVE-2003-0543</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-266" comment="Patch 113505-02 or later installed" negate="true"/>
          <criterion test_ref="spt-267" comment="Patch 113508-02 or later installed" negate="true"/>
          <criterion test_ref="spt-268" comment="Patch 115054-01 or later installed" negate="true"/>
          <criterion test_ref="spt-269" comment="Patch 115055-01 or later installed" negate="true"/>
          <criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" negate="false"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-13" comment="Apache running with SunPlex Manager config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4329" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.</description>
      <reference source="CVE">CVE-2002-0085</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
          <criterion test_ref="spt-110" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4374" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</description>
      <reference source="CVE">CVE-1999-0693</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false"/>
          <criterion test_ref="spt-108" comment="Patch 107893-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4383" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>lpstat</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</description>
      <reference source="CVE">CVE-2003-0091</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-43" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" negate="false"/>
          <criterion test_ref="spt-112" comment="Patch 107115-12 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4403" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.</description>
      <reference source="CVE">CVE-2004-0762</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4416" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:14">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:15" comment="Change apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:19" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</description>
      <reference source="CVE">CVE-2003-0987</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4430" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
      <reference source="CVE">CVE-2003-0082</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Vulnerability exists in standard Solaris kerberos and SEAM.  This definition only covers SEAM</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-29" comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false"/>
          <criterion test_ref="cmp-73" comment="Patches 112536-04 and 110057-07 or later installed" negate="true"/>
          <criterion test_ref="spt-51" comment="Patch 110060-04 or later installed" negate="true"/>
          <criterion test_ref="spt-52" comment="Patch 116462-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4561" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>kernel</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.</description>
      <reference source="CVE">CVE-2003-0669</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-92" comment="Patch 106541-25 or later installed" negate="true"/>
          <criterion test_ref="spt-93" comment="Patch 108528-19 or later installed" negate="true"/>
          <criterion test_ref="spt-94" comment="Patch 112233-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4574" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sun Cluster</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:10">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.</description>
      <reference source="CVE">CVE-2003-0544</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-266" comment="Patch 113505-02 or later installed" negate="true"/>
          <criterion test_ref="spt-267" comment="Patch 113508-02 or later installed" negate="true"/>
          <criterion test_ref="spt-268" comment="Patch 115054-01 or later installed" negate="true"/>
          <criterion test_ref="spt-269" comment="Patch 115055-01 or later installed" negate="true"/>
          <criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" negate="false"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-13" comment="Apache running with SunPlex Manager config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4629" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0722</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4661" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-03:18">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:16">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0772</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-250" comment="Patch 112908-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-12" comment="Kerberos Key Distribution Center (krb5kdc) running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4670" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:13">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:16" comment="Changes apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:19" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</description>
      <reference source="CVE">CVE-2003-0993</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4728" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Sun RPC</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Specific applications using this library are not tested for because Suns advisory only provides a sample of known vulnerable applications and states that they are still investigating.</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="cmp-63" comment="Patches 106942-22 and 108451-06 or later installed" negate="true"/>
          <criterion test_ref="cmp-205" comment="Patches 108827-30 and 108901-06" negate="true"/>
          <criterion test_ref="cmp-64" comment="Patches 113319-01 and 112233-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4756" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</description>
      <reference source="CVE">CVE-2004-0718</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4834" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>LDAP</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.</description>
      <reference source="CVE">CVE-2004-1353</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-74" comment="Patch 108993-38 or later installed" negate="true"/>
          <criterion test_ref="spt-75" comment="Patch 112960-17 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-1" comment="/etc/nsswitch.conf configured to use LDAP with RBAC" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4863" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:12">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:16" comment="Changed apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:20" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</description>
      <reference source="CVE">CVE-2004-0492</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4936" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed kerberos unknown test to solaris file contents test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0642</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-250" comment="Patch 112908-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5141" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.</description>
      <reference source="CVE">CVE-2003-0834</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="cmp-82" comment="CDE Application Runtime or CDE Separable Help (any SUNWdtbas/SUNWdtbax/SUNWdthep) installed " negate="false"/>
          <criterion test_ref="spt-256" comment="Patch 107178-03 or later installed" negate="true"/>
          <criterion test_ref="spt-257" comment="Patch 108949-08 or later installed" negate="true"/>
          <criterion test_ref="spt-258" comment="Patch 116308-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100108" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</description>
      <reference source="CVE">CVE-2003-0987</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100109" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
      <reference source="CVE">CVE-2003-0020</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100110" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</description>
      <reference source="CVE">CVE-2004-0174</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100111" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</description>
      <reference source="CVE">CVE-2003-0993</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100112" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</description>
      <reference source="CVE">CVE-2004-0492</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100113" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>XDM</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Added CVE #">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.</description>
      <reference source="CVE">CVE-2004-1347</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-30006" comment="Solaris 8 (SPARC) meets Sun Alert ID 101549 criteria." negate="false"/>
          <criterion test_ref="cmp-30007" comment="Solaris 8 (x86) meets Sun Alert ID 101549 criteria." negate="false"/>
          <criterion test_ref="cmp-30008" comment="Solaris 9 (SPARC) meets Sun Alert ID 101549 criteria." negate="false"/>
          <criterion test_ref="cmp-30009" comment="Solaris 9 (x86) meets Sun Alert ID 101549 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100114" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>libtiff</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.</description>
      <reference source="CVE">CVE-2004-0803</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100115" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>libtiff</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.</description>
      <reference source="CVE">CVE-2004-0804</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100116" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>libtiff</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.</description>
      <reference source="CVE">CVE-2004-0886</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100117" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>libtiff</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-1308</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <patch_test id="spt-10016" comment="Patch 119901-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">119901</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="sat-10002"/>
      <subtest negate="true" test_ref="spt-10016"/>
    </compound_test>
    <patch_test id="spt-10015" comment="Patch 119900-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">119900</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <uname_test id="uut-10001" comment="Solaris 10 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">SunOS</os_name>
        <os_release operator="equals">5.10</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest test_ref="sat-10002"/>
      <subtest negate="true" test_ref="spt-10015"/>
    </compound_test>
    <patch_test id="spt-10014" comment="Patch 114220-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114220</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30011" comment="Solaris 9 (x86) supporting CDE criteria for Sun Alert ID 101677." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="sat-47"/>
      <subtest negate="true" test_ref="spt-10014"/>
    </compound_test>
    <compound_test id="cmp-30013" comment="Solaris 9 (x86) supporting criteria for Sun Alert ID 101677." operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-30011"/>
      <subtest test_ref="sat-10002"/>
      <subtest test_ref="sat-10003"/>
    </compound_test>
    <compound_test id="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="cmp-30013"/>
    </compound_test>
    <package_test id="sat-10003" comment="Pkg SUNWTiffx is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWTiffx</pkginst>
      </object>
    </package_test>
    <package_test id="sat-10002" comment="Pkg SUNWTiff is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWTiff</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-10013" comment="Patch 114219-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114219</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30010" comment="Solaris 9 (SPARC) supporting CDE criteria for Sun Alert ID 101677." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="sat-47"/>
      <subtest negate="true" test_ref="spt-10013"/>
    </compound_test>
    <compound_test id="cmp-30012" comment="Solaris 9 (SPARC) supporting criteria for Sun Alert ID 101677." operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-30010"/>
      <subtest test_ref="sat-10002"/>
      <subtest test_ref="sat-10003"/>
    </compound_test>
    <compound_test id="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest test_ref="cmp-30012"/>
    </compound_test>
    <patch_test id="spt-10012" comment="Patch 109932-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109932</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10012"/>
    </compound_test>
    <patch_test id="spt-10011" comment="Patch 109931-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109931</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10011"/>
    </compound_test>
    <patch_test id="spt-10010" comment="Patch 118954-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118954</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-5"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10010"/>
    </compound_test>
    <patch_test id="spt-10009" comment="Patch 118953-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118953</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-5"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10009"/>
    </compound_test>
    <patch_test id="spt-10008" comment="Patch 112786-27 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112786</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">27</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30009" comment="Solaris 9 (x86) meets Sun Alert ID 101549 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10008"/>
    </compound_test>
    <patch_test id="spt-10007" comment="Patch 112785-38 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112785</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">38</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30008" comment="Solaris 9 (SPARC) meets Sun Alert ID 101549 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10007"/>
    </compound_test>
    <patch_test id="spt-10006" comment="Patch 111845-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111845</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30007" comment="Solaris 8 (x86) meets Sun Alert ID 101549 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10006"/>
    </compound_test>
    <patch_test id="spt-10005" comment="Patch 111844-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111844</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30006" comment="Solaris 8 (SPARC) meets Sun Alert ID 101549 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10005"/>
    </compound_test>
    <patch_test id="spt-10004" comment="Patch 114145-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114145</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10004"/>
    </compound_test>
    <patch_test id="spt-10002" comment="Patch 113146-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113146</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10002"/>
    </compound_test>
    <patch_test id="spt-10003" comment="Patch 116974-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116974</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <uname_test id="uut-10002" comment="ix86 architecture" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <processor_type operator="pattern match">^i.*86</processor_type>
      </data>
    </uname_test>
    <compound_test id="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10003"/>
    </compound_test>
    <patch_test id="spt-10001" comment="Patch 116973-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116973</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <uname_test id="uut-10003" comment="sparc architecture" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <processor_type operator="pattern match">[Ss][Pp][Aa][Rr][Cc]</processor_type>
      </data>
    </uname_test>
    <compound_test id="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10001"/>
    </compound_test>
    <patch_test id="spt-258" comment="Patch 116308-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116308</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-257" comment="Patch 108949-08 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108949</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <patch_test id="spt-256" comment="Patch 107178-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107178</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <package_test id="sat-33" comment="Separable help for CDE (SUNWdthep) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWdthep</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-82" comment="CDE Application Runtime or CDE Separable Help (any SUNWdtbas/SUNWdtbax/SUNWdthep) installed " operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-32"/>
      <subtest negate="false" test_ref="sat-33"/>
    </compound_test>
    <textfilecontent_test id="tft-1" comment="/etc/nsswitch.conf configured to use LDAP with RBAC" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/nsswitch.conf</component>
        </path>
        <line operator="pattern match">^[^#].*_attr.*ldap</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-75" comment="Patch 112960-17 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112960</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">17</version>
      </data>
    </patch_test>
    <patch_test id="spt-74" comment="Patch 108993-38 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108993</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">38</version>
      </data>
    </patch_test>
    <patch_test id="spt-29" comment="Patch 112233-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">11233</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-28" comment="Patch 113319-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113319</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-64" comment="Patches 113319-01 and 112233-02 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-28"/>
      <subtest negate="false" test_ref="spt-29"/>
    </compound_test>
    <patch_test id="spt-27" comment="Patch 108451-06 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108451</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <compound_test id="cmp-63" comment="Patches 106942-22 and 108451-06 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-211"/>
      <subtest negate="false" test_ref="spt-27"/>
    </compound_test>
    <process_test id="uct-12" comment="Kerberos Key Distribution Center (krb5kdc) running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">.*krb5kdc.*</command>
      </object>
    </process_test>
    <patch_test id="spt-94" comment="Patch 112233-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112233</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-93" comment="Patch 108528-19 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108528</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">19</version>
      </data>
    </patch_test>
    <patch_test id="spt-92" comment="Patch 106541-25 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">25</version>
      </data>
    </patch_test>
    <patch_test id="spt-52" comment="Patch 116462-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116462</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-51" comment="Patch 110060-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110060</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-50" comment="Patch 110057-07 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110057</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-49" comment="Patch 112536-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112536</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <compound_test id="cmp-73" comment="Patches 112536-04 and 110057-07 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-49"/>
      <subtest negate="false" test_ref="spt-50"/>
    </compound_test>
    <patch_test id="spt-112" comment="Patch 107115-12 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107115</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">12</version>
      </data>
    </patch_test>
    <patch_test id="spt-108" comment="Patch 107893-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107893</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <textfilecontent_test id="tft-4" comment="/etc/nsswitch.conf configured to resolve hosts through DNS" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/nsswitch.conf</component>
        </path>
        <line operator="pattern match">^[^#]*hosts:.*dns</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-32" comment="Patch 112970-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112970</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-31" comment="Patch 109326-09 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109326</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-30" comment="Patch 106938-06 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106938</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <patch_test id="spt-45" comment="Patch 113329-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113329</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-44" comment="Patch 109320-07 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109320</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-43" comment="Patch 107115-13 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107115</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">13</version>
      </data>
    </patch_test>
    <package_test id="sat-25" comment="Solaris Print - LP Server - Usr (SUNWpsu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpsu</pkginst>
      </object>
    </package_test>
    <package_test id="sat-24" comment="Solaris Print - LP Server - Root (SUNWpsr) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpsr</pkginst>
      </object>
    </package_test>
    <package_test id="sat-23" comment="Solaris Print - Client - Usr (SUNWpcu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpcu</pkginst>
      </object>
    </package_test>
    <package_test id="sat-22" comment="Solaris Print - Client - Root (SUNWpcr) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpcr</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-71" comment="Solaris Printing Services installed (any SUNWpcr/SUNWpcu/SUNWpsr/SUNWpsu)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-22"/>
      <subtest negate="false" test_ref="sat-23"/>
      <subtest negate="false" test_ref="sat-24"/>
      <subtest negate="false" test_ref="sat-25"/>
    </compound_test>
    <patch_test id="spt-39" comment="Patch 109324-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109324</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-37" comment="Patch 110898-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110898</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-41" comment="Patch 110943-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110943</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-70" comment="Patches 110943-01, 110898-02, and 109324-03 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-41"/>
      <subtest negate="false" test_ref="spt-37"/>
      <subtest negate="false" test_ref="spt-39"/>
    </compound_test>
    <patch_test id="spt-40" comment="Patch 108416-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108416</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-38" comment="Patch 108162-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108162</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-36" comment="Patch 108574-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108574</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-69" comment="Patches 108574-03, 108162-04, and 108416-02 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-36"/>
      <subtest negate="false" test_ref="spt-38"/>
      <subtest negate="false" test_ref="spt-40"/>
    </compound_test>
    <package_test id="sat-9" comment="CDE Desktop Applications (SUNWdtdst) installed                                                                                               " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWdtdst</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-265" comment="Patch 112810-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112810</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <patch_test id="spt-264" comment="Patch 109613-07 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109613</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <file_test id="uft-31" comment="File /etc/named.conf exists " check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <oval:notes>
        <oval:note>The presence of /etc/named.conf indicates that system system is probably configured as a DNS server</oval:note>
      </oval:notes>
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/named.conf</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-66" comment="Patch 109326-16 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109326</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">16</version>
      </data>
    </patch_test>
    <process_test id="uct-18" comment="xntpd running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="equals">/usr/lib/inet/xntpd</command>
      </object>
    </process_test>
    <patch_test id="spt-62" comment="Patch 109667-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109667</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-61" comment="Patch 109409-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109409</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <package_test id="sat-35" comment="NTP daemon - Usr (SUNWntpu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWntpu</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-263" comment="Patch 113146-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113146</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-114" comment="Patch 112233-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112233</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-113" comment="Patch 108528-18 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108528</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">18</version>
      </data>
    </patch_test>
    <patch_test id="spt-239" comment="Patch 110615-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110615</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <patch_test id="spt-238" comment="Patch 107684-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <unknown_test id="ukn-36" comment="Sendmail has recipient or final rulesets" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>egrep "^[Srecipient=2|S2]|^[^#]*\$>2|^[^#]*\$>recipient|^[^#]*\$>4|^[^#]*\$>final" /etc/mail/sendmail.cf True if any lines returned</oval:note>
      </oval:notes>
    </unknown_test>
    <patch_test id="spt-12" comment="Patch 112963-09 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112963</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-11" comment="Patch 109147-07 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109147</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-10" comment="Patch 106950-14 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106950</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">14</version>
      </data>
    </patch_test>
    <compound_test id="cmp-54" comment="Solaris 9 OR Patch 106950-14+ OR Patch 109147-07+ installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-10"/>
      <subtest negate="false" test_ref="spt-11"/>
      <subtest negate="false" test_ref="uut-6"/>
    </compound_test>
    <textfilecontent_test id="tft-3" comment="/etc/system has BSM enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/system</component>
        </path>
        <line operator="pattern match">^[^\*]*set.*c2audit.*</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-85" comment="Patch 114332-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114332</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-84" comment="Patch 114332-08 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114332</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">08</version>
      </data>
    </patch_test>
    <textfilecontent_test id="tft-2" comment="/etc/ssh/sshd_config has 0.0.0.0 as ListenAddress" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/ssh/sshd_config</component>
        </path>
        <line operator="pattern match">^[^#]*ListenAddress.*0\.0\.0\.0</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-83" comment="Patch 113273-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113273</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <package_test id="sat-41" comment="Secure Shell Server - Usr (SUNWsshdu) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsshdu</pkginst>
      </object>
    </package_test>
    <textfilecontent_test id="tft-9" comment="/etc/vfstab is configured with SVM devices" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/vfstab</component>
        </path>
        <line operator="equals">^/dev/md/</line>
      </object>
    </textfilecontent_test>
    <file_test id="uft-24" comment="svm.init init script exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="pattern match">
          <component type="literal">/etc/rc[2-4].d/S[0-9][0-9]svm.init</component>
        </path>
      </object>
    </file_test>
    <package_test id="sat-4" comment="Solaris Volume Manager package installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst>SUNWlvmr</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-241" comment="Patch 113073-13 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113073</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">13</version>
      </data>
    </patch_test>
    <patch_test id="spt-73" comment="Patch 116774-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116774</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-72" comment="Patch 116986-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116986</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-71" comment="Patch 118313-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118313</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-39" comment="Solaris Basic IP Commands (SUNWbip) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWbip</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-88" comment="Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-6"/>
      <subtest negate="false" test_ref="sat-39"/>
    </compound_test>
    <compound_test id="cmp-96" comment="Solaris 7 or 8 OR Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-43"/>
      <subtest negate="false" test_ref="cmp-88"/>
    </compound_test>
    <patch_test id="spt-106" comment="Patch 108219-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108219</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-32" comment="CDE application basic runtime environment (SUNWdtbas/SUNWdtbax) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="pattern match">SUNWdtba[sx]</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-240" comment="Patch 113575-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113575</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-14" comment="Patch 110615-10 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110615</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-13" comment="Patch 107684-10 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-79" comment="Patch 117000-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117000</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-78" comment="Patch 116895-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116895</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-42" comment="Patch 113923-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113923</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-21" comment="X Window System Font Server (SUNWxwfs) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWxwfs</pkginst>
      </object>
    </package_test>
    <process_test id="uct-16" comment="sshd running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*sshd.*</command>
      </object>
    </process_test>
    <patch_test id="spt-19" comment="Patch 113273-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113273</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <unknown_test id="ukn-2" comment="Lance Ethernet interface in use" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note/>
      </oval:notes>
    </unknown_test>
    <file_test id="uft-30" comment="Lance Ethernet (le) interface configured to start" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="pattern match">
          <component type="literal">hostname6?\.le.*</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-18" comment="Patch 115172-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115172</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-17" comment="Patch 112609-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112609</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-16" comment="Patch 112604-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112604</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-2" comment="Sun Crypto Accelerator 4000 software installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWkcl2r</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-243" comment="Patch 114796-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114796</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-22" comment="Patch 111400-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111400</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-21" comment="Patch 107337-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107337</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-20" comment="Patch 114636-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114636</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-18" comment="Kodak Color Managment Server (KCMS) Runtime Environment (SUNWkcsrt/SUNWkcsrx) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="pattern match">SUNWkcsr[tx]</pkginst>
      </object>
    </package_test>
    <process_test id="uct-13" comment="Apache running with SunPlex Manager config" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^/usr/apache/bin/httpd.*SUNWscvw/conf/httpd.conf.*</command>
      </object>
    </process_test>
    <package_test id="sat-8" comment="SunCluster Component SUNWscvw installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWscvw</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-269" comment="Patch 115055-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115055</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-268" comment="Patch 115054-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115054</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-267" comment="Patch 113508-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113508</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-266" comment="Patch 113505-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113505</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-59" comment="Patch 112908-10 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-58" comment="Patch 112921-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112921</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-57" comment="Patch 112923-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112923</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-56" comment="Patch 112925-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112925</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-81" comment="Patches 112925-03,112923-03,112921-02, and 112908-10 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-56"/>
      <subtest negate="false" test_ref="spt-57"/>
      <subtest negate="false" test_ref="spt-58"/>
      <subtest negate="false" test_ref="spt-59"/>
    </compound_test>
    <patch_test id="spt-55" comment="Patch 112390-08 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112390</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <patch_test id="spt-54" comment="Patch 112237-09 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112237</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <compound_test id="cmp-79" comment="Patches 112237-09 and 112390-08 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-54"/>
      <subtest negate="false" test_ref="spt-55"/>
    </compound_test>
    <package_test id="sat-31" comment="Kerberos v5 - Usr (SUNWkrbu/SUNWkrbux) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>SUNWkrbu - 32bit, SUNWkrbux - 64bit</oval:note>
      </oval:notes>
      <object>
        <pkginst operator="pattern match">SUNWkrbux?</pkginst>
      </object>
    </package_test>
    <package_test id="sat-30" comment="Kerberos v5 - Root (SUNWkrbr) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkrbr</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-74" comment="Kerberos v5 (any SUNWkrbr/SUNWkrbu/SUNWkrbux) installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-30"/>
      <subtest negate="false" test_ref="sat-31"/>
    </compound_test>
    <unknown_test id="ukn-27" comment="Auditing Administrative or System-Wide Administrative audit classes" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>egrep ^flags:.*a[sd] /etc/security/audit_control True if any lines returned</oval:note>
      </oval:notes>
    </unknown_test>
    <unknown_test id="ukn-26" comment="Basic Security Module enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>grep c2audit /etc/system True if "set c2audit:audit_load = 1" or similiar</oval:note>
      </oval:notes>
    </unknown_test>
    <patch_test id="spt-235" comment="Patch 114332-12 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114332</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">12</version>
      </data>
    </patch_test>
    <patch_test id="spt-234" comment="Patch 109007-18 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="not equal">109007</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">18</version>
      </data>
    </patch_test>
    <patch_test id="spt-233" comment="Patch 106541-33 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">33</version>
      </data>
    </patch_test>
    <process_test id="uct-17" comment="ypxfrd running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*ypxfrd.*</command>
      </object>
    </process_test>
    <patch_test id="spt-35" comment="Patch 113579-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113579</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-34" comment="Patch 109328-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109328</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-33" comment="Patch 106541-24 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">24</version>
      </data>
    </patch_test>
    <package_test id="sat-20" comment="NIS Server - User (SUNWypu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>Package which contains /usr/lib/netsvc/yp/ypxfrd</oval:note>
      </oval:notes>
      <object>
        <pkginst operator="equals">SUNWypu</pkginst>
      </object>
    </package_test>
    <process_test id="uct-21" comment="rpcbind running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">.*rpcbind.*</command>
      </object>
    </process_test>
    <patch_test id="spt-142" comment="Patch 108764-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108764</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-141" comment="Patch 108762-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108762</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-140" comment="Patch 108760-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108760</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-139" comment="Patch 108758-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108758</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-138" comment="Patch 108756-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108756</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-137" comment="Patch 108754-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108754</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-136" comment="Patch 108551-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108551</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-135" comment="Patch 107477-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">107477</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-134" comment="Patch 106942-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">106942</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-133" comment="Patch 106541-14 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">106541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">14</version>
      </data>
    </patch_test>
    <patch_test id="spt-132" comment="Patch 108752-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108752</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-285" comment="Patches 108752-01 or 106541-14 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-132"/>
      <subtest negate="false" test_ref="spt-133"/>
    </compound_test>
    <patch_test id="spt-131" comment="Patch 108750-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108750</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-130" comment="Patch 108748-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108748</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-287" comment="All RPC w/TCP patches installed - CVE-2002-1265" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-130"/>
      <subtest negate="false" test_ref="spt-131"/>
      <subtest negate="false" test_ref="cmp-285"/>
      <subtest negate="false" test_ref="spt-134"/>
      <subtest negate="false" test_ref="spt-135"/>
      <subtest negate="false" test_ref="spt-136"/>
      <subtest negate="false" test_ref="spt-137"/>
      <subtest negate="false" test_ref="spt-138"/>
      <subtest negate="false" test_ref="spt-139"/>
      <subtest negate="false" test_ref="spt-140"/>
      <subtest negate="false" test_ref="spt-141"/>
      <subtest negate="false" test_ref="spt-142"/>
    </compound_test>
    <process_test id="uct-11" comment="Sendmail running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">.*sendmail .*</command>
      </object>
    </process_test>
    <patch_test id="spt-65" comment="Patch 113575-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113575</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-64" comment="Patch 110615-08 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110615</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <patch_test id="spt-63" comment="Patch 107684-08 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <package_test id="sat-14" comment="Sendmail - user (SUNWsndmu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsndmu</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-2" comment="Patch 113575-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113575</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-3" comment="Sendmail - root (SUNWsndmr) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsndmr</pkginst>
      </object>
    </package_test>
    <inetd_test id="sit-2" comment="inetd.conf contains smbd" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="pattern match">^.*smbd.*</server_program>
      </object>
    </inetd_test>
    <compound_test id="cmp-56" comment="Inetd running and inetd.conf contains smbd" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uct-4"/>
      <subtest negate="false" test_ref="sit-2"/>
    </compound_test>
    <patch_test id="spt-15" comment="Patch 114684-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-15" comment="Samba (SUNWsmbar) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUWNsmbar</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-250" comment="Patch 112908-15 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">15</version>
      </data>
    </patch_test>
    <patch_test id="spt-25" comment="Patch 109326-10 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109326</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-24" comment="Patch 106938-07 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106938</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <textfilecontent_test id="tft-8" comment="/etc/syslog.conf is configured to log &quot;debug&quot; level messages for at least daemon" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/syslog.conf</component>
        </path>
        <line operator="pattern match">^[^#]*(\*|daemon)\.debug</line>
      </object>
    </textfilecontent_test>
    <textfilecontent_test id="tft-7" comment="/etc/pam.conf is configured to use pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/pam.conf</component>
        </path>
        <line operator="pattern match">[^#]*pam_krb5.*debug</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-236" comment="Patch 112908-12 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">12</version>
      </data>
    </patch_test>
    <patch_test id="spt-248" comment="Patch 112908-13 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">13</version>
      </data>
    </patch_test>
    <patch_test id="spt-7" comment="Patch 111085-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112085</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-6" comment="Patch 112300-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112300</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-10" comment="Core Solaris (SUNWcsu/SUNWcsxu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>SUNWcsu = 32bit, SUNWcsxu = 64bit</oval:note>
      </oval:notes>
      <object>
        <pkginst operator="pattern match">SUNWcsx?u</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-272" comment="Patch 112970-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112970</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <patch_test id="spt-271" comment="Patch 109326-13 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109326</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">13</version>
      </data>
    </patch_test>
    <patch_test id="spt-270" comment="Patch 106938-08 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106938</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <textfilecontent_test id="tft-6" comment="/etc/krb5/krb5.conf is configured with explicit or rules-based mapping" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/krb5/krb5.conf</component>
        </path>
        <line operator="pattern match">^[^#]auth_to_local.*</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-245" comment="Patch 112390-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112390</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-244" comment="Patch 112237-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112237</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <compound_test id="cmp-1104" comment="Patches 112237-11 and 112390-09 or greater installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-244"/>
      <subtest negate="false" test_ref="spt-245"/>
    </compound_test>
    <patch_test id="spt-247" comment="Patch 112536-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112536</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-246" comment="Patch 112908-16 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">16</version>
      </data>
    </patch_test>
    <file_test id="uft-25" comment="Kerberos 5 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/etc/krb5/krb5.conf</component>
        </path>
      </object>
    </file_test>
    <package_test id="sat-5" comment="Apache (SUNWapchu) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWapchu</pkginst>
      </object>
    </package_test>
    <process_test id="uct-10" comment="Apache running (httpd)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">.*httpd</command>
      </object>
    </process_test>
    <patch_test id="spt-254" comment="Patch 113146-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113146</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-253" comment="Patch 116973-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116973</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <inetd_test id="sit-3" comment="inetd.conf contains in.ftpd" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/sbin/in.ftpd</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-60" comment="Patch 114564-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114564</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-34" comment="FTP Server - Usr (SUNWftpu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWftpu</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-102" comment="Patch 114497-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114497</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-101" comment="Patch 109354-19 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109354</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">19</version>
      </data>
    </patch_test>
    <patch_test id="spt-100" comment="Patch 107702-12 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107702</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">12</version>
      </data>
    </patch_test>
    <package_test id="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWdtwm</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-107" comment="Patch 108221-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108221</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-49" comment="CDE Daemons (SUNWdtdmn) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWdtdmn</pkginst>
      </object>
    </package_test>
    <process_test id="uct-3" comment="ypbind running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*ypbind.*</command>
      </object>
    </process_test>
    <patch_test id="spt-9" comment="Patch 110322-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110322</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-8" comment="Patch 108750-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108750</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-13" comment="NIS/NIS+ Utilities installed (SUNWnisu)" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWnisu</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-91" comment="Patch 113329-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113329</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-90" comment="Patch 109320-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109320</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-89" comment="Patch 107115-14 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107115</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">14</version>
      </data>
    </patch_test>
    <package_test id="sat-43" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpcu</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-242" comment="Patch 117367-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117367</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-1" comment="Sun Enterprise Storage Manager installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst>SUNWstm</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-80" comment="Patch 112233-12 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112233</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">12</version>
      </data>
    </patch_test>
    <patch_test id="spt-81" comment="Patch 108528-27 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108528</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">27</version>
      </data>
    </patch_test>
    <patch_test id="spt-67" comment="Patch 112668-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112668</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-36" comment="GNU Zip (gzip, SUNWgzip) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWgzip</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-95" comment="Patch 110943-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110943</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <process_test id="uct-20" comment="smcboot running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <oval:notes>
        <oval:note>Solaris Management Console web interface</oval:note>
      </oval:notes>
      <object>
        <command operator="pattern match">.*smcboot</command>
      </object>
    </process_test>
    <patch_test id="spt-77" comment="Patch 116807-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116807</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-76" comment="Patch 111313-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111313</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-40" comment="Solaris Management Console Web Components (SUNWwbmc) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWwbmc</pkginst>
      </object>
    </package_test>
    <package_test id="sat-11" comment="Netscape installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWnsb</pkginst>
      </object>
    </package_test>
    <process_test id="uct-15" comment="smbd running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*smbd.*</command>
      </object>
    </process_test>
    <patch_test id="spt-48" comment="Patch 114684-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-28" comment="Samba - Usr (SUNWsmbau) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsmbau</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-249" comment="Patch 107180-31 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107180</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">31</version>
      </data>
    </patch_test>
    <patch_test id="spt-232" comment="Patch 112807-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112807</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-231" comment="Patch 108919-21 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="binary" operator="equals">108919</base>
      </object>
      <data operation="AND">
        <version datatype="binary" operator="greater than or equal">21</version>
      </data>
    </patch_test>
    <process_test id="uct-9" comment="dtlogin running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^.*dtlogin.*</command>
      </object>
    </process_test>
    <file_test id="uft-23" comment="File /usr/dt/bin/dtlogin exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtlogin</component>
        </path>
      </object>
    </file_test>
    <inetd_test id="sit-210" comment="Sadmin called using strong authentication" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/sbin/sadmind</server_program>
      </object>
      <data operation="AND">
        <server_arguments datatype="string" operator="equals">-S 2</server_arguments>
      </data>
    </inetd_test>
    <patch_test id="spt-261" comment="Patch 116454-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116454</base>
      </object>
      <data operation="AND">
        <version datatype="string" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-260" comment="Patch 116442-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116442</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-259" comment="Patch 116457-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116457</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <inetd_test id="sit-209" comment="inetd.conf contains sadmind" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/sbin/sadmind</server_program>
      </object>
    </inetd_test>
    <package_test id="sat-7" comment="System and Network Administration Framework Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWadmfw</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-47" comment="Patch 117767-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117767</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-46" comment="Patch 117765-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117765</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-27" comment="Mozilla Mail (SUNWmozmail) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWmozmail</pkginst>
      </object>
    </package_test>
    <package_test id="sat-26" comment="Mozilla (SUNWmoznav) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWmoznav</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-26"/>
      <subtest negate="false" test_ref="sat-27"/>
    </compound_test>
    <patch_test id="spt-88" comment="Patch 113322-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113322</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-87" comment="Patch 111570-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111570</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-86" comment="Patch 106952-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106952</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <package_test id="sat-42" comment="Networking UUCP Utilities - Usr (SUNWbnuu) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWbnuu</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-1080" comment="Solaris 7,8,or 9 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-4"/>
      <subtest negate="false" test_ref="uut-5"/>
      <subtest negate="false" test_ref="uut-6"/>
    </compound_test>
    <textfilecontent_test id="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>Rough translation of the Sun recommended test of: % grep default_realm /etc/krb5/krb5.conf | grep -v ___default_realm___  default_realm = EXAMPLE.COM</oval:note>
      </oval:notes>
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/krb5/krb5.conf</component>
        </path>
        <line operator="pattern match">^[^#_]*default_realm[^=]*=[^_]*$</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-98" comment="Patch 112390-07 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112390</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-97" comment="Patch 112237-07 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112237</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-99" comment="Patch 112908-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-96" comment="Patch 112536-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112536</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-46" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkrggl</pkginst>
      </object>
    </package_test>
    <package_test id="sat-45" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkrgdo</pkginst>
      </object>
    </package_test>
    <package_test id="sat-44" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkr5sl</pkginst>
      </object>
    </package_test>
    <package_test id="sat-29" comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkr5sv</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-118" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-29"/>
      <subtest negate="false" test_ref="sat-44"/>
      <subtest negate="false" test_ref="sat-45"/>
      <subtest negate="false" test_ref="sat-46"/>
    </compound_test>
    <compound_test id="cmp-156" comment="Solaris 7 AND Solaris Enterprise Authentication Mechanism installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-5"/>
      <subtest negate="false" test_ref="cmp-118"/>
    </compound_test>
    <compound_test id="cmp-157" comment="Solaris 7 and Solaris Enterprise Authentication Mechanism OR Solaris 8 or 9 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-156"/>
      <subtest negate="false" test_ref="cmp-1081"/>
    </compound_test>
    <patch_test id="spt-255" comment="Patch 112808-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112808</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="pattern match">SUNWtltkx?</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-105" comment="Patch 108869-15 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108869</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">15</version>
      </data>
    </patch_test>
    <patch_test id="spt-104" comment="Patch 107709-18 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107709</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">18</version>
      </data>
    </patch_test>
    <package_test id="sat-48" comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsasnm</pkginst>
      </object>
    </package_test>
    <process_test id="uct-19" comment="in.rwhod is running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="equals">/usr/sbin/in.rwhod</command>
      </object>
    </process_test>
    <patch_test id="spt-70" comment="Patch 117455-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117455</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-69" comment="Patch 116984-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116984</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-68" comment="Patch 118239-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118239</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-38" comment="Remote Network Server Commands - Usr (SUNWrcmds) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWrcmds</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-85" comment="Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-6"/>
      <subtest negate="false" test_ref="sat-38"/>
    </compound_test>
    <compound_test id="cmp-87" comment="Solaris 7 or 8 OR Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-43"/>
      <subtest negate="false" test_ref="cmp-85"/>
    </compound_test>
    <package_test id="sat-12" comment="X Window System platform software (SUNWxwplt) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWxwplt</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-5" comment="Patch 108652-30 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108652</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">30</version>
      </data>
    </patch_test>
    <patch_test id="spt-4" comment="Patch 108376-25 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108376</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">25</version>
      </data>
    </patch_test>
    <compound_test id="cmp-43" comment="Solaris 7 or 8 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-5"/>
      <subtest negate="false" test_ref="uut-4"/>
    </compound_test>
    <process_test id="uct-14" comment="in.named running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="equals">/usr/sbin/in.named</command>
      </object>
    </process_test>
    <patch_test id="spt-26" comment="Patch 112970-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112970</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <package_test id="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWinamd</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-230" comment="Patch 110286-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110286</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-229" comment="Patch 107654-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107654</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-228" comment="Patch 107893-20 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107893</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">20</version>
      </data>
    </patch_test>
    <patch_test id="spt-227" comment="Patch 108117-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108117</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">6</version>
      </data>
    </patch_test>
    <permission_test id="upt-857" comment="File xfs executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xfs</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-856" comment="File xfs executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xfs</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-855" comment="File xfs executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xfs</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-267" comment="File xfs executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-855"/>
      <subtest negate="false" test_ref="upt-856"/>
      <subtest negate="false" test_ref="upt-857"/>
    </compound_test>
    <inetd_test id="sit-207" comment="inetd.conf contains fs.auto" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/openwin/lib/fs.auto</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-226" comment="Patch 109862-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109862</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">3</version>
      </data>
    </patch_test>
    <file_test id="uft-22" comment="File xfs exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xfs</component>
        </path>
      </object>
    </file_test>
    <file_test id="uft-21" comment="File fs.auto exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/lib/fs.auto</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-225" comment="Patch 108376-30 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108376</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">30</version>
      </data>
    </patch_test>
    <permission_test id="upt-854" comment="File kcms_server executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_server</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-853" comment="File kcms_server executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_server</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-852" comment="File kcms_server executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_server</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-255" comment="File kcms_server executable and SUID or SGID" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-852"/>
      <subtest negate="false" test_ref="upt-853"/>
      <subtest negate="false" test_ref="upt-854"/>
    </compound_test>
    <inetd_test id="sit-206" comment="inetd.conf contains kcms_server" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/openwin/bin/kcms_server</server_program>
      </object>
    </inetd_test>
    <file_test id="uft-20" comment="File kcms_server exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_server</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-224" comment="Patch 111590-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111590</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <patch_test id="spt-110" comment="Patch 110896-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110896</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <permission_test id="upt-851" comment="File lbxproxy SGID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/lbxproxy</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-850" comment="File lbxproxy SGID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/lbxproxy</component>
        </path>
      </object>
      <data operation="AND">
        <sgid datatype="int" operator="equals">1</sgid>
      </data>
    </permission_test>
    <compound_test id="cmp-247" comment="File lbxproxy SGID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-850"/>
      <subtest negate="false" test_ref="upt-851"/>
    </compound_test>
    <patch_test id="spt-223" comment="Patch 108652-51 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108652</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">51</version>
      </data>
    </patch_test>
    <file_test id="uft-19" comment="File lbxproxy exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/lbxproxy</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-222" comment="Patch 107893-19 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107893</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">19</version>
      </data>
    </patch_test>
    <patch_test id="spt-221" comment="Patch 112846-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112846</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <patch_test id="spt-220" comment="Patch 106934-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106934</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">4</version>
      </data>
    </patch_test>
    <permission_test id="upt-849" comment="File dtspcd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtspcd</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-848" comment="File dtspcd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtspcd</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-847" comment="File dtspcd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtspcd</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-239" comment="File dtspcd executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-847"/>
      <subtest negate="false" test_ref="upt-848"/>
      <subtest negate="false" test_ref="upt-849"/>
    </compound_test>
    <inetd_test id="sit-205" comment="inetd.conf contains dtspcd" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/dt/bin/dtspcd</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-219" comment="Patch 108949-07 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108949</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">7</version>
      </data>
    </patch_test>
    <file_test id="uft-18" comment="File dtspcd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtspcd</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-218" comment="Patch 108721-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108721</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <patch_test id="spt-217" comment="Patch 110453-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110453</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <patch_test id="spt-216" comment="Patch 107337-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107337</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <process_test id="uct-8" comment="mibiisa running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^.*mibiisa.*</command>
      </object>
    </process_test>
    <patch_test id="spt-215" comment="Patch 107709-19 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107709</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">19</version>
      </data>
    </patch_test>
    <file_test id="uft-17" comment="File mibiisa exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/snmp/mibiisa</component>
        </path>
      </object>
    </file_test>
    <process_test id="uct-7" comment="rpc.yppasswdd running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^.*rpc\.yppasswdd.*</command>
      </object>
    </process_test>
    <patch_test id="spt-214" comment="Patch 111596-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111596</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <file_test id="uft-16" comment="File rpc.yppasswdd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rpc.yppasswdd</component>
        </path>
      </object>
    </file_test>
    <permission_test id="upt-846" comment="File admintool SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">^.*/bin/admintool</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-845" comment="File admintool SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">^.*/bin/admintool</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-229" comment="File admintool SUID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-845"/>
      <subtest negate="false" test_ref="upt-846"/>
    </compound_test>
    <file_test id="uft-15" comment="File admintool exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="pattern match">
          <component type="literal">^.*/bin/admintool$</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-213" comment="Patch 111826-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111826</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <patch_test id="spt-109" comment="Patch 108800-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108800</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-212" comment="Patch 108541-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">6</version>
      </data>
    </patch_test>
    <patch_test id="spt-211" comment="Patch 106942-22 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106942</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">22</version>
      </data>
    </patch_test>
    <compound_test id="cmp-223" comment="Patches 106942-22 and 108451-06" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-211"/>
      <subtest negate="false" test_ref="spt-212"/>
    </compound_test>
    <permission_test id="upt-844" comment="File rpc.rwalld executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rwall/rpc.rwalld</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-843" comment="File rpc.rwalld executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rwall/rpc.rwalld</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-842" comment="File rpc.rwalld executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rwall/rpc.rwalld</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-221" comment="File rpc.rwalld executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-842"/>
      <subtest negate="false" test_ref="upt-843"/>
      <subtest negate="false" test_ref="upt-844"/>
    </compound_test>
    <inetd_test id="sit-204" comment="inetd.conf contains rpc.rwalld" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/lib/netsvc/rwall/rpc.rwalld</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-210" comment="Patch 112899-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112899</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <file_test id="uft-14" comment="File rpc.rwalld exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rwall/rpc.rwalld</component>
        </path>
      </object>
    </file_test>
    <permission_test id="upt-841" comment="File whodo SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">^/usr/sbin/sparcv./whodo</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-840" comment="File whodo SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">^/usr/sbin/sparcv./whodo</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-219" comment="File whodo SUID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-840"/>
      <subtest negate="false" test_ref="upt-841"/>
    </compound_test>
    <patch_test id="spt-209" comment="Patch 111600-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111600</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <file_test id="uft-13" comment="File whodo exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="pattern match">
          <component type="literal">^/usr/sbin/sparcv./whodo$</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-208" comment="Patch 108376-38 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108376</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">38</version>
      </data>
    </patch_test>
    <uname_test id="uut-5" comment="Solaris 7 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">SunOS</os_name>
        <os_release operator="equals">5.7</os_release>
      </data>
    </uname_test>
    <permission_test id="upt-839" comment="File cachefsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/usr/lib/fs/cachefs/cachefsd</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-838" comment="File cachefsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/usr/lib/fs/cachefs/cachefsd</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-837" comment="File cachefsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/usr/lib/fs/cachefs/cachefsd</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-217" comment="File cachefsd executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-837"/>
      <subtest negate="false" test_ref="upt-838"/>
      <subtest negate="false" test_ref="upt-839"/>
    </compound_test>
    <inetd_test id="sit-203" comment="inetd.conf contains cachefsd" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/lib/fs/cachefs/cachefsd</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-111" comment="Patch 114008-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114008</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <uname_test id="uut-6" comment="Solaris 9 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">SunOS</os_name>
        <os_release operator="equals">5.9</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-1081" comment="Solaris 8 or 9 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-4"/>
      <subtest negate="false" test_ref="uut-6"/>
    </compound_test>
    <patch_test id="spt-207" comment="Patch 110896-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110896</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <file_test id="uft-12" comment="File cachefsd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/usr/lib/fs/cachefs/cachefsd</component>
        </path>
      </object>
    </file_test>
    <permission_test id="upt-836" comment="File rpc.ttdbserverd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.ttdbserverd</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-835" comment="File rpc.ttdbserverd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.ttdbserverd</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-834" comment="File rpc.ttdbserverd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.ttdbserverd</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-211" comment="File rpc.ttdbserverd executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-834"/>
      <subtest negate="false" test_ref="upt-835"/>
      <subtest negate="false" test_ref="upt-836"/>
    </compound_test>
    <inetd_test id="sit-202" comment="inetd.conf contains rpc.ttdbserverd" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/dt/bin/rpc.ttdbserverd</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-206" comment="Patch 110286-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110286</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">9</version>
      </data>
    </patch_test>
    <file_test id="uft-11" comment="File rpc.ttdbserverd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.ttdbserverd</component>
        </path>
      </object>
    </file_test>
    <permission_test id="upt-833" comment="File Xsun SGID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/Xsun</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-832" comment="File Xsun SGID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/Xsun</component>
        </path>
      </object>
      <data operation="AND">
        <sgid datatype="int" operator="equals">1</sgid>
      </data>
    </permission_test>
    <compound_test id="cmp-210" comment="File Xsun SGID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-832"/>
      <subtest negate="false" test_ref="upt-833"/>
    </compound_test>
    <patch_test id="spt-205" comment="Patch 108652-52 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108652</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">52</version>
      </data>
    </patch_test>
    <file_test id="uft-10" comment="File Xsun exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/Xsun</component>
        </path>
      </object>
    </file_test>
    <process_test id="uct-6" comment="snmpdx running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*snmpdx.*</command>
      </object>
    </process_test>
    <patch_test id="spt-204" comment="Patch 108869-16 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108869</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">16</version>
      </data>
    </patch_test>
    <file_test id="uft-9" comment="File snmpdx exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/snmp/snmpdx</component>
        </path>
      </object>
    </file_test>
    <permission_test id="upt-831" comment="File xlock SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xlock</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-830" comment="File xlock SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xlock</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-209" comment="File xlock SUID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-830"/>
      <subtest negate="false" test_ref="upt-831"/>
    </compound_test>
    <patch_test id="spt-203" comment="Patch 108652-38 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108652</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">38</version>
      </data>
    </patch_test>
    <file_test id="uft-8" comment="File xlock exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xlock</component>
        </path>
      </object>
    </file_test>
    <process_test id="uct-5" comment="dmispd running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^.*dmispd.*</command>
      </object>
    </process_test>
    <permission_test id="upt-829" comment="File rpc.cmsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.cmsd</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-828" comment="File rpc.cmsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.cmsd</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-827" comment="File rpc.cmsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.cmsd</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-208" comment="File rpc.cmsd executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-827"/>
      <subtest negate="false" test_ref="upt-828"/>
      <subtest negate="false" test_ref="upt-829"/>
    </compound_test>
    <process_test id="uct-4" comment="inetd running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*inetd.*</command>
      </object>
      <data operation="AND">
        <user_id operator="equals">root</user_id>
      </data>
    </process_test>
    <inetd_test id="sit-201" comment="inetd.conf contains rpc.cmsd" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/dt/bin/rpc.cmsd</server_program>
      </object>
    </inetd_test>
    <compound_test id="cmp-207" comment="rpc.cmsd enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sit-201"/>
      <subtest negate="false" test_ref="uct-4"/>
      <subtest negate="false" test_ref="cmp-208"/>
    </compound_test>
    <compound_test id="cmp-206" comment="rpc.cmsd enabled OR dmispd running" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-207"/>
      <subtest negate="false" test_ref="uct-5"/>
    </compound_test>
    <patch_test id="spt-202" comment="Patch 108901-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108901</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">6</version>
      </data>
    </patch_test>
    <patch_test id="spt-201" comment="Patch 108827-30 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108827</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">30</version>
      </data>
    </patch_test>
    <compound_test id="cmp-205" comment="Patches 108827-30 and 108901-06" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-201"/>
      <subtest negate="false" test_ref="spt-202"/>
    </compound_test>
    <file_test id="uft-7" comment="File dmispd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/dmi/dmispd</component>
        </path>
      </object>
    </file_test>
    <file_test id="uft-6" comment="File rpc.cmsd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.cmsd</component>
        </path>
      </object>
    </file_test>
    <compound_test id="cmp-204" comment="rpc.cmsd or dmispd exist" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uft-6"/>
      <subtest negate="false" test_ref="uft-7"/>
    </compound_test>
    <permission_test id="upt-826" comment="File kcms_configure executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_configure</component>
        </path>
      </object>
      <data operation="AND">
        <sgid datatype="int" operator="equals">1</sgid>
      </data>
    </permission_test>
    <permission_test id="upt-825" comment="File kcms_configure executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_configure</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-203" comment="File kcms_configure executable and SUID or SGID" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-825"/>
      <subtest negate="false" test_ref="upt-826"/>
    </compound_test>
    <permission_test id="upt-824" comment="File kcms_configure executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_configure</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <compound_test id="cmp-202" comment="File kcms_configure executable and SUID or SGID" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-824"/>
      <subtest negate="false" test_ref="cmp-203"/>
    </compound_test>
    <file_test id="uft-5" comment="File kcms_configure exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_configure</component>
        </path>
      </object>
    </file_test>
    <uname_test id="uut-4" comment="Solaris 8 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">SunOS</os_name>
        <os_release operator="equals">5.8</os_release>
      </data>
    </uname_test>
  </tests>
</oval>